Tags
Language
Tags
May 2024
Su Mo Tu We Th Fr Sa
28 29 30 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31 1

The Practical Guide to sqlmap for SQL Injections (08/2021)

Posted By: ParRus
The Practical Guide to sqlmap for SQL Injections (08/2021)

The Practical Guide to sqlmap for SQL Injections
WEBRip | English | MP4 | 1280 x 720 | AVC ~1601 Kbps | 30 fps
AAC | 128 Kbps | 48.0 KHz | 2 channels | Subs: English (.srt) | ~5.5 hours | 3.51 GB
Genre: eLearning Video / IT & Software, Network & Security, Ethical Hacking

Learn how to use sqlmap for professional engagements with the most in-depth sqlmap course
What you'll learn
What sqlmap is and how it's used to test web applications for SQL injection vulnerabilities
How to create a home lab environment to safely and legally attack web applications with SQL injections
Find and exploit your first SQL injections with sqlmap
Learn, in-depth, all of the options that sqlmap offers
How to enumerate vulnerable database information (such as database names, schema, tables, and data within those tables)
How sqlmap code is structured and how to find what you're looking for (ie: payloads and settings)
How to manipulate headers, parameters, methods, data, cookies, and more
How to configure targets via URLs, logfile, bulkfiles, and request files (from Burp/ZAP)
How to configure proxies and Tor to use sqlmap anonymously
How to modify requests on the fly with simple Python scripts
How to identify WAFs and manually as well as automatically bypass them (with tamper scripts)
How to troubleshoot common sqlmap errors and overcome issues
Understand how (and when) to use –level and –risk, and how it affects results (this is important!)
How to use regular and advanced takeover options and techniques to take control of back-end databases and servers
How to run sqlmap as an API server and client
How to fingerprint, enumerate, and takeover

Description
About the course:

Learn how to use sqlmap in-depth for professional engagements, and help support open-source in the process. 40% of every sale will be donated to the sqlmap project to help support its development.

sqlmap is the most powerful and widely used SQL injection tool, and for good reason. It packs an impressive array of features and options specifically crafted to fingerprint, enumerate, and takeover databases as well as underlying systems. In this course, we take a look at all of that. We start by looking at the sqlmap project, including how the source code repository is structured, where to find important files such as configuration and payload files, and how to set up a home lab environment to safely and legally practice what we're learning. Then, we explore every single option that sqlmap offers with examples and explanations of how and when to use the option(s). We learn tips & tricks to see what sqlmap is doing under the hood and to troubleshoot when we come across issues. Once we've covered sqlmap's options and features, we tie it all together by running through scenarios. This is when we get to see how those options can be used together or on their own to achieve our pentest or bug bounty objectives.

The course also includes sections dedicated to specific topics such as bypassing WAFs and evading security controls, and how to run sqlmap as an API.

Instructor

My name is Christophe Limpalair, and I have helped thousands of individuals pass IT certifications, learn how to use the cloud, and develop secure applications. I got started in IT at the age of 11 and unintentionally fell into the world of cybersecurity. Fast-forward to today, and I've co-founded a fast-growing cybersecurity community, Cybr, that also provides training resources.

As I developed a strong interest in programming and cloud computing, my focus for the past few years has been training thousands of individuals in small, medium, and large businesses (including Fortune 500) on how to use cloud providers (such as Amazon Web Services) efficiently, and how to develop more secure applications.

I've taught certification courses such as the AWS Certified Developer, AWS Certified SysOps Administrator, and AWS Certified DevOps Professional, as well as non-certification courses such as Introduction to Application Security (AppSec), SQL Injection Attacks, Introduction to OS Command Injections, Lambda Deep Dive, Backup Strategies, and others.

Working with individual contributors as well as managers, I realized that most were also facing serious challenges when it came to cybersecurity.

Digging deeper, it became clear that there was a lack of training for AppSec specifically. As we explore in the course, SQL injection vulnerabilities can be absolutely devastating when exploited, but preventing SQL injections is actually quite simple. So my goal with this course is to help you get started on your journey of learning the tools, techniques, and concepts to properly find injection vulnerabilities in your own applications (or your client's).

It's time to take security into our own hands and to learn how to build more secure software in order to help make the world a safer place! Join me in the course, and we'll do just that!

I welcome you on your journey to learning more about sqlmap, and I look forward to being your instructor!

Who this course is for:
Web pentesters
Application Security Engineers
Web Developers
Bug Bounty Hunters
DevSecOps Engineers
Security Researchers
Database administrators

also You can find my other useful: IT & Software-posts

General
Complete name : 004 Proxies and using sqlmap anonymously.mp4
Format : MPEG-4
Format profile : Base Media
Codec ID : isom (isom/iso2/avc1/mp41)
File size : 120 MiB
Duration : 9 min 39 s
Overall bit rate : 1 737 kb/s
Writing application : Lavf58.12.100

Video
ID : 1
Format : AVC
Format/Info : Advanced Video Codec
Format profile : Main@L3.1
Format settings : CABAC / 4 Ref Frames
Format settings, CABAC : Yes
Format settings, RefFrames : 4 frames
Format settings, GOP : M=4, N=60
Codec ID : avc1
Codec ID/Info : Advanced Video Coding
Duration : 9 min 39 s
Bit rate : 1 601 kb/s
Nominal bit rate : 3 000 kb/s
Width : 1 280 pixels
Height : 720 pixels
Display aspect ratio : 16:9
Frame rate mode : Constant
Frame rate : 30.000 FPS
Color space : YUV
Chroma subsampling : 4:2:0
Bit depth : 8 bits
Scan type : Progressive
Bits/(Pixel*Frame) : 0.058
Stream size : 111 MiB (92%)
Writing library : x264 core 148
Encoding settings : cabac=1 / ref=3 / deblock=1:0:0 / analyse=0x1:0x111 / me=umh / subme=6 / psy=1 / psy_rd=1.00:0.00 / mixed_ref=1 / me_range=16 / chroma_me=1 / trellis=1 / 8x8dct=0 / cqm=0 / deadzone=21,11 / fast_pskip=1 / chroma_qp_offset=-2 / threads=22 / lookahead_threads=3 / sliced_threads=0 / nr=0 / decimate=1 / interlaced=0 / bluray_compat=0 / constrained_intra=0 / bframes=3 / b_pyramid=2 / b_adapt=1 / b_bias=0 / direct=1 / weightb=1 / open_gop=0 / weightp=2 / keyint=60 / keyint_min=6 / scenecut=0 / intra_refresh=0 / rc_lookahead=60 / rc=cbr / mbtree=1 / bitrate=3000 / ratetol=1.0 / qcomp=0.60 / qpmin=0 / qpmax=69 / qpstep=4 / vbv_maxrate=3000 / vbv_bufsize=6000 / nal_hrd=none / filler=0 / ip_ratio=1.40 / aq=1:1.00

Audio
ID : 2
Format : AAC
Format/Info : Advanced Audio Codec
Format profile : LC
Codec ID : mp4a-40-2
Duration : 9 min 39 s
Bit rate mode : Constant
Bit rate : 128 kb/s
Channel(s) : 2 channels
Channel positions : Front: L R
Sampling rate : 48.0 kHz
Frame rate : 46.875 FPS (1024 SPF)
Compression mode : Lossy
Stream size : 8.84 MiB (7%)
Default : Yes
Alternate group : 1

Screenshots

The Practical Guide to sqlmap for SQL Injections (08/2021)

The Practical Guide to sqlmap for SQL Injections (08/2021)

The Practical Guide to sqlmap for SQL Injections (08/2021)

The Practical Guide to sqlmap for SQL Injections (08/2021)

The Practical Guide to sqlmap for SQL Injections (08/2021)

Exclusive eLearning Videos ParRus-blogadd to bookmarks

The Practical Guide to sqlmap for SQL Injections (08/2021)