강의

멘토링

로드맵

BEST
Security & Network

/

Computer Security

SQL Injection Attack Techniques and Secure Coding Explained by a Simulated Hacking Practitioner: PART 1

SQL Injection, the flower of web hacking, explained by a mock hacking practitioner! Learn attack and defense at the same time.

(4.8) 108 reviews

1,154 learners

  • crehacktive
Penetration Testing
Injection

Reviews from Early Learners

What you will learn!

  • Building a basic understanding of vulnerabilities

  • Understand why vulnerabilities occur and the detailed principles

  • Identifying various attack points that occur in practice

  • Learn the attacks used in practice

  • Apply direct countermeasures to vulnerable functions and learn secure coding

📖 A series of SQL Injection attacks, taught by a simulated hacking expert!

  • PART (1): Basics / Practical Attacks / Secure Coding ◀ Current Course
    This course covers the most crucial aspects of SQL injection attacks, from the basics to practical attack techniques, various countermeasures, and secure coding. This course serves as a foundation for subsequent courses.

  • PART(2): Application / Advanced / Advanced
    This is training on applied attack techniques and advanced attack techniques not covered in PART(1).

  • PART(3): Creating an Automation Tool
    This training course will teach you how to create a Python-based automation tool by applying the attack techniques you have learned to an automation tool.

📖 Why should you learn SQL Injection?

A popular figure in the web hacking world! The fact that so many people are aware of the attack means its impact is significant, right?

Most web applications today feature dynamic page generation based on user input. In this environment, attackers face a growing number of attack targets, necessitating effective analysis methods and adaptive attack techniques tailored to each situation. Conversely, defenders often implement inline security solutions or secure coding for effective defense. Understanding attacks is crucial for effective defense, right?

📖 Attack techniques that can be applied immediately in practice!

For effective vulnerability analysis, you'll learn how to analyze various attack points using specific methodologies. You'll also learn the appropriate attack techniques and the specific environments in which they should be used. This course covers each attack technique used in practice in detail.

📖 Provides a PHP-based practice bulletin board for each DBMS!

We provide a practice bulletin board based on PHP-MYSQL, PHP-MSSQL, and PHP-ORACLE, through which you can practice SQL injection for various DBMS.

📖 Learn SQL Injection attack techniques and secure coding by following along!

Each technical element for completing SQL Injection attack techniques does not end in theory.
We will conduct hands-on training for each DBMS.

We'll take a closer look at the response measures for each function and conduct hands-on practice applying secure coding to vulnerable bulletin boards.

📖 Expected effects through education

  • If you're just starting to learn about SQL Injection, this course will serve as a guide to point you in the right direction.
  • If you already know about SQL Injection, you will experience the magic of connecting your scattered knowledge, and if you are lost, we will point you in the right direction.

🛠 Programs covered here

  • Burp Suite
  • APMSetup / MSSQL / ORACLE
  • QueryBox

※ How to use Burp Suite is not covered in this training. You can refer to the basic usage method in the training " Stories about Web Hacking and Simulated Hacking in the Field ".

🙋🏻‍♂ Questions QnA

Q. I want to take the course, but is there anything I need to know beforehand?
A. Basically, you must know and listen to the basics of web and SQL grammar , and it is also recommended to take additional web hacking training.

Q. If I complete the training, can I get a practical diagnosis?
A. Of course! However, simply receiving training isn't enough. To achieve satisfactory results, you need to study and practice on your own. To achieve anything, you need to put in the effort.

Q. Why is the training time so much longer than that of other mock hacking training programs for SQL injection?
A. This training is specialized and covers only SQL injection, so it's bound to be long. Of course, the approach will also be completely different. While existing attack approaches are separate and distinct, this training connects them into a single, unified framework. You'll also discover why you need to carry out this type of attack.

Q. Can non-majors and students also take the course?
A. Of course! However, you must complete the required viewing lectures below and fully understand them before taking this course.

💡 Must-see lectures

Web Technology Fundamentals You Must Know
A course to learn the basics of web technology
Basic SQL Grammar for Successful SQL Injection Attacks
Basic Steps to Mastering SQL Injection Attacks

※ This training PPT uses Nanum font provided by Naver.

Recommended for
these people

Who is this course right for?

  • For those who want to learn SQL Injection properly

  • For practitioners who have difficulty finding SQL Injection vulnerabilities when diagnosing websites

  • For practitioners who only perform vulnerability diagnosis

  • People who can't attack without SQL Injection automation tool

  • For those who want to gather their knowledge about SQL Injection in one place.

  • If you want to know exactly what attack to do in what environment

  • For those who want to know the exact attack process

  • If you fail to provide the correct response plan

Need to know before starting?

  • Web Basics

  • Buff Suite Basic Usage

  • Web Hacking Basics

  • SQL Basic Grammar

Hello
This is

26,167

Learners

1,387

Reviews

502

Answers

4.9

Rating

18

Courses

안녕하섞요, 크늬핵티람입니닀.

닀년간 닀양한 웹 서비슀륌 진닚하고 연구한 겜험을 바탕윌로, 싀묎에 바로 적용 가능한 지식을 읞프런 플랫폌에서 공유핎였고 있습니닀.

귞늬고 웹 핎킹 Ʞ쎈륌 첎계적윌로 닀룬 『크늬핵티람의 한 권윌로 끝낮는 웹 핎킹 바읎랔』을 집필했습니닀. Ʞ쎈가 부족한 분듀께는 읎 책윌로 학습을 시작하싀 것을 권합니닀.

 

Curriculum

All

123 lectures ∙ (24hr 31min)

Course Materials:

Lecture resources
Published: 
Last updated: 

Reviews

All

108 reviews

4.8

108 reviews

  • hackgenius226849님의 프로필 읎믞지
    hackgenius226849

    Reviews 4

    ∙

    Average Rating 5.0

    Edited

    5

    80% enrolled

    I am currently working for an information security company, so I wanted to take related training, and I applied for and took this course. The result is very satisfactory. The instructor's expertise is evident throughout the lecture. The more I listened to the lecture, the more ashamed I felt of myself for having only done superficial diagnoses. I didn't know what kind of attacks to perform in what kind of environment, but through this training, I was able to clearly understand what attacks to perform depending on the environment. Also, it seems that the instructor created the attack process himself, and I think it will be really helpful in practical diagnosis. There are many times when I have to attack, but I just stare blankly at the parameters and don't know what to do, but if I refer to this, I think I can smoothly perform the diagnosis sequentially. Oh, and that roadmap is amazing. I printed it out. I've only watched it once now, but I'm going to watch it two more times as the instructor said. Thank you, instructor.

    • crehacktive
      Instructor

      長受講評ありがずうございたしたお圹に立おたなんお本圓に幞いですねㅎ倧切な受講評ありがずうございたす。良い䞀日をお過ごしください〜

  • webwh님의 프로필 읎믞지
    webwh

    Reviews 14

    ∙

    Average Rating 4.5

    5

    94% enrolled

    原理䞀぀䞀぀説明しおくださったので、隙のない知識を埗たず感じたした。プロセスを頭の䞭でずっず敎理しおみお蚺断をするようになったら䜕からしなければならないのかすぐに浮䞊するのがずおも良かったです。珟圚ホワむトハッカヌではないので、もう2床聞いお実習する環境をゞャンゎ、スプリングを掻甚しお䜜っおいるのですが、開発しながらもプロセスが思い浮かび、フィルタリングロゞックを曞きたいず思いたした。次の講矩であるPart 2,3,4も早く芋たいですね [蚈3回+@受講埌远加] 初めお受講した時点で、セキュリティコンサルタントのキャリアを開始するこずになりたした。そしお䜕よりも、ペむロヌドをn幎目の実務コンサルタントが理解できず、私に質問する様子を芋るず、クリクリプティブ様の講矩が倚倧な内空を持ったこずに気づくこずができたした。繰り返し孊習しながら、WAFバむパスや効率的なデヌタ照䌚などをすべお実務で掻甚できるようになりたした。もう䞀床ありがずうございたす。

    • crehacktive
      Instructor

      プロセスが浮かび䞊がるなんお嬉しいですねㅎㅎ受講評を䞊手くくださりありがずうございたす 倧切な受講評で力を埗たすね。送っおください〜

  • springsik님의 프로필 읎믞지
    springsik

    Reviews 1

    ∙

    Average Rating 5.0

    5

    100% enrolled

    実務家です。理論から実技たでしっかりずした講矩でした。どんな教育だず特定されないでしょうが、他の教育を聞いた時は党䜓的に䞍足した感じでしたが、いっぱいに満ちた感じですね。良い講矩ありがずうございたす。

    • hyeonseok985238님의 프로필 읎믞지
      hyeonseok985238

      Reviews 15

      ∙

      Average Rating 5.0

      5

      99% enrolled

      これより良い講矩があるかず思いたす。最高の講矩ですね

      • bryan님의 프로필 읎믞지
        bryan

        Reviews 8

        ∙

        Average Rating 4.9

        5

        99% enrolled

        講矩の途䞭で "サヌバヌ偎 DB ク゚リ情報を考えながら䜜成せよ" は内容が本圓に届きたした。 良い講矩です。

        $127.60

        crehacktive's other courses

        Check out other courses by the instructor!

        Similar courses

        Explore other courses in the same field!