Injection Vulnerabilities

Explore critical web injection flaws including Command Injection and SQL Injection (SQLi). Learn manual exploitation techniques and automate database compromise using the powerful sqlmap tool.

Cybersecurity EngineerCybersecurityKali LinuxLinux

Introduction

Injection flaws appear when an application lets user-controlled data change the meaning of a shell command or database query. This course makes that boundary failure visible through command injection and SQL injection exercises against deliberately vulnerable local applications.

You will first build payloads manually so you can see why separators, quotes, comments, boolean expressions, and UNION SELECT alter program behavior. You will then use sqlmap to automate detection, schema enumeration, data extraction, and an OS-shell workflow before completing an independent database-compromise challenge.

What You Will Learn

  • Identify a command injection point and confirm execution with Linux command separators.
  • Bypass simple keyword filters with shell escaping and wildcards, then create a proof file on the target.
  • Trigger SQL errors and construct a boolean payload that bypasses a vulnerable login.
  • Determine query column counts and reflected positions with ORDER BY and UNION SELECT.
  • Query SQLite schema metadata and extract staged usernames and passwords through the application response.
  • Use sqlmap to detect SQLi, enumerate databases, dump a selected table, and attempt an interactive OS shell.
  • Independently validate two SQLi entry points and export a staged customer table in the final challenge.

Who This Course Is For

This intermediate course is for web security learners who want to understand injection mechanics before relying on automation. It suits aspiring penetration testers, application security learners, and developers who need concrete examples of how unsafe command construction and dynamic SQL lead to system and data exposure.

Prerequisites: Comfort with a Linux terminal and curl, basic HTTP GET/POST requests and URL encoding, and introductory SQL concepts such as SELECT, WHERE, columns, and tables.

Learning environment: An Ubuntu 22.04 terminal with sqlmap and isolated, deliberately vulnerable web applications on local ports 5000, 8080, and port 80. All commands and extracted sample data remain inside the course environment.

Frequently Asked Questions

Do I need to know advanced SQL before starting?

No. The labs explain the query context, boolean logic, comments, column counting, and UNION SELECT sequence. Familiarity with basic SQL vocabulary will make the intermediate exercises easier to follow.

Are the injection payloads sent to real systems?

No. Every target is a local application intentionally configured for practice. The commands, credentials, customer records, and tokens are staged lab data.

Why does the course teach manual SQL injection before sqlmap?

Manual exercises show how input changes query syntax and how reflected columns expose data. That understanding helps you interpret sqlmap’s detection techniques and scope its automated enumeration rather than treating its output as a black box.

Does the course obtain operating-system command execution?

Yes, within the isolated labs. The command-injection exercise runs selected Linux commands directly, and the sqlmap lab guides you through its --os-shell workflow against a prepared PHP target. These activities do not extend beyond the local environment.

Teacher

labby
Labby
Labby is the LabEx teacher.

Recommended For You

no data