Player FM 앱으로 오프라인으로 전환하세요!
Ep. 5 – Stored XSS & SQL Injection: Small Flaws, Big Breaches
Manage episode 471294002 series 3643227
A simple filename triggered stored XSS, hijacking accounts and stealing API keys. A SQL injection bypassed a web firewall, dumping an entire database in one request.
Both attacks exploited basic security flaws—flaws that should have been caught.
Learn how these exploits worked, why they were missed, and what should have been done differently.
Chapters:
0:00 - INTRO
01:39 - FINDING #1 – Stored XSS That Took Over User Accounts
07:14 - FINDING #2 – The SQL Injection That Bypassed a Firewall and Dumped the Entire Database
15:22 - OUTRO
Want your pentest discovery featured? Submit your creative findings through the Google Form in the episode description, and we might showcase your finding in an upcoming episode!
🌍 Follow & Connect → LinkedIn, YouTube, Twitter, Instagram
📩 Submit Your Pentest Findings → https://forms.gle/7pPwjdaWnGYpQcA6A
📧 Feedback? Email Us → [email protected]
🔗 Podcast Website → Website Link
챕터
1. INTRO (00:00:00)
2. FINDING #1 – Stored XSS That Took Over User Accounts (00:01:39)
3. FINDING #2 – The SQL Injection That Bypassed a Firewall and Dumped the Entire Database (00:07:14)
4. OUTRO (00:15:22)
14 에피소드
Manage episode 471294002 series 3643227
A simple filename triggered stored XSS, hijacking accounts and stealing API keys. A SQL injection bypassed a web firewall, dumping an entire database in one request.
Both attacks exploited basic security flaws—flaws that should have been caught.
Learn how these exploits worked, why they were missed, and what should have been done differently.
Chapters:
0:00 - INTRO
01:39 - FINDING #1 – Stored XSS That Took Over User Accounts
07:14 - FINDING #2 – The SQL Injection That Bypassed a Firewall and Dumped the Entire Database
15:22 - OUTRO
Want your pentest discovery featured? Submit your creative findings through the Google Form in the episode description, and we might showcase your finding in an upcoming episode!
🌍 Follow & Connect → LinkedIn, YouTube, Twitter, Instagram
📩 Submit Your Pentest Findings → https://forms.gle/7pPwjdaWnGYpQcA6A
📧 Feedback? Email Us → [email protected]
🔗 Podcast Website → Website Link
챕터
1. INTRO (00:00:00)
2. FINDING #1 – Stored XSS That Took Over User Accounts (00:01:39)
3. FINDING #2 – The SQL Injection That Bypassed a Firewall and Dumped the Entire Database (00:07:14)
4. OUTRO (00:15:22)
14 에피소드
Minden epizód
×플레이어 FM에 오신것을 환영합니다!
플레이어 FM은 웹에서 고품질 팟캐스트를 검색하여 지금 바로 즐길 수 있도록 합니다. 최고의 팟캐스트 앱이며 Android, iPhone 및 웹에서도 작동합니다. 장치 간 구독 동기화를 위해 가입하세요.