Turning SQL injection in MySQL into file read #bugbounty #bugbountytips #bugbountyhunter



Turning SQL injection in MySQL into file read #bugbounty #bugbountytips #bugbountyhunter

Turning SQL injection in MySQL into file read #bugbounty #bugbountytips #bugbountyhunter

Full video: https://youtu.be/ClnVdYf4PK0
📕 The full case study: https://bbre.dev/sqlics
📧 Subscribe to BBRE Premium: https://bbre.dev/premium
✉️ Sign up for the mailing list: https://bbre.dev/nl
📣 Follow me on Twitter: https://bbre.dev/tw

This video is a part of the case study of 128 SQL injection bug bounty reports. In this part, I take a look at how did bug hunters demonstrate the impact of SQL injection bugs, including how they turned them into RCEs and file reads or writes.