Null offensive hacking hands-on training.

Proposed sessions for this event:

  • Advanced SQL Injections by Sanchay Singh
  • Advanced SQL Injections by Shashwat Tiwari
  • Advanced SQL Injections by Harsh Verma
Note: The session details including schedule are available below.

This is an invite-only event. The attendees will be shortlisted based on their replies filled in the google form - https://forms.gle/GjAeNK77Z84qYxWo8

Expected Audience Skill Level:
1. Knowledge of Basic Web Application PenTesting
2. Knowledge of Basic Bug Bounty Hunting

The team will give a brief about basic types of Injections and will quickly jump to advanced Injections.

Content Covered:

  • Introduction
    - Basics to Injections
    - SQL Injection and its types

  • Login and Union Based Injections
    - How login works
    - Login based injections
    - How URL parameter works
    - Exploiting information_Schema

  • Blind SQL Injections
    - Finding parameter in BurpSuite Request
    - Exploiting Blind Injection using UNION
    - SQLMap and automation of Injections
    - SQLMap for finding Blind Injections

  • Conditional Response Based SQL Injections
    - Finding parameter in the request
    - Setting up query for Conditional Response
    - Finding username from tables
    - Validation of length of data
    - Brute-forcing for data retrieval
    - SQL Injections by triggering errors

  • SQL Injections by triggering time-delays
    - What are time-delays
    - How to exploit using time delays

  • SQL Injection using Out-of-Band Techniques
    - Out of band techniques
    - Data Exfiltration
    - DNS Queries and other attacks

Prerequisites:

  • A working Laptop
  • BurpSuite Community Edition
  • VirtualBox or any other Hypervisor platform
  • Kali Linux
Date Saturday February 11 2023
Chapter Delhi NCR
Registrations 0
Max Registrations 15
Event Type Invite Only
Start Time 09:50 AM
End Time 02:30 PM

Session Schedule

Name Speaker Start Time End Time Resources
Introduction to Null community 09:50 AM 10:00 AM
Advanced SQL Injections Sanchay Singh 10:00 AM 02:20 PM
Advanced SQL Injections Shashwat Tiwari 10:00 AM 02:00 PM
Advanced SQL Injections Harsh Verma 10:00 AM 02:00 PM

Venue


This is an invite only event. If you are selected you will receive further information via e-mail.