
DEF CON 32 -Ticking SQLi - Iggy
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 25:11
SQL injection remains a critical and relevant web vulnerability despite being an older technique, as demonstrated by historical attacks and ongoing prevalence in security reports 2:51. The talk explores various types of SQL injection—such as inband, union-based, blind (Boolean and time-based), and out-of-band—with a focus on time-based injection, which exploits database response delays to infer sensitive data [3:50–4:47]. A real-world example shows how an attacker used a time-based payload to extract a database version by triggering a 5-second delay, ultimately earning a $5,000 bounty [16:30–17:15]. The presentation highlights how the activist group Team Goel used SQL injection in 2012 to hack institutions and leak data, emphasizing their mission to promote activism through cyber operations [19:20–21:45]. Despite being outdated in terms of tools, these techniques remain relevant due to their foundational nature and applicability to modern attacks [23:06–24:14].
The speaker concludes by recommending a free, practical resource—Paul Swigle’s "Bleach" tool—for learning SQL injection hands-on, emphasizing that understanding these concepts builds transferable skills for cybersecurity 25:01.
[Sources:
- 2:51 Briefly discusses the ongoing relevance of SQL injection in modern security landscapes.
- 3:50–4:47 Explains the mechanics of inband and union-based SQL injection with live examples.
- 16:30–17:15 Details a real-world bounty scenario using time-based SQL injection.
- 19:20–21:45 Describes Team Goel’s historical use of SQL injection for activism and data leaks.
- 23:06–24:14 Argues that foundational attack concepts remain valuable despite technological evolution.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
all right folks it is that time if you have a seat that is in between you please collapse down specifically you sir thank you very much if you would bring it in close all right with that we are going to go ahead and kick everything off I would like to introduce Iggy to the stage thank you WSS [Applause] yeah uh so hello defon and welcome to my talk call in called the ticking sqli and we will begin so what's in it for you today today we will uh explore types of SQL injection we'll focus a bit on a Time Time based SQL injection we will see the impact team goost shell did in the past using those kinds of techniques we will understand why it's still relevant today and you will have a good time with a pretty much good presenter today uh so who am I my name is Eagle uh but please call me igy it'…