About the instructor


Hello, I'm Ibrahim Husić, the mind behind the SQLi LABS project. I am a senior penetration tester with over 10 years of experience in penetration testing and cybersecurity. In my free time, I enjoy working on bug bounty platforms.

I have discovered vulnerabilities on major bug bounty platforms for companies like Microsoft, Facebook, Apple, and Google, earning monetary rewards for my findings.

From January to the end of April 2024, I successfully identified over 30 XSS and few SQLI vulnerabilities on bug bounty platforms using my tools.

My dedication to improving internet and web application security drives my work, and I am passionate about sharing my knowledge and tools to help others in the cybersecurity community.

Introduction


This SQLi Labs course consists of 12 labs. Each lab contains a flag that needs to be found. Each lab is individually designed, covering different levels of SQL injection attacks. Along with this course, you will receive materials, including the created labs, tools used for this course, and helpful payloads.

This course is for anyone who wants to learn more about SQL injection attacks.It can be taken by individuals with varying levels of knowledge, from beginners to advanced, but it is preferred that participants have some prior knowledge of SQL injection attacks. All security tests have been conducted within the labs, and there is no harm that can be caused to anyone.


I hope it will be useful to you, especially for those working in IT security roles and participating in bug bounty programs.




Course syllabus




  SQL injection Login bypass
Available in days
days after you enroll
  [HEADER] X-Forwarded-For SQLi Injection
Available in days
days after you enroll
  Parameter id:
Available in days
days after you enroll
  LFi - Local File Inclusion
Available in days
days after you enroll
  Referer header & username
Available in days
days after you enroll
  [HEADER] Referer SQLi Injection
Available in days
days after you enroll
  SQLi error-based on User-Agent
Available in days
days after you enroll
  Error based SQL Injection on Login
Available in days
days after you enroll
  [HEADER] User-Agent SQLi Injection
Available in days
days after you enroll
  Try to find me
Available in days
days after you enroll
  Blind based SQLi Injection multiple parameters
Available in days
days after you enroll
  SQL manual payloads
Available in days
days after you enroll
  ALL TOOLS & PAYLOADS & LABS PHP FILES + DATABASES
Available in days
days after you enroll
  Ibrahim's Methodology for SQLi Injection & Bug bounty hunt
Available in days
days after you enroll
  #IBRAHIMXSS TOOL PRESENTATION
Available in days
days after you enroll