GitHunt
IM

imvickykumar999/SQL-Injection-Bypass-Authentication

Using Selenium to Automate login via SQL Injection. https://youtu.be/nYVj4BmR0bM

SQL Injection Bypass Authentication


image

 YouTube Video : Login using SQL Injection ๐Ÿ’‰ via Selenium web Automation

SELECT * from ADMIN where USERNAME='{uname}' and PASSWORD='{pwd}'


image

SQL Injection Input : ' OR 1=1 --

image


Tkinter Login.py

ss


SQLite3 Colab Gist

image


Flask User Authentication

image


https://haveibeenpwned.com/

  • Canva: In May 2019, the graphic design tool website Canva suffered a data breach that impacted 137 million subscribers. The exposed data included email addresses, usernames, names, cities of residence and passwords stored as bcrypt hashes for users not using social logins. The data was provided to HIBP by a source who requested it be attributed to "JimScott.Sec@protonmail.com".

    Compromised data: Email addresses, Geographic locations, Names, Passwords, Usernames
    
  • Domino's India: In April 2021, 13TB of compromised Domino's India appeared for sale on a hacking forum after which the company acknowledged a major data breach they dated back to March. The compromised data included 22.5 million unique email addresses, names, phone numbers, order histories and physical addresses.

    Compromised data: Email addresses, Names, Phone numbers, Physical addresses, Purchases
    

Account Affected v/s Companies : Spreadsheet

Account Affected vs  Code


Oh no โ€” pwned!

  Pwned in 2 data breaches and found no pastes (subscribe to search sensitive breaches)

image

  >>> Task Idea ๐Ÿ’ก: Use web-scrapping to create spreadsheed.