Buna Byte Cybersecurity
848 subscribers
269 photos
10 videos
2 files
189 links
Learn, Hack, and Defend

Website: bunabyte.com
YouTube: youtube.com/@bunabyte
BunaByte Files: @hacker_habesha
Download Telegram
$book_name = $_GET['book_name'] ?? '';
$special_chars = array("OR", "or", "AND", "and" , "UNION", "SELECT");
$book_name = str_replace($special_chars, '', $book_name);
$sql = "SELECT * FROM books WHERE book_name = '$book_name'";
echo "<p>Generated SQL Query: $sql</p>";
$result = $conn->query($sql) or die("Error: " . $conn->error . " (Error Code: " . $conn->errno . ")");
if ($result->num_rows > 0) {
while ($row = $result->fetch_assoc()) {
...
..

What makes this code vulnerable?

bunabyte.com
โค9โšก3
Buna Byte Cybersecurity
$book_name = $_GET['book_name'] ?? ''; $special_chars = array("OR", "or", "AND", "and" , "UNION", "SELECT"); $book_name = str_replace($special_chars, '', $book_name); $sql = "SELECT * FROM books WHERE book_name = '$book_name'"; echo "<p>Generated SQL Query:โ€ฆ
Why this code is vulnerable

โ€ข User input is directly concatenated into the SQL query
โ€ข Once input enters the query string, SQL injection is already possible


Why str_replace makes it worse

โ€ข SQL is a grammar-based language, not a keyword list
โ€ข Removing words like OR, AND, UNION, SELECT does not change SQL logic


str_replace is:

- case-sensitive
- literal
- context-unaware


Attackers can bypass filters using:

- alternative operators
- comments
- encodings
- numeric logic

- functions and comparisons

๐Ÿ™…โ€โ™‚๏ธThe critical mistake

โ€ข User input is still placed inside quotes

WHERE book_name = '$book_name'


โ€ข The database still parses input as executable SQL
โ€ข Filtering inside a dangerous context does not make it safe


Additional security issues

โ€ข Echoing the SQL query leaks:

- table names
- column names
- filtering logic

โ€ข Displaying database errors gives attackers free reconnaissance



Here is the bestโ€‘practice version of that code


$book_name = $_GET['book_name'] ?? '';

$stmt = $conn->prepare(
"SELECT * FROM books WHERE book_name = ?"
);

$stmt->bind_param("s", $book_name);
$stmt->execute();

$result = $stmt->get_result();

if ($result->num_rows > 0) {
while ($row = $result->fetch_assoc()) {
// process result
}
}


โ˜•๏ธ $stmt turns user input from code into data.


bunabyte.com
@bunabytecs
๐Ÿ”ฅ8๐Ÿ‘Œ4โค1
แŠฅแŠ•แŠณแŠ• แŠ แ‹ฐแˆจแˆณแ‰ฝแˆ! แˆ˜แˆแŠซแˆ แ‹จแŒฅแˆแ‰€แ‰ต แ‰ แ‹“แˆ!

bunabyte.com
โค8๐ŸŽ‰3
Buna Byte Resources Channel, You can find book files related to ethical hacking and cybersecurity in this channel.

๐Ÿ‘‰ here: @hacker_habesha
๐Ÿ‘7๐Ÿ‘3โค2
Forwarded from Cyber Vanguard @ CTBE
Are you ready to join today and tomorrow's cybersecurity foot soldiers?

picoCTF-Africa 2026 is back! Bigger, better and upto 80 students to be awarded!

Join our picoCTF-Africa prep info session
๐Ÿ“… 24 January
โฐ 11 am Rwanda time ( convert time to your own country )
โ›“๏ธโ€๐Ÿ’ฅ  bit.ly/picoCTF2026

Registration for the CTF opens on 1 February 2026, so get ready.
Competition runs 9 - 19 March 2026

stay alert. protect your accounts. share this with a friend

https://www.instagram.com/p/DTxI73ZDAS2/?igsh=MWlzYWgwbTZ1c3UyMA==
๐Ÿ”ฅ7๐Ÿ‘3
#Buna_Qurs

The original definition of hacking, emerging in the 1950s-1960s at MITโ€™s Tech Model Railroad Club, referred to
creative, skillful, and often playful modification of technical systems to improve them or make them function in new, unconventional ways.

@bunabytecs
โค9๐Ÿ”ฅ2๐Ÿ‘1๐ŸŽ‰1
โšก๏ธ Buna Byte Academy is coming.

We are building a focused learning space for:
โ€ข Hands-on cybersecurity labs
โ€ข Expert-led training
โ€ข Structured paths for real-world skills


The waitlist is now open.

Join early to get launch updates, early access, and exclusive opportunities reserved for first members.

๐Ÿ‘‰ Join the waitlist: academy.bunabyte.com

#Cybersecurity #Learning @bunabytecs
โค9๐Ÿ”ฅ4๐Ÿคฉ2๐Ÿ‘1๐Ÿ™1
BBJST Buna Byte Junior Security Tester Course Batch 04 is coming....๐Ÿ‘จโ€๐Ÿ’ป๐Ÿ‘ฉโ€๐Ÿ’ป

A
R
E

Y
O
U

R
E
A
D
Y
โ“

๐ŸŒ: bunabyte.com
โ˜Ž๏ธ: +251923167274
โœ‰๏ธ: info@bunabyte.com

#BBJST@bunabytecs
๐Ÿ”ฅ8๐Ÿคฉ2
THE LONG AWAITED ANNOUNCEMENT IS HERE ๐Ÿ”ฅ

โ€‹The most intensive Cybersecurity training in Ethiopia BBJST Batch 04 is officially open for registration. ๐Ÿ›ก๐Ÿ’ป

โ€‹Youโ€™ve been asking for it. Now itโ€™s here. This is your chance to stop being a spectator and start becoming a Junior Security Tester.

โ€‹Why now?

โœ… High-demand skill set
โœ… Practical, lab-based learning
โœ… Limited seats for maximum focus

โ€‹Stop waiting for the "perfect time." The perfect time is now.

โ€‹๐Ÿš€ REGISTER BEFORE SLOTS FILL UP: ๐Ÿ‘‰ bunabyte.com/bbjst

@bunabytecs
โค10๐Ÿ”ฅ4โšก1
๐ŸŸฃ The BBJST program is crafted for individuals with a passion for technology and security but who lack formal experience.

We strip away the complexity and focus on actionable, real-world skills used by penetration testers every day.

Register here: bunabyte.com/bbjst

#BBJST@bunabytecs
๐Ÿ”ฅ6โค2๐ŸŽ‰2
๐ŸชซSlides donโ€™t make security testers.

Practice does.

BBJST focuses on hands-on labs, real-world attack scenarios, and beginner-friendly guidance to help you build actual security skills, not just knowledge.


Learn cybersecurity the right way.
๐Ÿ”— bunabyte.com/bbjst
โšก6๐Ÿ”ฅ3โค1๐Ÿ’ฏ1
Who Should Join BBJST? ๐Ÿค”

โœ… Absolute beginners
โœ… IT students
โœ… Career switchers
โœ… Curious ethical hackers

Learn cybersecurity the right way.
๐Ÿ”— bunabyte.com/bbjst
โค7๐ŸŽ‰1
Only 3๏ธโƒฃ Days Left! Donโ€™t Miss Out!
โšก
Become a Buna Byte Junior Security Tester and kickstart your cybersecurity journey. ๐Ÿ”

What youโ€™ll get:
๐Ÿ›ก Hands-on hacking experience
๐Ÿ›ก Insider tips from industry pros
๐Ÿ›ก Certificate that stands out

Time is running outโฐ

Registration closes in just 3 DAYS!
Secure your spot now before itโ€™s too late limited seats available.

โœ… Donโ€™t be the one who hears about it laterโ€ฆ be the one who gets ahead today.

https://bunabyte.com/bbjst

@bunabytecs
๐Ÿ”ฅ4โคโ€๐Ÿ”ฅ3โค1
Only 2๏ธโƒฃ DAYS LEFT
BunaByte Junior Security Tester (BBJST) Registration is about to close ๐Ÿ”’

Gain skills in:
โœ…Ethical Hacking & Cybersecurity Basics
โœ…Linux & Windows for Hackers
โœ… Network Security & Cryptography
โœ… Web & System Hacking
โœ… Social Engineering Defense

https://bunabyte.com/bbjst

@bunabytecs
๐Ÿ‘5โคโ€๐Ÿ”ฅ3๐Ÿ”ฅ1
ONLY 1โƒฃ DAY LEFT ALERT!โฐ
Registration for BunaByte Junior Security Tester (BBJST) closes tomorrow โณ

Do you know? ๐Ÿ‘€

โžก๏ธ Cybersecurity experts and Bug Bounty Hunters are some of the most in-demand and highly paid tech professionals today.

โžก๏ธ Companies worldwide are desperate for skilled testers who can secure their systems.

This is YOUR chance to step in.๐Ÿ˜‰

https://bunabyte.com/bbjst

@bunabytecs
๐Ÿ‘4โค3๐Ÿ”ฅ1