Buna Byte Cybersecurity
We built this TryHackMe room while teaching the BBJST Buna Byte Junior Security Tester program batch 03. Itโs hands-on Linux fundamentals - not theory, not slides. This is how we learn. This is how we teach. ๐ https://tryhackme.com/jr/bbjstlinux More structuredโฆ
YouTube
แแแญแตแ แ 3 แฐแแต! Linux fundamentals Full course
#2025 #Amharic #cybersecurity #ethiopia #linux
แแแญแตแ แ 3 แฐแแต! แจแแฐแจแฑ แฅแตแจ แแจแจแปแ แแแแ แ แ แแต แชแฒแฎแข แฅแแณแซแแแฅแ!
Full Play list: https://www.youtube.com/playlist?list=PLPVCmb8ehZK3Ta5r8C2-7I_8mmoKNpLms
//๐Timestamps://
0:00 โถ๏ธ Intro
//๐ฑ Stay Connected//
Instagram:โฆ
แแแญแตแ แ 3 แฐแแต! แจแแฐแจแฑ แฅแตแจ แแจแจแปแ แแแแ แ แ แแต แชแฒแฎแข แฅแแณแซแแแฅแ!
Full Play list: https://www.youtube.com/playlist?list=PLPVCmb8ehZK3Ta5r8C2-7I_8mmoKNpLms
//๐Timestamps://
0:00 โถ๏ธ Intro
//๐ฑ Stay Connected//
Instagram:โฆ
โค7๐2
$book_name = $_GET['book_name'] ?? '';
$special_chars = array("OR", "or", "AND", "and" , "UNION", "SELECT");
$book_name = str_replace($special_chars, '', $book_name);
$sql = "SELECT * FROM books WHERE book_name = '$book_name'";
echo "<p>Generated SQL Query: $sql</p>";
$result = $conn->query($sql) or die("Error: " . $conn->error . " (Error Code: " . $conn->errno . ")");
if ($result->num_rows > 0) {
while ($row = $result->fetch_assoc()) {
...
..
What makes this code vulnerable?
bunabyte.com
โค9โก3
Buna Byte Cybersecurity
$book_name = $_GET['book_name'] ?? ''; $special_chars = array("OR", "or", "AND", "and" , "UNION", "SELECT"); $book_name = str_replace($special_chars, '', $book_name); $sql = "SELECT * FROM books WHERE book_name = '$book_name'"; echo "<p>Generated SQL Query:โฆ
Why this code is vulnerable
โข User input is directly concatenated into the SQL query
โข Once input enters the query string, SQL injection is already possible
Why
โข SQL is a grammar-based language, not a keyword list
โข Removing words like OR, AND, UNION, SELECT does not change SQL logic
- case-sensitive
- literal
- context-unaware
Attackers can bypass filters using:
- alternative operators
- comments
- encodings
- numeric logic
- functions and comparisons
๐ โโ๏ธThe critical mistake
โข User input is still placed inside quotes
โข The database still parses input as executable SQL
โข Filtering inside a dangerous context does not make it safe
Additional security issues
โข Echoing the SQL query leaks:
- table names
- column names
- filtering logic
โข Displaying database errors gives attackers free reconnaissance
Here is the bestโpractice version of that code
bunabyte.com
@bunabytecs
โข User input is directly concatenated into the SQL query
โข Once input enters the query string, SQL injection is already possible
Why
str_replace makes it worseโข SQL is a grammar-based language, not a keyword list
โข Removing words like OR, AND, UNION, SELECT does not change SQL logic
str_replace is:- case-sensitive
- literal
- context-unaware
Attackers can bypass filters using:
- alternative operators
- comments
- encodings
- numeric logic
- functions and comparisons
๐ โโ๏ธThe critical mistake
โข User input is still placed inside quotes
WHERE book_name = '$book_name'
โข The database still parses input as executable SQL
โข Filtering inside a dangerous context does not make it safe
Additional security issues
โข Echoing the SQL query leaks:
- table names
- column names
- filtering logic
โข Displaying database errors gives attackers free reconnaissance
Here is the bestโpractice version of that code
$book_name = $_GET['book_name'] ?? '';
$stmt = $conn->prepare(
"SELECT * FROM books WHERE book_name = ?"
);
$stmt->bind_param("s", $book_name);
$stmt->execute();
$result = $stmt->get_result();
if ($result->num_rows > 0) {
while ($row = $result->fetch_assoc()) {
// process result
}
}
โ๏ธ $stmt turns user input from code into data.
bunabyte.com
@bunabytecs
๐ฅ8๐4โค1
Buna Byte Resources Channel, You can find book files related to ethical hacking and cybersecurity in this channel.
๐ here: @hacker_habesha
๐ here: @hacker_habesha
๐7๐3โค2
Forwarded from Cyber Vanguard @ CTBE
Are you ready to join today and tomorrow's cybersecurity foot soldiers?
picoCTF-Africa 2026 is back! Bigger, better and upto 80 students to be awarded!
Join our picoCTF-Africa prep info session
๐ 24 January
โฐ 11 am Rwanda time ( convert time to your own country )
โ๏ธโ๐ฅ bit.ly/picoCTF2026
Registration for the CTF opens on 1 February 2026, so get ready.
Competition runs 9 - 19 March 2026
stay alert. protect your accounts. share this with a friend
https://www.instagram.com/p/DTxI73ZDAS2/?igsh=MWlzYWgwbTZ1c3UyMA==
picoCTF-Africa 2026 is back! Bigger, better and upto 80 students to be awarded!
Join our picoCTF-Africa prep info session
๐ 24 January
โฐ 11 am Rwanda time ( convert time to your own country )
โ๏ธโ๐ฅ bit.ly/picoCTF2026
Registration for the CTF opens on 1 February 2026, so get ready.
Competition runs 9 - 19 March 2026
stay alert. protect your accounts. share this with a friend
https://www.instagram.com/p/DTxI73ZDAS2/?igsh=MWlzYWgwbTZ1c3UyMA==
๐ฅ7๐3
#Buna_Qurs
The original definition of hacking, emerging in the 1950s-1960s at MITโs Tech Model Railroad Club, referred to
The original definition of hacking, emerging in the 1950s-1960s at MITโs Tech Model Railroad Club, referred to
creative, skillful, and often playful modification of technical systems to improve them or make them function in new, unconventional ways.@bunabytecs
โค9๐ฅ2๐1๐1
โก๏ธ Buna Byte Academy is coming.
The waitlist is now open.
Join early to get launch updates, early access, and exclusive opportunities reserved for first members.
๐ Join the waitlist: academy.bunabyte.com
#Cybersecurity #Learning @bunabytecs
We are building a focused learning space for:
โข Hands-on cybersecurity labs
โข Expert-led training
โข Structured paths for real-world skills
The waitlist is now open.
Join early to get launch updates, early access, and exclusive opportunities reserved for first members.
๐ Join the waitlist: academy.bunabyte.com
#Cybersecurity #Learning @bunabytecs
โค9๐ฅ4๐คฉ2๐1๐1
BBJST
A
R
E
Y
O
U
R
E
A
D
Y
โ
๐: bunabyte.com
โ๏ธ: +251923167274
โ๏ธ: info@bunabyte.com
#BBJST@bunabytecs
Buna Byte Junior Security Tester Course Batch 04 is coming....๐จโ๐ป๐ฉโ๐ปA
R
E
Y
O
U
R
E
A
D
Y
โ
๐: bunabyte.com
โ๏ธ: +251923167274
โ๏ธ: info@bunabyte.com
#BBJST@bunabytecs
๐ฅ8๐คฉ2
THE LONG AWAITED ANNOUNCEMENT IS HERE ๐ฅ
โThe most intensive Cybersecurity training in Ethiopia BBJST Batch 04 is officially open for registration. ๐ก๐ป
โYouโve been asking for it. Now itโs here. This is your chance to stop being a spectator and start becoming a Junior Security Tester.
โWhy now?
โ High-demand skill set
โ Practical, lab-based learning
โ Limited seats for maximum focus
โStop waiting for the "perfect time." The perfect time is now.
โ๐ REGISTER BEFORE SLOTS FILL UP: ๐ bunabyte.com/bbjst
@bunabytecs
โThe most intensive Cybersecurity training in Ethiopia BBJST Batch 04 is officially open for registration. ๐ก๐ป
โYouโve been asking for it. Now itโs here. This is your chance to stop being a spectator and start becoming a Junior Security Tester.
โWhy now?
โ High-demand skill set
โ Practical, lab-based learning
โ Limited seats for maximum focus
โStop waiting for the "perfect time." The perfect time is now.
โ๐ REGISTER BEFORE SLOTS FILL UP: ๐ bunabyte.com/bbjst
@bunabytecs
โค10๐ฅ4โก1
๐ฃ The BBJST program is crafted for individuals with a passion for technology and security but who lack formal experience.
We strip away the complexity and focus on actionable, real-world skills used by penetration testers every day.
Register here: bunabyte.com/bbjst
#BBJST@bunabytecs
We strip away the complexity and focus on actionable, real-world skills used by penetration testers every day.
Register here: bunabyte.com/bbjst
#BBJST@bunabytecs
๐ฅ6โค2๐2
๐ชซSlides donโt make security testers.
Practice does.
Learn cybersecurity the right way.
๐ bunabyte.com/bbjst
Practice does.
BBJST focuses on hands-on labs, real-world attack scenarios, and beginner-friendly guidance to help you build actual security skills, not just knowledge.
Learn cybersecurity the right way.
๐ bunabyte.com/bbjst
โก6๐ฅ3โค1๐ฏ1
Who Should Join BBJST? ๐ค
โ Absolute beginners
โ IT students
โ Career switchers
โ Curious ethical hackers
Learn cybersecurity the right way.
๐ bunabyte.com/bbjst
โ Absolute beginners
โ IT students
โ Career switchers
โ Curious ethical hackers
Learn cybersecurity the right way.
๐ bunabyte.com/bbjst
โค7๐1
Only 3๏ธโฃ Days Left! Donโt Miss Out!
โก
Become a Buna Byte Junior Security Tester and kickstart your cybersecurity journey. ๐
What youโll get:
๐ก Hands-on hacking experience
๐ก Insider tips from industry pros
๐ก Certificate that stands out
Time is running outโฐ
Registration closes in just 3 DAYS!
Secure your spot now before itโs too late limited seats available.
โ Donโt be the one who hears about it laterโฆ be the one who gets ahead today.
https://bunabyte.com/bbjst
@bunabytecs
โก
Become a Buna Byte Junior Security Tester and kickstart your cybersecurity journey. ๐
What youโll get:
๐ก Hands-on hacking experience
๐ก Insider tips from industry pros
๐ก Certificate that stands out
Time is running outโฐ
Registration closes in just 3 DAYS!
Secure your spot now before itโs too late limited seats available.
โ Donโt be the one who hears about it laterโฆ be the one who gets ahead today.
https://bunabyte.com/bbjst
@bunabytecs
๐ฅ4โคโ๐ฅ3โค1
Only 2๏ธโฃ DAYS LEFT
BunaByte Junior Security Tester (BBJST) Registration is about to close ๐
Gain skills in:
โ Ethical Hacking & Cybersecurity Basics
โ Linux & Windows for Hackers
โ Network Security & Cryptography
โ Web & System Hacking
โ Social Engineering Defense
https://bunabyte.com/bbjst
@bunabytecs
BunaByte Junior Security Tester (BBJST) Registration is about to close ๐
Gain skills in:
โ Ethical Hacking & Cybersecurity Basics
โ Linux & Windows for Hackers
โ Network Security & Cryptography
โ Web & System Hacking
โ Social Engineering Defense
https://bunabyte.com/bbjst
@bunabytecs
๐5โคโ๐ฅ3๐ฅ1
ONLY 1โฃ DAY LEFT ALERT!โฐ
Registration for BunaByte Junior Security Tester (BBJST) closes tomorrow โณ
Do you know? ๐
โก๏ธ Cybersecurity experts and Bug Bounty Hunters are some of the most in-demand and highly paid tech professionals today.
โก๏ธ Companies worldwide are desperate for skilled testers who can secure their systems.
This is YOUR chance to step in.๐
https://bunabyte.com/bbjst
@bunabytecs
Registration for BunaByte Junior Security Tester (BBJST) closes tomorrow โณ
Do you know? ๐
โก๏ธ Cybersecurity experts and Bug Bounty Hunters are some of the most in-demand and highly paid tech professionals today.
โก๏ธ Companies worldwide are desperate for skilled testers who can secure their systems.
This is YOUR chance to step in.๐
https://bunabyte.com/bbjst
@bunabytecs
๐4โค3๐ฅ1