SQL Injection
ExplainedConcept
Also known as: SQLi
An attack that injects malicious SQL through input fields to manipulate the database.
SQL Injection, explained
Written by EduVerseWhat it is
SQL injection is a security risk that appears when user input is pasted straight into a SQL query as text. The database can’t tell the query you intended apart from what the user typed, so carefully chosen input can change what the query does.
Why teams use it
A successful injection can let an attacker read data they shouldn’t see, change or delete records, or skip a login check. The standard defence is parameterised queries (prepared statements), where the input travels separately from the SQL and is treated only as data. Most ORMs do this for you.
An example from work
In an older part of the codebase you spot a query that glues the search term from a form directly into the SQL string. A static analysis tool in the pipeline flags it, and you rewrite it to use a placeholder (such as ? or $1) with the value passed as a parameter.
Our own explanation, not a quote from the book.
Where it fits
Web security, input validation, parameterised queries
Coverage in the book
Explained and compared with alternatives, so you know where and why it’s used.