CyberNotes
CN-002RESTRICTED

What Is SQL Injection?

How untrusted input becomes a database command, and how to stop it.

What Is SQL Injection?

SQL injection happens when user input is concatenated directly into a database query instead of being treated as pure data. If an application builds a query like SELECT * FROM users WHERE name = ' + input + ', an attacker can supply input that changes the query's meaning entirely.

Why it still happens

Despite being decades old, SQLi persists because string-concatenated queries are the "obvious" way to write one, especially in legacy code.

Detection

Web application firewalls can catch common patterns, but the more reliable signal is application-layer logging: unexpected quote characters, UNION, or -- sequences in fields that should just be names or emails.

Prevention

Parameterized queries (prepared statements) are the fix: the database treats input strictly as data, never as part of the query structure, regardless of what characters it contains.

← Back to topic hub