Sql injunction SQL Injection (SQLi) SQL Injection is a web application vulnerability that occurs when an attacker inserts malicious SQL code into an input field, URL parameter, or request to manipulate a database. For example, an attacker may use SQL injection to: Bypass a login page. View sensitive database information. Modify or delete records. Access information they aren't authorized to see. 1. Simple example Imagine a website login form: Login page Username Enter username Password Enter password This is a demonstration form, not a real login. A vulnerable application might build a database query like this: SELECT * FROM users WHERE username = 'admin' AND password = '1234'; If the application directly joins user input into the SQL statement, an attacker may be able to change what the query does. 2. Types of SQL Injection 1. In-band SQL Injection The attacker uses the same communication channel to send the injection and receive database results. Error-based: Uses database error messages to learn about the database. UNION-based: Uses UNION to combine results from another query. 2. Blind SQL Injection The application doesn't directly display database results, so the attacker infers information from the application's behavior. Boolean-based: Checks whether a condition produces a true or false response. Time-based: Checks whether a condition causes a measurable delay. 3. Out-of-band SQL Injection The database sends information through a separate channel, such as a network request, when the database and environment support it. 3. Example of UNION-based SQLi A normal query might be: SELECT name, price FROM products WHERE id = 1; A UNION-based injection attempts to append results from another SELECT statement. For it to work, the two queries generally need compatible column counts and data types. 4. How to prevent SQL Injection Parameterized queries: Keep SQL instructions separate from user input. Input validation: Check that input matches the expected format. Least privilege: Give database accounts only the permissions they need. Safe error handling: Don't expose detailed database errors to users. Avoid dynamic SQL: Don't construct queries by concatenating untrusted input. Example of a safer query in Python: cursor.execute( "SELECT * FROM users WHERE username = %s", (username,) )
Sql injunction SQL Injection (SQLi) SQL Injection is a web application vulnerability that occurs when an attacker inserts malicious SQL code into an input field, URL parameter, or request to manipulate a database. For example, an attacker may use SQL injection to: Bypass a login page. View sensitive database information. Modify or delete records. Access information they aren't authorized to see. 1. Simple example Imagine a website login form: Login page Username Enter username Password Enter password This is a demonstration form, not a real login. A vulnerable application might build a database query like this: SELECT * FROM users WHERE username = 'admin' AND password = '1234'; If the application directly joins user input into the SQL statement, an attacker may be able to change what the query does. 2. Types of SQL Injection 1. In-band SQL Injection The attacker uses the same communication channel to send the injection and receive database results. Error-based: Uses database error messages to learn about the database. UNION-based: Uses UNION to combine results from another query. 2. Blind SQL Injection The application doesn't directly display database results, so the attacker infers information from the application's behavior. Boolean-based: Checks whether a condition produces a true or false response. Time-based: Checks whether a condition causes a measurable delay. 3. Out-of-band SQL Injection The database sends information through a separate channel, such as a network request, when the database and environment support it. 3. Example of UNION-based SQLi A normal query might be: SELECT name, price FROM products WHERE id = 1; A UNION-based injection attempts to append results from another SELECT statement. For it to work, the two queries generally need compatible column counts and data types. 4. How to prevent SQL Injection Parameterized queries: Keep SQL instructions separate from user input. Input validation: Check that input matches the expected format. Least privilege: Give database accounts only the permissions they need. Safe error handling: Don't expose detailed database errors to users. Avoid dynamic SQL: Don't construct queries by concatenating untrusted input. Example of a safer query in Python: cursor.execute( "SELECT * FROM users WHERE username = %s", (username,) )
Created using ChatSlide
SQL Injection (SQLi) poses significant risks, allowing attackers to bypass logins and expose sensitive data. Understanding how SQLi operates, including in-band, blind, and out-of-band methods, is crucial. By comparing vulnerable and secure queries, one can illustrate the dangers of UNION-based manipulations. To effectively prevent SQLi, it is essential to implement parameterised queries, validate inputs, and enforce least privilege access. Regular testing and monitoring are vital to mitigate...