Tools / Cyber Security Interview Questions
What is SQL Injection?
SQL injection is an attack where malicious SQL code is inserted into an input field so it gets executed by the backend database, usually because user input is concatenated directly into a query instead of being treated as data.
-- Vulnerable query SELECT * FROM users WHERE username = '" + userInput + "'; -- Malicious input ' OR '1'='1
The input above turns the query into one that always evaluates true, potentially returning every row in the users table or bypassing a login check entirely.
Parameterized queries and prepared statements are the standard fix, since they keep user input separate from the SQL command structure.
More Related questions...