SQL Injection (Detailed)
SQL Injection (Detailed) is a SQL statement in the SELECT Queries category. SQL injection can lead to data theft, data destruction, or privilege escalation. Always use parameterized queries. The syntax is -- SQL injection: an attack where malicious SQL is inserted into query strings through user input.. It returns security detail. A typical example: -- Classic injection: -- Query: SELECT * FROM users WHERE username = '{input}' AND password = '{input2}' -- Input: ' OR '1'='1 -- Result: SELECT * FROM users WHERE username = '' OR '1'='1' -- Always returns users! -- Second-order injection: -- Input stored in DB, later used unsafely in another query -- Blind injection: -- Attacker infers data from true/false responses -- ' AND SUBSTRING(password,1,1) = 'a' -- --… A close relative is SELECT, which retrieves data from a table. The most fundamental SQL statement. A close relative is SELECT *, which selects all columns from a table.