SQL Injection: How It Works, How It Is Automated, and How to Stop It
SQL injection happens when user-supplied input is concatenated into a database query instead of being passed as data. The database cannot tell the difference between the query the developer wrote and the fragment the attacker appended, because by the time it arrives they are the same string. Decades after it was first documented it is still a leading cause of breaches, and it still appears on every security certification. The root cause in one line Building a query by string concatenation mixes code and data in the same channel. Input intended as a value — a username, a product ID — becomes part of the query's structure the moment it contains SQL syntax the parser will honor. Everything else about the vulnerability follows from that. The attack payloads vary by database and context, but the defect is always the same: the boundary between instruction and input was never established. The categories In-band injection returns results through the same channel used to atta...