SQL Injection (SQLi)
SQL injection occurs when untrusted input changes the meaning of a database query instead of being treated strictly as data.
Mechanism
The application builds a database statement from user-controlled input without safe parameterization or equivalent controls. The resulting query can alter reads, writes, authentication logic, or errors returned to the user.
Indicators to watch
Look for database errors, unusual query patterns, repeated malformed requests, unexpected data access, abnormal response sizes, and application logs showing rejected or anomalous parameters.
Concept diagram
Defensive controls
Use parameterized queries/prepared statements, safe ORM patterns, allow-list validation, least-privileged database accounts, secrets protection, WAF rules, and security testing in authorized environments.
Recommended security control
Parameterized queries + WAF
Keep demonstrations inside a deliberately vulnerable local lab; do not test third-party systems.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.