Suggest an editImprove this articleRefine the answer for “What is SQL Injection?”. Your changes go to moderation before they’re published.Approval requiredContentWhat you’re changing🇺🇸EN🇺🇦UAPreviewTitle (EN)Short answer (EN)**SQL Injection** is an attack on a web application in which the attacker inserts malicious SQL code into input data to trick a database query. **Key point:** user input must never be inserted directly into a SQL query - the main defense is prepared statements.Shown above the full answer for quick recall.Answer (EN)Image**SQL Injection** is an attack on a web application in which the attacker **inserts malicious SQL code into input data** to **trick a database query**. In simple terms: *the application expects ordinary input (a login, a password, a search) but receives a SQL command and executes it.* --- ## How SQL Injection works in simple terms An application usually builds a SQL query roughly like this: ``` SELECT * FROM users WHERE login = 'user' AND password = 'pass'; ``` If the application **does not validate the input**, the attacker can enter: ``` ' OR 1=1 -- ``` As a result, the query turns into: ``` SELECT * FROM users WHERE login = '' OR 1=1 --'; ``` `1=1` is always true, so the database returns every record and the login succeeds without a password. --- ## What the attacker can do With SQL Injection, an attacker can: - bypass authentication; - read data from the database (passwords, personal data); - modify or delete data; - gain full control over the database; - sometimes execute commands on the server. This is **one of the most dangerous L7 attacks**. --- ## Where SQL Injection occurs - login forms; - search forms; - URL parameters; - API requests; - anywhere user input ends up in a SQL query. --- ## Which security properties are violated - **Confidentiality** - data leaks; - **Integrity** - data spoofing or deletion; - sometimes **Availability** - dropping tables or the database. --- ## Types of SQL Injection (briefly) - **Classic SQLi**, where the result is visible right away; - **Blind SQLi**, where the result is inferred indirectly (true/false, delays); - **Union-based SQLi**, combining queries (`UNION`); - **Error-based SQLi**, exploiting database errors. --- ## Why SQL Injection still exists - lack of input validation; - dynamically building SQL queries; - outdated or insecure code; - absence of secure development practices. --- ## How to defend against SQL Injection ### Main defense measures: - **prepared statements / parameterized queries** (the main one); - validating and filtering input data; - minimal privileges for the database user; - WAF; - updating applications and frameworks. **Never insert user input directly into a SQL query.**For the reviewerNote to the moderator (optional)Visible only to the moderator. Helps review go faster.