DFIELDSOLUTIONS

Security

GlossarySQL injection

Smuggling database commands through input fields — the attack that turns 'name' into 'show me every user's password hash'.

When a query is built by concatenating strings, user input stops being data and becomes code: ' OR '1'='1 in a login field, a UNION SELECT in a search box. One of the oldest web vulnerabilities and still on every top-ten list because it keeps paying — full database read, sometimes write.

The fix is boring and total: parameterized queries, where the driver keeps data and code on separate channels. ORMs do it by default; the holes appear in the one hand-written query that 'just needed a dynamic table name'.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain