SECURITY / A CONCEPT NOTE
Injection Attacks
when input becomes code
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
An attack where malicious input strings are interpreted as system commands (SQL, Shell, HTML). Input sanitization and parameterized queries keep input separated from executable commands.
02 / FOLLOW THE MECHANISM
How injection executions occur
User Input
attacker types: 1' OR '1'='1 into a search bar.
App query
application concatenates strings to run sql database commands.
Execution
database engine interprets input OR '1'='1 as instructions, returning all tables.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
test endpoints for SQL injection vulnerabilities
sqlmap -u \"https://example.com/item?id=1\"05 / CHECK YOURSELF
Could you explain Injection Attacks to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityEncryption Rest vs Transittwo places data leaks