SECURITY / A CONCEPT NOTE

Injection Attacks

when input becomes code

~65 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

An attack where malicious input strings are interpreted as system commands (SQL, Shell, HTML). Input sanitization and parameterized queries keep input separated from executable commands.

02 / FOLLOW THE MECHANISM

How injection executions occur

  1. User Input

    attacker types: 1' OR '1'='1 into a search bar.

  2. App query

    application concatenates strings to run sql database commands.

  3. Execution

    database engine interprets input OR '1'='1 as instructions, returning all tables.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

test endpoints for SQL injection vulnerabilities

sqlmap -u \"https://example.com/item?id=1\"

Explore command anatomy in the CLI lab