0% found this document useful (0 votes)
6 views10 pages

Understanding SQL Injection Risks

Uploaded by

hackhubadi3
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views10 pages

Understanding SQL Injection Risks

Uploaded by

hackhubadi3
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

 Tutorials  References  Exercises  Get Certified

ML  CSS JAVASCRIPT SQL PYTHON JAVA PHP HOW TO [Link] C C++

SQL Injection
❮ Previous Next ❯

SQL Injection
SQL injection is a code injection technique that might destroy your database.

SQL injection is one of the most common web hacking techniques.

SQL injection is the placement of malicious code in SQL statements, via web page input.

SQL in Web Pages


SQL injection usually occurs when you ask a user for input, like their username/userid, and
instead of a name/id, the user gives you an SQL statement that you will unknowingly run on
your database.

Look at the following example which creates a SELECT statement by adding a variable
(txtUserId) to a select string. The variable is fetched from user input (getRequestString):
 Tutorials 
Example
References  Exercises  Get Certified
Get your own SQL Server

ML  CSS JAVASCRIPT SQL PYTHON JAVA PHP HOW TO [Link] C C++


txtUserId = getRequestString("UserId");
txtSQL = "SELECT * FROM Users WHERE UserId = " + txtUserId;

The rest of this chapter describes the potential dangers of using user input in SQL statements.

SQL Injection Based on 1=1 is Always True


Look at the example above again. The original purpose of the code was to create an SQL
statement to select a user, with a given user id.

If there is nothing to prevent a user from entering "wrong" input, the user can enter some
"smart" input like this:

UserId: 105 OR 1=1

Then, the SQL statement will look like this:

SELECT * FROM Users WHERE UserId = 105 OR 1=1;

The SQL above is valid and will return ALL rows from the "Users" table, since OR 1=1 is always
TRUE.

Does the example above look dangerous? What if the "Users" table contains names and
passwords?

The SQL statement above is much the same as this:

SELECT UserId, Name, Password FROM Users WHERE UserId = 105 or 1=1;
A hacker might get access to all the user names and passwords in a database, by simply
 Tutorials  References  Exercises 
inserting 105 OR 1=1 into the input field. Get Certified

ML  CSS JAVASCRIPT SQL PYTHON JAVA PHP HOW TO [Link] C C++

REMOVE ADS

SQL Injection Based on ""="" is Always True


Here is an example of a user login on a web site:

Username:

John Doe

Password:

myPass

Example

uName = getRequestString("username");
uPass = getRequestString("userpassword");

sql = 'SELECT * FROM Users WHERE Name ="' + uName + '" AND Pass ="' +
uPass + '"'

Result

SELECT * FROM Users WHERE Name ="John Doe" AND Pass ="myPass"

A hacker might get access to user names and passwords in a database by simply inserting "
OR ""=" into the user name or password text box:
User Name:
 " or ""="
Tutorials  References  Exercises  Get Certified

ML  CSS JAVASCRIPT SQL PYTHON JAVA PHP HOW TO [Link] C C++


Password:

" or ""="

The code at the server will create a valid SQL statement like this:

Result

SELECT * FROM Users WHERE Name ="" or ""="" AND Pass ="" or ""=""

The SQL above is valid and will return all rows from the "Users" table, since OR ""="" is always
TRUE.

SQL Injection Based on Batched SQL


Statements
Most databases support batched SQL statement.

A batch of SQL statements is a group of two or more SQL statements, separated by


semicolons.

The SQL statement below will return all rows from the "Users" table, then delete the "Suppliers"
table.

Example

SELECT * FROM Users; DROP TABLE Suppliers

Look at the following example:


 Tutorials 
Example
References  Exercises  Get Certified

ML  CSS JAVASCRIPT SQL PYTHON JAVA PHP HOW TO [Link] C C++


txtUserId = getRequestString("UserId");
txtSQL = "SELECT * FROM Users WHERE UserId = " + txtUserId;

And the following input:

User id: 105; DROP TABLE Suppliers

The valid SQL statement would look like this:

Result

SELECT * FROM Users WHERE UserId = 105; DROP TABLE Suppliers;

Use SQL Parameters for Protection


To protect a web site from SQL injection, you can use SQL parameters.

SQL parameters are values that are added to an SQL query at execution time, in a controlled
manner.

[Link] Razor Example

txtUserId = getRequestString("UserId");
txtSQL = "SELECT * FROM Users WHERE UserId = @0";
[Link](txtSQL,txtUserId);

Note that parameters are represented in the SQL statement by a @ marker.

The SQL engine checks each parameter to ensure that it is correct for its column and are
treated literally, and not as part of the SQL to be executed.
 Tutorials 
Another Example
References  Exercises  Get Certified

ML  CSS JAVASCRIPT SQL PYTHON JAVA PHP HOW TO [Link] C C++


txtNam = getRequestString("CustomerName");
txtAdd = getRequestString("Address");
txtCit = getRequestString("City");
txtSQL = "INSERT INTO Customers (CustomerName,Address,City)
Values(@0,@1,@2)";
[Link](txtSQL,txtNam,txtAdd,txtCit);

Examples
The following examples shows how to build parameterized queries in some common web
languages.

SELECT STATEMENT IN [Link]:

txtUserId = getRequestString("UserId");
sql = "SELECT * FROM Customers WHERE CustomerId = @0";
command = new SqlCommand(sql);
[Link]("@0",txtUserId);
[Link]();

INSERT INTO STATEMENT IN [Link]:

txtNam = getRequestString("CustomerName");
txtAdd = getRequestString("Address");
txtCit = getRequestString("City");
txtSQL = "INSERT INTO Customers (CustomerName,Address,City)
Values(@0,@1,@2)";
command = new SqlCommand(txtSQL);
[Link]("@0",txtNam);
[Link]("@1",txtAdd);
[Link]("@2",txtCit);
 Tutorials  References 
[Link](); Exercises  Get Certified

ML  CSS JAVASCRIPT SQL PYTHON JAVA PHP HOW TO [Link] C C++

INSERT INTO STATEMENT IN PHP:

$stmt = $dbh->prepare("INSERT INTO Customers


(CustomerName,Address,City)
VALUES (:nam, :add, :cit)");
$stmt->bindParam(':nam', $txtNam);
$stmt->bindParam(':add', $txtAdd);
$stmt->bindParam(':cit', $txtCit);
$stmt->execute();

?
Exercise
What is SQL injection?

A technique to optimize SQL queries

A code injection technique to access or destroy a database

A method to protect SQL queries from being hacked

A debugging process for SQL queries

Submit Answer »

❮ Previous Next ❯
XP 0 • 🔥 1 day
 Tutorials  References  Exercises  Get Certified

ML  CSS JAVASCRIPT SQL PYTHON JAVA PHP HOW TO [Link] C C++

COLOR PICKER

 

REMOVE ADS

 PLUS SPACES
 Tutorials  References 
GET CERTIFIED
Exercises 
FOR TEACHERS
Get Certified

ML  CSS JAVASCRIPT SQL PYTHON JAVA PHP HOW TO [Link] C C++

FOR BUSINESS CONTACT US

Top Tutorials
HTML Tutorial
CSS Tutorial
JavaScript Tutorial
How To Tutorial
SQL Tutorial
Python Tutorial
[Link] Tutorial
Bootstrap Tutorial
PHP Tutorial
Java Tutorial
C++ Tutorial
jQuery Tutorial

Top References
HTML Reference
CSS Reference
JavaScript Reference
SQL Reference
Python Reference
[Link] Reference
Bootstrap Reference
PHP Reference
HTML Colors
Java Reference
AngularJS Reference
jQuery Reference

Top Examples Get Certified


HTML Examples HTML Certificate
CSS Examples CSS Certificate
JavaScript Examples JavaScript Certificate
How To Examples Front End Certificate
SQL Examples SQL Certificate
Python Examples Python Certificate
[Link] Examples PHP Certificate
Bootstrap Examples jQuery Certificate
PHP Examples Java Certificate
Java Examples C++ Certificate
XML Examples C# Certificate
jQuery Examples XML Certificate

    
 Tutorials  References 
FORUM ABOUT
Exercises 
ACADEMY
Get Certified
W3Schools is optimized for learning and training. Examples might be simplified to improve reading and
learning.
ML  CSS JAVASCRIPT
Tutorials, SQL
references, and PYTHON
examples JAVA to avoid
are constantly reviewed PHP errors,HOW
but weTO [Link]
cannot warrant full C C++
correctness
of all content. While using W3Schools, you agree to have read and accepted our terms of use, cookies and
privacy policy.

Copyright 1999-2025 by Refsnes Data. All Rights Reserved. W3Schools is Powered by [Link].

You might also like