SQL Injection
SQL Injection
INFORMATION
SECURITY
Fundamentals
Open
SQL
source: https://www.navicat.com/en/products/navicat-for-sqlserver
Open
SQL
source: https://www.navicat.com/en/products/navicat-for-sqlserver
Open
Open
SQL INJECTION
A successful SQL injection exploit can read sensitive data from the
database, modify database data (Insert/Update/Delete), execute
administration operations on the database…
Open
SQL INJECTION
username_x SELECT *
FROM users
WHERE username = ‘username_x’
password_x AND password = ‘password_x’
Open
SQL INJECTION
‘ OR ‘1’=‘1 SELECT *
FROM users
WHERE username = ‘’ OR ‘1’=‘1’
123 AND password = 123
Open
INFORMATION
SECURITY
Fundamentals