Overview
SQL injection happens when untrusted input reaches a SQL statement without being parameterised.
An attacker can rewrite the query logic to dump tables, bypass login screens or, on poorly configured servers, execute operating-system commands.
It remains in the OWASP Top 10 because it is trivial to introduce and devastating when it lands.
Indicators of Compromise
Signals that suggest this is present on a system.
- Error messages leaking SQL syntax
- Unexpected response times on parameter changes
- Rows returned that the UI never requests
Controls that stop it
-
Use Parameterised Queries
Never build SQL by concatenating input. Use prepared statements with bound parameters so the driver treats data as data, never as query structure. This single change eliminates SQL injection and a large share of related injection classes, and it is the default in every modern ORM and database abstraction layer.