0 / 4
SQL Injection
A value typed on the web page goes to the API server (backend). The API server uses it to build an SQL query and sends the query to the database (DB). If the query is built by string concatenation, SQL in the input is read as part of the query instead of as a value. SQL injection exploits this to change the structure of the query.
Example: see how a normal name is handled. You can pick another input above.
1 / 4
Web page: type a name
A user types alice into the name field on the web page. It contains only ordinary characters.
2 / 4
API server: build the query
The API server (backend) appends the input from the web page between the fixed parts of the query. The input sits inside the single quotes.
3 / 4
API server → DB: send the query
The API server sends the finished query to the DB as one statement. It does not tell the DB where the query ends and the input begins.
4 / 4
DB: run the query
The DB reads the query. Inside the quotes, alice is a value, so it finds only the one member named alice.
1 / 4
Web page: type malicious SQL
An attacker types ' OR '1'='1 into the name field instead of a name. It closes the name slot in the query with a quote and adds an always-true condition.
2 / 4
API server: build the query
The API server does not check what the web page sent and appends it as it is. So the quote and the OR condition in the input become part of the query.
3 / 4
API server → DB: send the query
The API server sends the query to the DB. Its condition is already name = '' OR '1'='1', which is not what the developer intended.
4 / 4
DB: run the query
The DB reads the appended condition as part of the query too. The condition '1'='1' is always true, so every member comes back regardless of the name.
1 / 4
Web page: type a name
A user types alice into the name field on the web page. The input goes to the API server as it is.
2 / 4
API server: send the template first
The API server (backend) sends the query template to the DB first. The slot for the value is left as a question mark. The DB fixes the query structure from this template.
3 / 4
API server → DB: send the value separately
Then it sends the input value separately. The DB puts this value into the question mark of the template, only as a value.
4 / 4
DB: run the query
The DB compares alice as the name value and finds one member. A normal input is handled the same way with binding.
1 / 4
Web page: type malicious SQL
An attacker types ' OR '1'='1 into the name field. The input goes to the API server as it is.
2 / 4
API server: send the template first
The API server (backend) sends the query template to the DB first. The slot for the value is left as a question mark. The DB fixes the query structure from this template.
3 / 4
API server → DB: send the value separately
Then it sends the input value separately. Even if the input contains a quote and an OR condition, it cannot get into the structure that is already fixed.
4 / 4
DB: run the query
The DB compares the whole input ' OR '1'='1 only as one string value. No member has that string as a name, so it finds none. The attack attempt does nothing.