Case 308B89 · Web AppSec · L1 Foundations
SQL Injection
Practise as: Explain it · Interview
Interview questionWalk me through how SQL injection works and how you would prevent it in a modern codebase.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- User input concatenated into a query string changes the query structure, e.g. ' OR 1=1-- bypasses a login check
- Variants: in-band (UNION, error-based), blind (boolean/time-based via SLEEP), and out-of-band (DNS/HTTP callbacks)
- Primary fix: parameterized queries / prepared statements so input is bound as data, never parsed as SQL
- ORMs help but raw fragments (ORDER BY, table names) still need allowlisting since they cannot be parameterized
- Defense in depth: least-privilege DB accounts, no stacked queries, WAF as a speed bump, not a fix
If the interviewer pushes back
- Why can you not parameterize an ORDER BY column, and how do you handle it safely?
- How does second-order SQL injection bypass input validation done at write time?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.