Open cardosec

Case 308B89 · Web AppSec · L1 Foundations

SQL Injection

Practise as: Explain it · Interview

Interview questionWalk me through how SQL injection works and how you would prevent it in a modern codebase.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. User input concatenated into a query string changes the query structure, e.g. ' OR 1=1-- bypasses a login check
  2. Variants: in-band (UNION, error-based), blind (boolean/time-based via SLEEP), and out-of-band (DNS/HTTP callbacks)
  3. Primary fix: parameterized queries / prepared statements so input is bound as data, never parsed as SQL
  4. ORMs help but raw fragments (ORDER BY, table names) still need allowlisting since they cannot be parameterized
  5. Defense in depth: least-privilege DB accounts, no stacked queries, WAF as a speed bump, not a fix

If the interviewer pushes back

  • Why can you not parameterize an ORDER BY column, and how do you handle it safely?
  • How does second-order SQL injection bypass input validation done at write time?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.