Skip to main content

SQL Injection - How Attackers Exploit Databases

About 2 min read

SQL injection (SQL Injection) is an attack technique that inserts malicious SQL statements into the input forms of a web application to manipulate the database illicitly. It is an extremely dangerous vulnerability that can lead to bypassing authentication, stealing, tampering with, or deleting data, and even seizing control of the server. It has ranked near the top of the OWASP Top 10 for many years, and in 2024 injection attacks remain positioned as a major threat category.

Why Inspecting the Input Does Not Close It

The cause of this vulnerability is not that dangerous symbols appear in the text someone typed, but that a path remains where a value received from outside is interpreted as part of a command. Placing the cause there changes the direction of the response as well. Stripping symbols regarded as dangerous, or rejecting input that contains particular words, turns the work into maintaining a list of what has to be caught. Yet what belongs on that list varies with the kind of database in use and with how the statement is written, and the same meaning can sometimes be expressed a different way. Meanwhile, input containing symbols arises in ordinary business use too. Symbols appear in names, in addresses and in search terms, so widening the range of rejection blocks legitimate input, while narrowing it leaves room to pass through. The adjustment cannot settle at either end, and a judgement about where to place the boundary keeps having to be made. Replacing the mechanism with one that never hands the value over as part of a command, and can only treat it as a value, removes the need for that boundary judgement altogether. The other thing that causes difficulty in practice is the unit of repair. When it is confirmed on one screen, the same way of assembling the statement is often lined up on other screens as well, because the style written for one feature is referred to when a similar feature is built. Repairing the screen that was found therefore leaves every path where the same style remains in the same condition. What should be counted is not the number of screens pointed out, but how many styles of assembling the value exist and in how many places each of them is used.

The SQL Injection Flow

Enter malicious SQL
The server executes the SQL
Data is illicitly retrieved from the DB
Information leakage / tampering

How the Attack Works

Programs that embed user input directly into SQL statements become targets of attack. For example, by entering "' OR 1=1 --" into a login form, an attacker can bypass authentication, or use a UNION clause to retrieve data from other tables. With blind SQL injection, even when no error message is displayed, data can be inferred from differences in true/false responses.

Concrete Damage Scenarios

A common misconception is that "SQL injection is an old attack technique that does not happen in modern systems." In reality, code that builds SQL through string concatenation without using parameterized queries is still found, even in the modernization of legacy systems and in new development. In 2024 as well, there were reported cases of millions of customer records being leaked from the databases of major companies through SQL injection. Because attackers use automated tools (such as sqlmap) to efficiently scan for vulnerable sites, even small sites become targets.

Preparation as a User

SQL injection is a server-side vulnerability, but users also need to be prepared. If you set a unique, random password for each service, then even if a data breach occurs at one service, your other accounts remain safe. If a service you use announces a data breach, change your password promptly.

Related Terms

Was this article helpful?