Understanding SQL / command injection
What it is
Injection is untrusted input reaching an interpreter as code rather than as data. When a value you supply is concatenated into a SQL query or a shell command, characters that mean something to that interpreter let you change what it does — read tables you should not, or run commands the app never intended.
How you approach it
- Feed the input a character that is special to a query — a quote, a semicolon. Does the error, or the change in behaviour, tell you it reached the interpreter raw?
- Once you are in the syntax, you decide what runs. For SQL, a UNION or a boolean condition; for a shell, a separator and a second command.
- The flag lives in a table or a file the intended query never touches. Redirect the query to read it.
How it gets fixed
Input was concatenated into the interpreter instead of being passed as a bound parameter, so crafted syntax changed the statement itself. That let the query — or the command — reach data outside its intended scope, where the flag sat. The fix is parameterised queries and never building a command line from user input.
Practise it
Every lab in the SQL / command injection category drills exactly this. Start at Apprentice and work up.