← Web Security Foundations
ReadingLesson 4 of 5 · 10 min

Understanding injection

What it is

Injection is untrusted input reaching an interpreter as code rather than as data. When a value you supply is concatenated into a SQL query or a shell command, characters that mean something to that interpreter let you change what it does — read tables you should not, or run commands the app never intended.

How you approach it

  1. Feed the input a character that is special to a query — a quote, a semicolon. Does the error, or the change in behaviour, tell you it reached the interpreter raw?
  2. Once you are in the syntax, you decide what runs. For SQL, a UNION or a boolean condition; for a shell, a separator and a second command.
  3. The flag lives in a table or a file the intended query never touches. Redirect the query to read it.

How it gets fixed

Input was concatenated into the interpreter instead of being passed as a bound parameter, so crafted syntax changed the statement itself. That let the query — or the command — reach data outside its intended scope, where the flag sat. The fix is parameterised queries and never building a command line from user input.

Practise it

Every lab in the SQL / command injection category drills exactly this. Start at Apprentice and work up.

← Lab: your neighbour's invoice
Sign in to track thisLab: the quote that breaks the query →