Skip to content · ⁨본문 바로가기⁩

SQL injection · ⁨SQL 주입攻击(SQL injection)⁩

English

When input becomes a command

  • Many apps build a database query by gluing the user's input into a string. That is dangerous.
  • If an attacker types SQL as their input, it can become part of the query. This is SQL injection — the most famous web attack.

한국어

입력이 명령어로 변환될 때

  • Many apps build a database query by gluing the user's input into a string. That is dangerous.
  • If an attacker types SQL as their input, it can become part of the query. This is SQL injection — the most famous web attack.

Malicious input OR 1=1 turns the WHERE clause always-true, leaking every row

Log in or create account · ⁨로그인 또는 계정 만들기⁩

IGCSE, A-Level & AP