Lazo Lab Sign up

Web Security / Injection

Lesson 7 of 27

SQL injection

If a site glues input into a SQL query with string formatting, an attacker can change what the query does. Parameterised queries make input always count as data.

Key points

  • Never build SQL with f-strings or +
  • Use ? or %s placeholders
  • ORMs parameterise for you
# Unsafe:  f"SELECT * FROM users WHERE name = '{name}'"
# Safe:
db.execute("SELECT * FROM users WHERE name = ?", (name,))
Watch a video on thisOpens YouTube search results for “SQL injection” in a new tab

Quiz · +10 XP

Which is the proper defence against SQL injection?

Log in to save progress and earn XP.