Web Security / Injection
Lesson 7 of 27
SQL injection
If a site glues input into a SQL query with string formatting, an attacker can change what the query does. Parameterised queries make input always count as data.
Key points
- Never build SQL with f-strings or +
- Use ? or %s placeholders
- ORMs parameterise for you
# Unsafe: f"SELECT * FROM users WHERE name = '{name}'"
# Safe:
db.execute("SELECT * FROM users WHERE name = ?", (name,))Quiz · +10 XP
Which is the proper defence against SQL injection?
Log in to save progress and earn XP.