DAY 3 · MODULE 6
SQL Injection & Database Security
Understand why unsafe query construction is dangerous and how parameterized queries separate code from data.
Understand the concept
SELECT / INSERT / UPDATE / DELETE
WHERE clauses
User input
Unsafe string building
Parameterized queries
Prepared statements
Least privilege
Why this matters
Secure database access prevents user-controlled data from changing the intended query structure.
See what happens internally
Interactive visualization loads here.
Perform the activity
- Trace input through a query visualizer.
- Compare unsafe string concatenation with a prepared statement.
- Review a deliberately vulnerable local example only in the approved lab.
- Rewrite the example using parameters.
Workshop safety: Activities involving scanning, web vulnerabilities or security testing must be performed only on the assigned training target or intentionally vulnerable lab.
Read and understand the working example
Unsafe concept:
query = "..." + user_input
Secure concept:
prepare("SELECT ... WHERE username = ?")This example is shown for guided learning. Real host/network execution is reserved for the isolated cyber-range stage.
Prove your understanding
Convert an unsafe training query into a parameterized query and explain why the new version is safer.