DAY 3 · MODULE 6

SQL Injection & Database Security

Understand why unsafe query construction is dangerous and how parameterized queries separate code from data.

65 minSecure-query exerciseIn Progress
01 · LEARN

Understand the concept

SELECT / INSERT / UPDATE / DELETE
WHERE clauses
User input
Unsafe string building
Parameterized queries
Prepared statements
Least privilege
Why this matters

Secure database access prevents user-controlled data from changing the intended query structure.

02 · VISUALIZE

See what happens internally

Interactive visualization loads here.
03 · PRACTICAL

Perform the activity

  1. Trace input through a query visualizer.
  2. Compare unsafe string concatenation with a prepared statement.
  3. Review a deliberately vulnerable local example only in the approved lab.
  4. Rewrite the example using parameters.
Workshop safety: Activities involving scanning, web vulnerabilities or security testing must be performed only on the assigned training target or intentionally vulnerable lab.
04 · CODE / COMMANDS

Read and understand the working example

Unsafe concept:
query = "..." + user_input

Secure concept:
prepare("SELECT ... WHERE username = ?")

This example is shown for guided learning. Real host/network execution is reserved for the isolated cyber-range stage.

05 · CHALLENGE

Prove your understanding

Convert an unsafe training query into a parameterized query and explain why the new version is safer.

Login to Save Progress