NOTE

1.7 SQL Injection

Cause of SQL injection and defense with parameterized queries.

SecurityCreated Updated 1 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

1. What Is SQL Injection

A kind of web attack. SQL injection is an attack technique in which SQL code is added to input parameters and passed to the server to be parsed and executed.

2. Why SQL Injection Happens

User input is concatenated directly into an SQL statement and executed.

3. How to Prevent SQL Injection

3.1. Enable SQL Precompilation

  1. Use ? as a placeholder for parameters when writing SQL.
  2. Use Prepared Statements / parameterized APIs provided by the database driver to bind parameters instead of directly concatenating user input.

This separates the SQL structure from parameter data, so user input is passed only as data and does not continue to participate in SQL syntax parsing. The key to preventing SQL injection is parameterization, not execution-plan caching.

4. Example

4.1. Golang

sql.md

5. References

Discussion

Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub