SQL Injection
How unsanitized SQL concatenates — parameterized queries as the fix. No live SQLi against others.
1. Why String-Built SQL Breaks
The query becomes attacker-controlled text. Mechanism, not a cheat sheet of unions.
15 min
+40 XP
2. Blind vs In-band as Defender Literacy
Enough to read a report; Topic 10 goes deeper in Cyberlium labs.
15 min
+40 XP
3. Parameterized Queries and Least Privilege DB
The actual fix. ORM pitfalls.
15 min
+40 XP
4. Lab — Rewrite a Unsafe Query You Wrote
Take a fictional concatenating snippet and write a parameterized version.
25 min
+40 XP
5. Quiz — SQL Injection
10 APPLY questions on mechanism and parameterized queries.
10 min
+40 XP