Web › Module 5 › Lesson 1
SQL Injection Mechanism
A05:2025 — SQLite binds on files YOU own.
Visual · sqli_mechanism
SQL Injection: Parameterize local SQLite. Never sqlmap strangers or hydra the LAN.
Opening
The bug is mixing code and data. The fix is keeping them apart — not a UNION cheat sheet.
OWASP Top 10:2025 A05 Injection includes SQL injection: concatenating untrusted bytes into SQL lets those bytes become syntax. Attacker goals: read rows, skip auth checks, modify data, or infer when quiet (blind). THE fix is parameterized queries / placeholders — not client-side quote stripping. This is ORIGINAL Cyberlium teaching — attack literacy first.
1. Mechanism: untrusted text compiled into SQL source
sql = "SELECT … WHERE sku = '" + sku + "'" builds a program. If sku contains SQL metacharacters, the engine parses attacker structure. Placeholders (?,?, :name) send values out-of-band so they stay data. ORM raw f-strings are still glue. Finding language: “User input concatenated into SQL.” Fix language: “Parameterize; allowlist identifiers; least privilege DB user.”
Command guide
A05 Injection — Mechanism
═══ LINUX / BASH (Network & Reconnaissance Audit) ═══
Scan target host for open ports and service version signatures
Command — copy this
nmap -sS -sV -p 80,443,8080 -Pn ${LAB_HOST:-127.0.0.1}DNS and WHOIS reconnaissance on authorized domain
Command — copy this
dig +short A target.local dig +short MX target.local whois target.local 2>/dev/null | grep -iE "(Registrar|Creation Date|Name Server)" | head -6
Inspect HTTP headers for technology stack fingerprinting
Command — copy this
curl -s -I "http://${LAB_HOST:-127.0.0.1}:8080" | grep -iE "(Server|X-Powered-By|Set-Cookie|Content-Security-Policy)"2. Attacker goals without payload homework
Change the WHERE clause, expand result sets, or short-circuit auth logic when queries are glued. Blind cases infer from behavior. This lesson names goals; it does not ship injection strings as recipes against live services. Channel words like in-band/blind are for reading reports — not for unauthorized reproduction.
3. THE fix: parameterized queries
cursor.execute("SELECT name FROM catalog_items WHERE sku = ?", (sku,)) keeps sku as a bound value. Escape libraries are a weaker cousin; prefer binds. Identifiers (table/column names) cannot bind — allowlist them. Error hygiene helps but does not replace parameters.
4. Safe demo: identify DEMO, then local catalog.db broken vs fixed
168.0.1/ — Create SQLite under $HOME/cyberlium-lab. Broken function concatenates. Fixed uses ?. Show that a malicious-looking string stays data in the fixed path — without teaching a live exploit against a network service. Do not point the script at a remote production DB.
5. What you record
Date (UTC). Identify banner. Mechanism sentence. Parameterize = THE fix. Ethics: NEVER sqlmap strangers; NEVER payload packs as attack recipes; NEVER hydra/nmap the LAN. Path: $HOME/cyberlium-lab/a05-sqli-notes.txt, chmod 600. Legal: original Cyberlium — not official OWASP certification.
6. Wrong vs right: foreign SQLi vs local bind contrast
Worked failure — same word “SQLi,” opposite target.
Wrong
sqlmap a shop search. sqlmap 192.168.0.1 because it is a router. Paste UNION cheat sheets at strangers. DVWA against hosts you do not own.
Right
Identify DEMO; broken vs fixed on local SQLite; lock a05-sqli-notes.txt. Next: XSS as Injection into the Browser.
Identify DEMO, run the local contrast. No remote DB URLs. No LAN scans.
Mission: a05-sqli-notes.txt (mode 600)
1)2) Run local fixed bind demo; record that odd input stays data. 3) Fill $HOME/cyberlium-lab/a05-sqli-notes.txt, chmod 600.
Stuck? Ask Cyberlium AI Mentor
If “I cannot learn SQLi without sqlmap” still feels true, ask for a hint — not a payload pack. Try: "Hint only: why concatenation mixes code and data, why ? placeholders are THE fix, why a router banner means STOP, and where locked a05-sqli-notes.txt lives?"
You treat SQL injection as A05 mechanism with parameterized queries as THE fix — proven on local SQLite, demo identified, not foreign hosts. Original Cyberlium — not official OWASP certification. Next — XSS as Injection into the Browser.
Knowledge Check
APPLY: sku is glued into SQL with +. What is the mechanism and THE fix?
Multiple choice
Knowledge Check
APPLY: True or False: Client-side quote stripping fully remediates SQLi.
True or False
Knowledge Check
APPLY: curl http://192.168.0.1/ shows a TP-Link Router Admin page. What do you do?
Multiple choice