
SQL Injection in Cyber Security | Definition, Examples, and Prevention
SQL Injection is a technique for exploiting vulnerabilities in a database. Using insecure written code, someone can view, modify, or destroy data within the database. It is important to know this not for hacking, but for saving your own website.
What is SQL Injection?
Suppose you have a login form on your website. The user enters their username and password.
You put that input directly into a SQL query.
If the input is not validated, the user can insert their own SQL code, which is SQL Injection.
Simply inserting SQL code instead of providing data is called SQL Injection.
Why do SQL Injection?
SQL injection is not doing for good reasons. Usually, the purpose is to see credentials (authentication) data (user, password, email), etc.
This way, an attacker can easily do these things, such as:
- Becoming an admin without logging in,
- deleting or modifying databases,
- Knowing the internal structure of the server database.
How to do SQL Injection?
The main reason is one: not properly validating/filtering user input data. We will see below how it tries to take control of the server.
$username = $_POST[‘username’];
$password = $_POST[‘password’];
SELECT * FROM users WHERE username = ‘$username’ AND password = ‘$password’;
Here, $username and $password come directly from the user, so this code is dangerous. It must be protected against SQL injection and then run the query.

5 SQL Injection Examples (for beginners to understand)
These are for learning purposes and to protect your own server. It is illegal to use them with another website.
1. Login Bypass real Injection explanation:
' OR ''=''What is happening inside the query?
Suppose the query code is like this:
SELECT * FROM users
WHERE username = '' OR ''=''
AND password = '';Now look at here
”=” => is always true
SQL is no longer concerned with username-password here.
Now results:
The database thinks, “The condition is true” that’s why it logs in the first user.
Why is this scary?
Because many times the first user is the admin. Through this, the hacker admin will be able to control everything, such as Delete, insert, edit, and even add files containing malware.
2. Admin Detect SQL Injection (Silent Search)
' AND username='admin' --Now look at here:
It does not log you in directly. It asks questions instead-
"Is there someone named admin in this system?"If the behavior of the page changes (error/ no error/response time), then the attacker understands that there is an admin user.
Now results:
The target of future attacks is determined. If you enter the wrong code on the website, you will face serious damage!
3. Time-Based Blind Injection (Detecting truth or falsehood through time)
Injection explanation:
' AND IF(1=1, SLEEP(5), 0) --What is being done with this ejection?
Now look at here
1=1 => is true
SQL is no longer concerned with username-password here. So the database will sleep for 5 seconds
Now, if the website loads 5 seconds late, the attacker knows the injection is working.
Why is this injection code used?
When
no error is shown
no data is shown
then information is extracted only with time
4. Extract Database Name (Silent)
Injection explanation:
' AND database() LIKE 'a%' --What is being done with this ejection?
Attacker asks questions:
Does the database name start with ‘a’?
If the page is normal => yes
If not => no
In this way, the entire name is found by guessing each letter.
Now results:
Knowing the database name without showing any data.
5. Data Delete Injection (the most dangerous type)
Injection explanation:
'; DELETE FROM users --If the injection code is like this:
$query = "SELECT * FROM users WHERE name = '$name'";Then the final code will be like this:
SELECT * FROM users WHERE name = '';
DELETE FROM users;Now results:
The entire users table is empty!
This is why SQL Injection is not just a “hack”, it is a direct business loss.
Practical Safety Checklist Brief Notes:
User input => Never make part of SQL
Prepared Statement => Mandatory
Admin panel => extra validation
SQL Error message => Do not show to user
DB user => DROP / DELETE permission must be limited.
SQL Injection is not a “smart trick“,
It’s basically the result of writing bad code.
If you’re a developer, it’s your responsibility to know this. Because once the data is gone, it never comes back.
PHP example(Safe):
$stmt = $conn->prepare("SELECT * FROM users WHERE username = ? AND password = ?");
$stmt->execute([$username, $password]);SQL Injection Prevention Examples
Currently Prepared Statement (the safest method). Below are some of the wrong methods (Vulnerable Code) and the correct method.
You can read the article about the top SQL Injection Prevention.
1. Prepared Statement (Safe Method)
Wrong Method
$sql = "SELECT * FROM users WHERE username = '$username' AND password = '$password'";Right Method (Prepared Statement – PHP PDO)
$stmt = $conn->prepare("SELECT * FROM users WHERE username = :username AND password = :password");
$stmt->bindParam(':username', $username);
$stmt->bindParam(':password', $password);
$stmt->execute();This is safe because user input and any SQL code are not mixed together here, and SQL injection code will not work here.
2. Input Validation (Data Verification)
This will block special characters, prevent unnecessary input, but it cannot be relied upon alone. Prepared Statements are definitely required.
if (!preg_match("/^[a-zA-Z0-9_]{3,20}$/", $username)) {
die("Invalid username");
}3. Passwords should never be kept in plain text.
Wrong Method
password = 'thbd123'Right Method
$hash = password_hash($password, PASSWORD_BCRYPT);Right Way Verify Password
password_verify($password, $hash);4. Limiting Database User Permissions
Even if the attacker performs an SQL DELETE injection, the attacker will not be able to delete the entire database.
Wrong Method
GRANT ALL PRIVILEGES ON *.* TO 'app_user';Right Method
GRANT SELECT, INSERT, UPDATE ON app_db.* TO 'app_user';5. Hiding Error Message
This way, attackers cannot know the SQL structure. Otherwise, the structure can be easily understood by looking at the error.
Wrong Method
echo $e->getMessage();Right Method
error_log($e->getMessage());
echo "Something went wrong!";6. Using LIMIT (prevent data dump)
Reduces massive data leaks.
SELECT * FROM users LIMIT 1;7. Web Application Firewall (WAF)
Detects SQL keywords and blocks suspicious payload
Example:
* ModSecurity
* Cloudflare WAF





