💉
Security

SQL injection: what it is and protection

04.02.2025
← All articles

SQL injection — injecting malicious SQL through user input. OWASP Top 10 #1.

Example

WHERE name='$name' — user enters admin' OR '1'='1 — logs in as admin.

Only right way: Prepared Statements

PDO: $st->prepare(...); $st->execute([$name]).

What NOT to do

String concatenation, mysql_real_escape — outdated.

ORM

Eloquent, Doctrine — auto prepared.

Related articles

🔐 Password managers — choosing between Bitwarden, 1Password, LastPass and KeePass 🍯 Honeypot — hidden form field that catches bots and stops spam 📄 /.well-known/security.txt — security contact standard 📋 GDPR Compliance — obligations for protecting European citizens' data
🌐 Language
🇺🇿 O'zbek 🇺🇿 Ўзбек 🇷🇺 Русский 🇬🇧 English ✓