

{"id":24336,"date":"2018-08-14T06:05:33","date_gmt":"2018-08-14T06:05:33","guid":{"rendered":"https:\/\/data-flair.training\/blogs\/?p=24336"},"modified":"2021-03-11T17:44:25","modified_gmt":"2021-03-11T12:14:25","slug":"sql-injection","status":"publish","type":"post","link":"https:\/\/data-flair.training\/blogs\/sql-injection\/","title":{"rendered":"What is SQL Injection (SQLi) | SQL Injection Example"},"content":{"rendered":"<p>In this tutorial, we will learn about one of the major injection attack used by the hackers i.e. SQL Injection attack. This is one of the most popular web hacking injection protocol.<\/p>\n<p>Here the hacker tries to execute malicious SQL statements on the database to access the hidden data which can corrupt and damage the database and the working of the whole system.<\/p>\n<p>If the hacker succeeds in an injection attack, he gets access to the data which is normally not accessible to them. And they can delete or change it causing abnormal changes in the application.<\/p>\n<p>Let us now dive deep into the concept of SQL injection and understand its causes and preventions.<\/p>\n<h3>What is an SQL Injection?<\/h3>\n<p>SQL Injection is also known as SQLi. SQLi is the web security vulnerability due to which the application is on the verge of losing private data.<\/p>\n<p>When a hacker can run malicious SQL queries on the database the private data is exposed hence corrupting the application.<\/p>\n<p>This can be done by interacting with the user input fields, using languages or particular special symbols, the most frequent being 1=1 and the \u2018or\u2019.<\/p>\n<h3>What happens if a SQL Injection is Successful?<\/h3>\n<p>When the hacker successfully breaks into the database by running the malicious SQL queries.<\/p>\n<p>Hackers get access to the private database of the application and can corrupt the application which leads to failure of backend services as well.<\/p>\n<p>Researchers have also seen that sometimes the hacker gets control of the backend system of the organization, even the backend stuff.<\/p>\n<p>This leads to the compromise between the services being provided to the users and in some cases, the services remain down for a long period.<\/p>\n<h3>Some of the Major SQL Injections<\/h3>\n<p>When we talk about Injection attacks in the case of the web, SQL injection attacks top the list.<\/p>\n<p>Some of the major SQL injection attacks are as follows:<\/p>\n<h4>1. SQL injection based on 1=1 which the system always evaluates to be True.<\/h4>\n<p>Here the hacker uses the fact that a or statement evaluates to true even if one condition evaluates to true. Hence the hacker uses a smart input like \u201c1=1\u201d which always evaluates to true.<\/p>\n<p><strong>For example:<\/strong><\/p>\n<p>If we have an emp_id column and the hacker wishes to view the database he can use an input like \u201c emp_id = 112 or 1=1\u201d this will evaluate to the SQL query as follows:<br \/>\n<strong>Query:<\/strong><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">Use DataFlair;\r\nSELECT emp_id,name,location,experience\r\nFROM DataFlair A1\r\nWHERE emp_id = '112' or 1=1;\r\n<\/pre>\n<p><strong>Output:<\/strong><\/p>\n<p><a href=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-86950\" src=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1.png\" alt=\"SQL Injections Example\" width=\"1920\" height=\"1032\" srcset=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1.png 1920w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1-300x161.png 300w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1-1024x550.png 1024w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1-150x81.png 150w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1-768x413.png 768w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1-1536x826.png 1536w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1-720x387.png 720w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1-520x280.png 520w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/1-320x172.png 320w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><\/a><\/p>\n<h4>2. SQL injection based on \u201c=\u201d which the system evaluates to be True always.<\/h4>\n<p>In this case, the hacker will manifest the fact that the expression on each side of =, if evaluate to true will return all the results stored in the database.<\/p>\n<p>For example, if we have an emp_id field and the hacker inputs- &#8220;&#8221; or &#8220;&#8221;=&#8221;&#8221; this expression evaluates to true and thus returns the whole database data to the hacker.<\/p>\n<p>If we put emp_id = &#8220;&#8221; or &#8220;&#8221;=&#8221;&#8221;, then the SQL query which automatically executes at the backend is as follows:<br \/>\n<strong>Query:<\/strong><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">Use DataFlair;\r\nSELECT emp_id,name,location,experience\r\nFROM DataFlair A1\r\nWHERE emp_id = \"\" or \"\"=\"\";\r\n<\/pre>\n<p><strong>Output:<\/strong><\/p>\n<p><a href=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-86951\" src=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2.png\" alt=\"SQL Injection Example\" width=\"1920\" height=\"1032\" srcset=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2.png 1920w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2-300x161.png 300w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2-1024x550.png 1024w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2-150x81.png 150w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2-768x413.png 768w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2-1536x826.png 1536w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2-720x387.png 720w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2-520x280.png 520w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/2-320x172.png 320w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><\/a><\/p>\n<h4>3. SQL injection based on batched SQL statements.<\/h4>\n<p>If the hacker passes some SQL statement in the input field it is treated as a valid SQL statement and is executed on our database.<\/p>\n<p><strong>For example:<\/strong><\/p>\n<p>If the hacker inputs the following in the emp_id user field: \u201c118\u201d; TRUNCATE location<\/p>\n<p>In this case, we will lose all the data stored in the location table of our database. The resulting query would be as follows:<br \/>\n<strong>Query:<\/strong><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">Use DataFlair;\r\nSELECT emp_id,name,location,experience\r\nFROM DataFlair A1\r\nWHERE emp_id = \"105\";\r\nTRUNCATE location;\r\n<\/pre>\n<p><strong>Output:<\/strong><\/p>\n<p><a href=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-86952\" src=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1.png\" alt=\"SQLi Example\" width=\"1920\" height=\"1032\" srcset=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1.png 1920w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1-300x161.png 300w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1-1024x550.png 1024w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1-150x81.png 150w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1-768x413.png 768w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1-1536x826.png 1536w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1-720x387.png 720w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1-520x280.png 520w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/3-1-320x172.png 320w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><\/a><\/p>\n<h4>4. SQL injection to access the hidden data.<\/h4>\n<p>Here the hacker accesses the hidden data by using malicious entries into the user input fields.<\/p>\n<p><strong>For Example:<\/strong><\/p>\n<p>If the hacker inputs some data which is always true into the user field whole application data is exposed.<br \/>\nIf the user inputs something like \u2018*\u2019, in the input field whole data is exposed as the query translates to the following:<\/p>\n<p><strong>Query:<\/strong><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">Use DataFlair;\r\nSELECT *\r\nFROM DataFlair;\r\n<\/pre>\n<p><strong>Output:<\/strong><\/p>\n<p><a href=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-86953\" src=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4.png\" alt=\"Example of SQL Injection\" width=\"1920\" height=\"1032\" srcset=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4.png 1920w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4-300x161.png 300w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4-1024x550.png 1024w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4-150x81.png 150w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4-768x413.png 768w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4-1536x826.png 1536w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4-720x387.png 720w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4-520x280.png 520w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/4-320x172.png 320w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><\/a><\/p>\n<h4>5. SQL injection to alter the application logic.<\/h4>\n<p>In this case, the hacker changes the hidden logic or gets access to the backend of the application hence corrupting the application. We can understand this by the following example:<\/p>\n<p>If the hacker inputs a random input in the emp_id input field and a truncate statement then we can lose all the data stored. Hence the logic at the backend would fail.<\/p>\n<p>Emp_id = \u2018789\u2019 ; TRUNCATE DataFlair<\/p>\n<p>This would translate to the following SQL query-<br \/>\n<strong>Query:<\/strong><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">Use DataFlair;\r\nSELECT *\r\nFROM DataFlair A1\r\nWHERE emp_id = \"789\";\r\nTRUNCATE DataFlair;\r\n<\/pre>\n<p><strong>Output:<\/strong><\/p>\n<p><a href=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-86954\" src=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5.png\" alt=\"SQL Injections Example\" width=\"1920\" height=\"1028\" srcset=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5.png 1920w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5-300x161.png 300w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5-1024x548.png 1024w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5-150x80.png 150w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5-768x411.png 768w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5-1536x822.png 1536w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5-720x386.png 720w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5-520x278.png 520w, https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/5-320x171.png 320w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><\/a><\/p>\n<h3>How to Prevent SQL Injections?<\/h3>\n<p>Some of the general methods which one can follow to avoid SQL Injection attacks are as follows:<\/p>\n<p>1. The organisation should make aware all the web developers and the backend developers about tips and tricks to avoid SQL injections.<\/p>\n<p>Regular training can help avoid these attacks to a large extent.<\/p>\n<p>2. All the user inputs should be treated as untrusted and should be checked before we run the query on our database.<\/p>\n<p>3. Filter the user input based on the white lists as the hacker always develops the tool to get past the blacklist almost always.<\/p>\n<p>4. The organisations and the hosting units should make sure that the website runs on the latest technologies and uses the latest security certificates to avoid injection attacks.<\/p>\n<p>5. Always implement the tried and tested mechanisms to prevent an attack on the system instead of deploying the system you built from scratch.<\/p>\n<p>6. Last but not least always ensure that the systems are regularly on the monitor for suspicious activity or events.<\/p>\n<h3>Summary<\/h3>\n<p>In this tutorial, we have seen what is an SQL injection and how it is done. We have then seen the problems one can face due to a successful injection attack.<\/p>\n<p>When the hacker performs an SQLi attack it can lead to the exposure of an internal database which could corrupt the whole application and can even result in breaking the backend logic.<\/p>\n<p>Then we also understood all the tips and tricks by which we can avoid SQLi attacks.<\/p>\n<p>Thus we can say that organizations and individuals should take care while hosting on the web to avoid any possible SQLi attacks which can be done by following required security protocols.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this tutorial, we will learn about one of the major injection attack used by the hackers i.e. SQL Injection attack. This is one of the most popular web hacking injection protocol. Here the&#46;&#46;&#46;<\/p>\n","protected":false},"author":6,"featured_media":86949,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[66],"tags":[5944,9482,13470,13472,13473,13474,13475,13477,13480],"class_list":["post-24336","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sql","tag-how-sql-injection-works","tag-php-sql","tag-sql-injection","tag-sql-injection-attack","tag-sql-injection-attack-example","tag-sql-injection-code","tag-sql-injection-code-list","tag-sql-injection-functioning","tag-sql-injection-types"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What is SQL Injection (SQLi) | SQL Injection Example - DataFlair<\/title>\n<meta name=\"description\" content=\"SQL injection, what is SQL Injection, how SQL Injection Works, example of SQL Injection, SQL Injection PHP, SQL injection attack, SQL injection prevention\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/data-flair.training\/blogs\/sql-injection\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is SQL Injection (SQLi) | SQL Injection Example - DataFlair\" \/>\n<meta property=\"og:description\" content=\"SQL injection, what is SQL Injection, how SQL Injection Works, example of SQL Injection, SQL Injection PHP, SQL injection attack, SQL injection prevention\" \/>\n<meta property=\"og:url\" content=\"https:\/\/data-flair.training\/blogs\/sql-injection\/\" \/>\n<meta property=\"og:site_name\" content=\"DataFlair\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/DataFlairWS\/\" \/>\n<meta property=\"article:published_time\" content=\"2018-08-14T06:05:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-03-11T12:14:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/SQL-injections.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"DataFlair Team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@DataFlairWS\" \/>\n<meta name=\"twitter:site\" content=\"@DataFlairWS\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"DataFlair Team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is SQL Injection (SQLi) | SQL Injection Example - DataFlair","description":"SQL injection, what is SQL Injection, how SQL Injection Works, example of SQL Injection, SQL Injection PHP, SQL injection attack, SQL injection prevention","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/data-flair.training\/blogs\/sql-injection\/","og_locale":"en_US","og_type":"article","og_title":"What is SQL Injection (SQLi) | SQL Injection Example - DataFlair","og_description":"SQL injection, what is SQL Injection, how SQL Injection Works, example of SQL Injection, SQL Injection PHP, SQL injection attack, SQL injection prevention","og_url":"https:\/\/data-flair.training\/blogs\/sql-injection\/","og_site_name":"DataFlair","article_publisher":"https:\/\/www.facebook.com\/DataFlairWS\/","article_published_time":"2018-08-14T06:05:33+00:00","article_modified_time":"2021-03-11T12:14:25+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/SQL-injections.jpg","type":"image\/jpeg"}],"author":"DataFlair Team","twitter_card":"summary_large_image","twitter_creator":"@DataFlairWS","twitter_site":"@DataFlairWS","twitter_misc":{"Written by":"DataFlair Team","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/#article","isPartOf":{"@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/"},"author":{"name":"DataFlair Team","@id":"https:\/\/data-flair.training\/blogs\/#\/schema\/person\/2c58ecb4f73a39f0ef993f1ddfcd7b89"},"headline":"What is SQL Injection (SQLi) | SQL Injection Example","datePublished":"2018-08-14T06:05:33+00:00","dateModified":"2021-03-11T12:14:25+00:00","mainEntityOfPage":{"@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/"},"wordCount":1000,"commentCount":0,"publisher":{"@id":"https:\/\/data-flair.training\/blogs\/#organization"},"image":{"@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/#primaryimage"},"thumbnailUrl":"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/SQL-injections.jpg","keywords":["how SQL injection works","PHP SQL","SQL Injection","SQL injection Attack","SQL Injection attack example","SQL Injection Code","SQL Injection code list","sql injection functioning","SQL Injection types"],"articleSection":["SQL Tutorials"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/data-flair.training\/blogs\/sql-injection\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/","url":"https:\/\/data-flair.training\/blogs\/sql-injection\/","name":"What is SQL Injection (SQLi) | SQL Injection Example - DataFlair","isPartOf":{"@id":"https:\/\/data-flair.training\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/#primaryimage"},"image":{"@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/#primaryimage"},"thumbnailUrl":"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/SQL-injections.jpg","datePublished":"2018-08-14T06:05:33+00:00","dateModified":"2021-03-11T12:14:25+00:00","description":"SQL injection, what is SQL Injection, how SQL Injection Works, example of SQL Injection, SQL Injection PHP, SQL injection attack, SQL injection prevention","breadcrumb":{"@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/data-flair.training\/blogs\/sql-injection\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/#primaryimage","url":"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/SQL-injections.jpg","contentUrl":"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2018\/08\/SQL-injections.jpg","width":1200,"height":628,"caption":"SQL injections"},{"@type":"BreadcrumbList","@id":"https:\/\/data-flair.training\/blogs\/sql-injection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog Home","item":"https:\/\/data-flair.training\/blogs\/"},{"@type":"ListItem","position":2,"name":"SQL Tutorials","item":"https:\/\/data-flair.training\/blogs\/category\/sql\/"},{"@type":"ListItem","position":3,"name":"What is SQL Injection (SQLi) | SQL Injection Example"}]},{"@type":"WebSite","@id":"https:\/\/data-flair.training\/blogs\/#website","url":"https:\/\/data-flair.training\/blogs\/","name":"DataFlair","description":"Learn Today. Lead Tomorrow.","publisher":{"@id":"https:\/\/data-flair.training\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/data-flair.training\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/data-flair.training\/blogs\/#organization","name":"DataFlair","url":"https:\/\/data-flair.training\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/data-flair.training\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2016\/07\/Data-Flair.png","contentUrl":"https:\/\/data-flair.training\/blogs\/wp-content\/uploads\/sites\/2\/2016\/07\/Data-Flair.png","width":106,"height":48,"caption":"DataFlair"},"image":{"@id":"https:\/\/data-flair.training\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/DataFlairWS\/","https:\/\/x.com\/DataFlairWS","https:\/\/www.linkedin.com\/company\/dataflair-web-services-pvt-ltd\/","https:\/\/www.youtube.com\/user\/DataFlairWS"]},{"@type":"Person","@id":"https:\/\/data-flair.training\/blogs\/#\/schema\/person\/2c58ecb4f73a39f0ef993f1ddfcd7b89","name":"DataFlair Team","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1ce4a0e3e542444fc73bbebf83e89e8b73e2d95ccb1fcee64da9945f078b97c5?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1ce4a0e3e542444fc73bbebf83e89e8b73e2d95ccb1fcee64da9945f078b97c5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1ce4a0e3e542444fc73bbebf83e89e8b73e2d95ccb1fcee64da9945f078b97c5?s=96&d=mm&r=g","caption":"DataFlair Team"},"description":"The DataFlair Team provides industry-driven content on programming, Java, Python, C++, DSA, AI, ML, data Science, Android, Flutter, MERN, Web Development, and technology. Our expert educators focus on delivering value-packed, easy-to-follow resources for tech enthusiasts and professionals.","url":"https:\/\/data-flair.training\/blogs\/author\/dfteam2\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/posts\/24336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/comments?post=24336"}],"version-history":[{"count":7,"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/posts\/24336\/revisions"}],"predecessor-version":[{"id":86955,"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/posts\/24336\/revisions\/86955"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/media\/86949"}],"wp:attachment":[{"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/media?parent=24336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/categories?post=24336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/data-flair.training\/blogs\/wp-json\/wp\/v2\/tags?post=24336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}