A security analyst is investigating a web application that allows users to create custom reports based on SQL queries. The application concatenates user-provided input directly into the SQL query string without proper sanitization. An attacker successfully injected `'; DROP TABLE users; --` into a report query field, leading to data loss. Which type of web application attack does this scenario describe?
- ABroken Authentication
- BSQL Injection
- CCommand Injection
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. SQL Injection
The scenario explicitly mentions an attacker injecting SQL commands (`DROP TABLE users`) into a query field, leading to data loss. This is the hallmark of a SQL Injection attack, where malicious SQL code is inserted into input fields to manipulate the database.
Why the other options are wrong
- A. Broken Authentication refers to vulnerabilities in authentication mechanisms, not direct data manipulation via query injection.
- C. Command Injection targets the operating system to execute arbitrary commands, not the database.
- D. XSS involves injecting client-side scripts into web pages, not direct SQL commands.
SQL Injection
A web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. It typically allows an attacker to view data that they are not normally able to retrieve, alter database data, execute administration operations on the database (such as shutting it down), or recover the contents of a given file present on the database server's file system.
- Injects malicious SQL code.
- Targets database operations.
- Can lead to data disclosure, modification, or destruction.
Memory trick: If the query gets dropped, SQL Injection has popped.