Academy
Practitioner track

SQL Injection

Break out of the query, read what you should not, then fix it with parameters.

Create a free account to track progress and earn the certificate. You can read the syllabus below without one.

Final exam

3 questions in 10 minutes, 3 to pass. Certificates require it.

Take the exam
  1. 01How SQL injection worksConcatenation is the vulnerability. Tautologies, unions, and blind inference.
  2. 02Lab: login bypassA concatenated login form on shop.test. Become admin without the password.
  3. 03SQL injection quizThree questions on cause, exploitation, and the real fix.