iwantcoding
.com
Tutorials
▾
Web Frontend
HTML
CSS
HTML5
CSS3
JavaScript
TypeScript
Sass
React
Vue
Svelte
Tailwind
Backend
Python
PHP
Node.js
Java
Go
Rust
Ruby
C#
Databases
SQL
MySQL
PostgreSQL
MongoDB
Firebase
GraphQL
Redis
Mobile
React Native
Flutter
Swift
Kotlin
Ionic
Cloud & DevOps
AWS
Docker
Kubernetes
CI/CD
Linux/Bash
AI & Data
NumPy/Pandas
Machine Learning
TensorFlow
PyTorch
LangChain
RAG
Cybersecurity
XSS
SQL Injection
CSRF
OWASP Top 10
Cryptography
Ethical Hacking
Tools
Git
DSA
Design Patterns
RegEx
VS Code
Specialty
Game Dev
WordPress
Web3/Solidity
Three.js
Capstone
Enterprise Architecture
HTML
CSS
JAVASCRIPT
SQL
PYTHON
PHP
TYPESCRIPT
REACT
NODEJS
MONGODB
DOCKER
GIT
TAILWIND
GRAPHQL
LINUX-BASH
AWS
KUBERNETES
VUE
SVELTE
SASS
THREEJS
GO
RUST
JAVA
RUBY
CSHARP
WORDPRESS
POSTGRESQL
MYSQL
REDIS
FIREBASE
REACT-NATIVE
FLUTTER
SWIFT
KOTLIN
IONIC
CICD
NUMPY-PANDAS
ML
TENSORFLOW
PYTORCH
LANGCHAIN
XSS
SQLI
CSRF
OWASP
CRYPTO
DSA
DESIGN-PATTERNS
REGEX
VSCODE
GAMEDEV
WEB3
ENTERPRISE
CAPSTONE
ETHICAL-HACKING
🔥 Daily
👥 Rooms
🏆 Top
Log in
Sign up
AI ✨
SQL Injection Tutorial
BOSS QUIZ
10 questions · 5 minutes · pass at 70% to clear the track.
05:00
Start
Q1.
In node-postgres, the placeholder for parameter #1 is…
from Parameterised Queries
?
\$1
:1
@p1
Q2.
A common safe pattern is…
from ORMs Done Right
User::where('email', \$email)
User::query()->raw(\$email)
"SELECT * WHERE email = " . \$email
eval(\$sql)
Q3.
Calling Eloquent's whereRaw with concatenation is…
from ORMs Done Right
Safe
Risky — bind values instead
Required
Encrypted
Q4.
Allow-listing is preferred to block-listing because…
from Allow-list for Identifiers
It misses fewer cases
It is faster
It is required by law
It is shorter
Q5.
In PDO (PHP), placeholders are…
from Parameterised Queries
? or :name
\$1
@p1
<%= ? %>
Q6.
SQL injection is caused by…
from Intro
Slow queries
Untrusted input changing the SHAPE of a SQL statement
Bad indexes
Wrong encoding
Q7.
A parameterised query separates…
from Parameterised Queries
Network from disk
SQL code from data
Encryption from auth
Schema from rows
Q8.
For sort direction, use…
from Allow-list for Identifiers
Raw input
An allow-list mapping (asc/desc → ASC/DESC)
A regex on the SQL
Hashing
Q9.
The strongest single defence is…
from Intro
A WAF
Parameterised queries
Escaping with addslashes
Stored procs alone
Q10.
You can't parameterise…
from Allow-list for Identifiers
Values
Identifiers (table / column / direction)
Strings
Dates
Submit
Back to SQL Injection Tutorial
🏆
Achievement unlocked!