SQL injection
Në shqip: Injektim SQL
ShpjegimiSQ
SQL injection ndodh kur një sulmues shkruan kod SQL në një formular (p.sh. te emri i përdoruesit) dhe aplikacioni e ngjit direkt në query. Kështu mund ta lexojë ose ta fshijë gjithë databazën. Mbrojtja: përdor gjithmonë query me parametra.
EnglishEN
SQL injection happens when an attacker types SQL code into a form (e.g. the username field) and the app pastes it straight into a query. That way they can read or delete the whole database. The defence: always use parameterised queries.
Si ta mendosh
Si kur i jep shitësit një listë blerjesh ku dikush ka shtuar fshehurazi në fund: „…dhe hapja arkën.“ Shitësi i kujdesshëm e lexon vetëm si listë, kurrë si urdhër.
Lexoje në anglisht
Like handing a shopkeeper a shopping list where someone has secretly added at the bottom: “…and open the till for him.” A careful shopkeeper reads it only as a list, never as orders.
Shembull kodipython
emri = input("Emri: ")
db.execute(f"SELECT * FROM perdoruesit WHERE emri = '{emri}'") # RREZIK
db.execute("SELECT * FROM perdoruesit WHERE emri = ?", (emri,)) # SIGURT