Database injection
Someone tries to slip database commands into your site.
What it is
Database commands typed into a search box, a form or an address, hoping your site passes them straight to its database.
- ' OR '1'='1 in a login form
- UNION SELECT in an address
- A command to delete a table in a search box
Why it matters
When it works, the attacker can read or change everything the site stores: customers, orders, passwords.
If a real visitor is ever stopped
This can catch real text that happens to look like a database command, such as a note about SQL or a name with an apostrophe beside certain words. Mark the request as real and that one field is let through.