Lesson 6 of 6 in SQL Injection
Catch It Next Time
The fix stops today's injection. Detection is what you write so the next one pages you at 3am instead of being found by a customer six months later — an alert on the telemetry you just learned to read, and a test that fails if the hole ever reopens.
3 min read
Not yet reviewed
The query is parameterised now. The attack is dead. Are we not done?
The attack is dead on that one query. But you fixed a hundred queries this year and you are human. Detection is the admission that a fix can be undone — by a teammate, by a refactor, by next year's rush — and it makes the undoing loud.
From reading the log to being paged by it
In the last lesson you read the injection in the query log with your own eyes. Detection is writing down what you noticed so a machine notices it for you, at 3am, when no one is looking. You are turning a thing you can recognise into a thing that recognises itself.
Alert: SQL errors from a single user
when a client causes > 5 database errors in 1 minute
→ page on-call; likely payload tuning in progress
Alert: tautology / UNION in a query
when a logged query matches OR 1=1 or UNION SELECT
→ raise a ticket; a search box does not write these
- Line 1The error burst you saw a defender notice. It fires while the attacker is still tuning, which is the best possible time — before the working payload exists.
- Line 5A content signal, not just a volume one. It can be noisy, so it raises a ticket rather than waking someone; the value is a trail, not a siren.
Alerts watch production. A test watches the code, and it is the cheaper, surer half: a single test that sends ' OR 1=1 -- at the endpoint and asserts it does not return every row will fail the build the moment anyone reintroduces string-building — which is exactly how a closed hole quietly reopens.
A fix, and nothing watching it
Parameterise the query.
Trust it stays parameterised forever.A fix that stays fixed
Parameterise the query.
A test that fails if injection ever works again.
An alert if a payload reaches production.The right column is the difference between fixing a bug and keeping it fixed. The test catches the regression before it ships; the alert catches the one that slips past the test. A fix with neither is a fix with a shelf life.
Why is a named regression test often more valuable than the production alert, even though the alert is what "catches attackers"?