> For the complete documentation index, see [llms.txt](https://edsonha.gitbook.io/my-gitbook/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://edsonha.gitbook.io/my-gitbook/junior-to-senior-1/security/injection.md).

# Injection

Injection are the most common attacks. Injection means injecting unwanted code into another piece of code in order to corrupt the data.&#x20;

Two injection type is&#x20;

* SQL injection (' or 1=1--). Bad as you can login without giving the correct password
* Input injection  (\<img src="/" onError="alert('boom');">). You can give a boom alert because image source is retrieving from wrong source.

**Solutions:**

* Sanitizing user inputs by data validation. Meaning to check that the user input are of your expected type. Number is number, string is string, etc.
* Use parameterized query or also called prepared statements. Think of it as a function that we can provide parameters. One solution is to use Object Relational Mappers. For SQL (Sequelize) and NonSQL (Mongoose). They provide these prepared statements (SQL statements) for you, so that all you need to supply are the parameters.&#x20;
