Watch
Running an SQL Injection Attack - Computerphile
Exploits a concatenated query live, dumping data table by table, then shows why parameterized queries close the hole: the model for the whole injection family.
Engineering Fundamentals for the Agent Era
A database query or shell command built by string concatenation with user input.
User-supplied content rendered as raw HTML, allowing cross-site scripting.
A server that fetches any URL a user provides, letting attackers reach internal services and cloud metadata endpoints.
A file-upload handler that trusts the client's file name, letting a name like ../../config overwrite files outside the upload folder.
Treating every input as hostile, and understanding the family of attacks where data ends up executed as code or commands.
An agent built a 'save as PDF' feature that downloads a user-supplied URL and passes the page title into a shell command, plus a support bot that reads ticket text and can issue refunds. Find the three injection paths and the smallest change that closes each one.
Watch
Exploits a concatenated query live, dumping data table by table, then shows why parameterized queries close the hole: the model for the whole injection family.
Animated walk through reflected, stored and DOM XSS, showing how user content becomes script when it is not encoded for the context it lands in.
The researcher who named prompt injection explains why filtering cannot fix it and why the defense is limiting what a model with untrusted input is allowed to do, as with the refund-issuing support bot.
Covers XSS, injection, SSRF and deserialization from both the attack and the defense side, updated for modern stacks such as GraphQL and server-side rendering.
Teaches domain primitives and strict parsing at the boundary: turn raw input into well-typed values once and reject anything that doesn't fit, which prevents whole classes of injection.
The classic on how browsers actually parse HTML, URLs and scripts, which explains why output encoding must match each context.
Reference
One page on SQL, LDAP and OS-command injection with parameterization and allow-list validation as the general cure.
Reference
The rules for encoding output per context (HTML body, attribute, JavaScript, URL, CSS), plus framework escape hatches and CSP as a backstop.