When you click submit, the credentials are securely sent to the server, most likely using .
The server uses SQL to determine if the correct credentials are stored in a database table eg:
SELECT username, password
FROM admin
WHERE username = 'postedUsername' and password = 'postedPassword'
LIMIT 1;
If the query returns a result, it means the credentials are correct and the user can login, otherwise they are directed to try again.
SQL Injection is very smart.
Try entering the following SQL into the username input box. Don't enter anything into the password box.
'admin' OR password = ''#
Can you login? The SQL is being injected into the above query and changing the SQL that is executed.
In fact, this is the resulting SQL:
SELECT username, password
FROM admin
WHERE username = 'admin' OR password = '' # and password = 'postedPassword'
LIMIT 1;
As you can see, OR logic is being used so as long as there is a username of 'admin' in the database, the query will return a result.
The hash tag # is used to create comments so everything following it is ignored! Sneaky!
Of course, the username is probably not admin, but hackers would probably try it first.
Web designers sanitize user input, ensuring that input is processed as text, and not as SQL.
XSS (cross-site scripting) is similar to SQL Injection in that malicious scripts are injected into a webpage and executed in the victim's browser.