Smuggling SQL into the input an application accepts. NSGs cannot detect it; WAF managed rule sets, such as those on Application Gateway, stop it at the web tier, and Microsoft Defender for SQL alerts on it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SQL injection in context, with comparison tables and the common traps.
Terms in this definition
- Serverless
Compute tier for single Azure SQL databases that scales automatically, pauses when idle and charges by the second. It is offered in General Purpose and Hyperscale, not Business Critical, and reserved capacity does not apply.
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
- Application Gateway
Layer-7 load balancer deployed per region, offering URL-based routing, TLS offload, cookie-based affinity and an optional WAF.
- Stop sequence
One of up to four strings that make the model halt generation; the sequence itself is not included in the output.
- Archive
Offline access tier for blobs, cheapest to store yet dearest to access. Reading a blob means rehydrating it first, which can take as long as 15 hours.
- Microsoft Defender for SQL
Combines SQL vulnerability assessment with Advanced Threat Protection, which alerts on brute force, SQL injection and anomalous access. As a Defender for Cloud plan it detects threats; it doesn't mask or encrypt data.
Related terms
- Advanced Threat Protection
Part of Defender for SQL that raises alerts for possible SQL injection, code vulnerable to injection, brute-force attacks and access by unusual principals or from unusual locations.
- DRS
The Default Rule Set, Microsoft's managed WAF rules that succeed OWASP CRS and defend against XSS, SQL injection and other frequent attacks. Single rules may be overridden or switched off.
- SAST
Static application security testing: inspecting source code for weaknesses like SQL injection or broken authentication. GitHub Advanced Security uses CodeQL for this; spotting vulnerable dependencies is a separate job called SCA.