Home/Labs/Web Attack Sandbox
All 280 Labs
INTERACTIVE LAB🧨

SQL Injection, XSS, and CSRF Defense Sandbox (Interactive)

Fire live payloads at a toy app and toggle parameterization, CSP, and SameSite. A working defense sandbox: tautology and UNION SQL injection against concatenation versus bound parameters, reflected XSS with escaping, CSP nonces, and HttpOnly cookies, and CSRF cookie matrices.

SQLi · XSS · CSRF Defense Sandbox

Fire hand-written payloads against each defense layer and watch the evaluation flip live.

Input bound as $1 literal — the compiled AST never changes shape.DB executes: SELECT ... WHERE email = $1 · bound value: "' OR '1'='1' --" · matches: 0 row(s). SQL operators inside the string are data, not code.

Rows leaked: 0 of 50,000

SQLi: regex/blacklist sanitizing is bypassable via URL-encoding, hex, Unicode, or /**/ comments; only separation of compiled plan from bound data (prepared statements) is structural.

XSS: three layers — context-aware escaping at render, CSP nonce gating execution, HttpOnly walling cookies off from document.cookie.

CSRF: SameSite=Lax still allows top-level GET navigations, so state changes must be POST/PUT/DELETE, token-verified, or require a custom header no cross-origin form can forge (JWT Bearer headers defeat ambient-cookie CSRF by design).

How It Works Under the Hood

The three classic web injection attacks all exploit trust placed in unprocessed input, and each has a structural defense that filters or escapes-at-render can only approximate. SQL injection dies to prepared statements: binding the payload as data makes an OR 1=1 string just a weird username. Cross-site scripting dies to output escaping plus a Content-Security-Policy with per-response nonces so inline injected scripts are refused, and dies hardest to HttpOnly cookies that make stolen sessions unreplayable. CSRF dies to SameSite plus a synchronizer token an attacker's origin cannot read. The sandbox evaluates your edited payload against each toggle, so the defense chain is visible as code, not as slogans.

Core Architectural Principles

  • Concatenated SQL admits tautologies that dump all rows; bound $1 parameters return zero-row results.
  • CSP with a response nonce blocks injected inline scripts even when escaping was forgotten.
  • SameSite Lax/Strict plus synchronizer tokens starve cross-origin forged POSTs of the session cookie.
Interview Round Script

Answer structurally, not tactically: prepared statements for injection, context-aware output encoding plus CSP for XSS, double-submit or synchronizer tokens with SameSite for CSRF. Then show depth by noting XSS exfiltration is capped by HttpOnly cookies and that WAFs are a compensating control, not the design.

Key Trade-Offs

Each defense adds developer ceremony (binding parameters, nonce plumbing, token state) in exchange for eliminating an entire bug class.

Related Curriculum Chapter

Design-Level Defenses: SQL Injection, XSS, & CSRF

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs