SQL Injection, XSS, and CSRF Defense Sandbox (Interactive)
Fire live payloads at a toy app and toggle parameterization, CSP, and SameSite. A working defense sandbox: tautology and UNION SQL injection against concatenation versus bound parameters, reflected XSS with escaping, CSP nonces, and HttpOnly cookies, and CSRF cookie matrices.
SQLi · XSS · CSRF Defense Sandbox
Fire hand-written payloads against each defense layer and watch the evaluation flip live.
Rows leaked: 0 of 50,000
SQLi: regex/blacklist sanitizing is bypassable via URL-encoding, hex, Unicode, or /**/ comments; only separation of compiled plan from bound data (prepared statements) is structural.
XSS: three layers — context-aware escaping at render, CSP nonce gating execution, HttpOnly walling cookies off from document.cookie.
CSRF: SameSite=Lax still allows top-level GET navigations, so state changes must be POST/PUT/DELETE, token-verified, or require a custom header no cross-origin form can forge (JWT Bearer headers defeat ambient-cookie CSRF by design).
How It Works Under the Hood
The three classic web injection attacks all exploit trust placed in unprocessed input, and each has a structural defense that filters or escapes-at-render can only approximate. SQL injection dies to prepared statements: binding the payload as data makes an OR 1=1 string just a weird username. Cross-site scripting dies to output escaping plus a Content-Security-Policy with per-response nonces so inline injected scripts are refused, and dies hardest to HttpOnly cookies that make stolen sessions unreplayable. CSRF dies to SameSite plus a synchronizer token an attacker's origin cannot read. The sandbox evaluates your edited payload against each toggle, so the defense chain is visible as code, not as slogans.
Core Architectural Principles
- Concatenated SQL admits tautologies that dump all rows; bound $1 parameters return zero-row results.
- CSP with a response nonce blocks injected inline scripts even when escaping was forgotten.
- SameSite Lax/Strict plus synchronizer tokens starve cross-origin forged POSTs of the session cookie.
Answer structurally, not tactically: prepared statements for injection, context-aware output encoding plus CSP for XSS, double-submit or synchronizer tokens with SameSite for CSRF. Then show depth by noting XSS exfiltration is capped by HttpOnly cookies and that WAFs are a compensating control, not the design.
Each defense adds developer ceremony (binding parameters, nonce plumbing, token state) in exchange for eliminating an entire bug class.