SQL Injection and Database Hacking
SQL injection is a flaw in the application's code, so the fix is in the code. Here is how it works and what the law says.
A bank's database is where the account numbers, balances, KYC documents and card data actually live. Database hacking is any unauthorised access to that store, and SQL injection is the best-known technical route: an attacker uses an ordinary input box on a website to slip in instructions the database then obeys.
Most database breaches, though, are less clever. A stolen administrator password, an unpatched database server, a backup copy left on an open server, or an insider with more access than the job needs. The exam covers both the technique and the controls.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
How SQL Injection Works
SQL is the language applications use to ask a database for data. When a customer types a loan reference into a tracking page, the application builds a SQL question around it. If the developer pastes whatever the user typed straight into that question, a user can type characters that change what the question means: instead of 'show me loan 1234', the database is effectively asked 'show me every loan'.
The flaw is in the application's code, not the database or the network. That is why a network firewall, which sees an ordinary web request on an allowed port, does not stop it. The fix is to write the code so user input is always treated as data and never as part of the command.
Routes Into a Database and the Matching Control
| Route | Control |
|---|---|
| SQL injection through a web or app form | Parameterised queries (prepared statements), input validation, secure coding against OWASP guidance, application testing |
| Stolen or default database administrator password | Centralised access management, MFA and monitoring for privileged accounts, no default passwords |
| Insider with excessive access | Least privilege, role-based access, database activity monitoring, maker-checker |
| Unpatched database server | Patch management, vulnerability assessment |
| Exposed backup or test copy with real data | Encryption at rest, data masking in test environments, asset inventory |
What RBI Expects
RBI's 2026 cybersecurity directions require banks to build applications against vulnerabilities using best practices such as OWASP (the Open Web Application Security Project), to adopt defence in depth, and to test applications beyond just the OWASP top 10 list. Privileged access to databases must be managed, logged and monitored through appropriate controls. Customer-facing systems in the DMZ must go through vulnerability assessment at least every six months and penetration testing at least every 12 months.
Quick practice on banking operations. No signup.
Legal Consequences
| Provision | Effect |
|---|---|
| IT Act s.43(a), (b), (i) | Accessing a computer system, downloading or extracting data, or altering or deleting information without permission: liability to pay compensation |
| IT Act s.66 | The same acts done dishonestly or fraudulently: imprisonment up to three years, or fine up to ₹5 lakh, or both |
| IT Act s.43A | A body corporate negligent in protecting sensitive personal data, causing wrongful loss or gain: liable to pay compensation |
| DPDP Act, 2023 s.8(5) and s.8(6) | Duty to take reasonable security safeguards and to notify a breach to the Data Protection Board and affected persons; penalties up to ₹250 crore and ₹200 crore |
| CERT-In Directions, 2022 | Attacks on database servers, data breaches and data leaks must be reported to CERT-In within 6 hours |
DPDP Timing
The DPDP Act's data-security duties in section 8 come into force 18 months from 13 November 2025, that is in May 2027. The same notification brings in section 44(2), which removes section 43A from the IT Act. Until then, section 43A and its rules on sensitive personal data still apply. Study material written before November 2025 may not mention these dates at all.
How the IIBF Exam Tests This
- check_circleWhere the flaw lives: in the application's code. Options blaming the network or the database engine are distractors.
- check_circleThe fix: parameterised queries and input validation. 'Encrypt the database' and 'install a firewall' are the common wrong answers.
- check_circleCivil versus criminal: unauthorised data extraction is a section 43 compensation matter; with dishonest or fraudulent intent it is a section 66 offence.
- check_circleInsiders count: database hacking includes an employee misusing legitimate access, which is why least privilege appears in the controls.
FAQs
What is SQL injection in simple words?expand_more
A flaw where a website pastes user input straight into a database command, letting an attacker type something that changes the command, for example to read records they should never see.
How do banks prevent SQL injection?expand_more
Mainly in the code: parameterised queries so input is never run as a command, plus input validation, secure-coding standards such as OWASP, application security testing and least-privilege database accounts.
Can a firewall stop SQL injection?expand_more
A network firewall usually cannot, because the attack arrives as a normal web request. A web application firewall can block known patterns, but the reliable fix is secure code.
What is the punishment for hacking a database in India?expand_more
Unauthorised access or data extraction attracts compensation under section 43 of the IT Act. If done dishonestly or fraudulently, section 66 provides imprisonment up to three years, a fine up to ₹5 lakh, or both.
Next steps
- Vulnerabilitiesarrow_forward
- Firewalls & IDSarrow_forward
- Encryptionarrow_forward
- Section 43 & 43Aarrow_forward
120 questions, 2 hours, scored instantly.
