Member-only story
The Devious Genius of “Prompt Injection Attacks”
An old trick, revamped for the new age of AI
data:image/s3,"s3://crabby-images/cbc62/cbc62efcd9fe7a495c174259df09552ceb630524" alt=""
Introduction
For years, one of the easiest ways to break into a website was to use an “SQL injection” attack.
And now a new version of this old malicious behavior is coming back …
… hypercharged for the new age of AI!
Let’s unpack this. I promise you, it’s a bit nerdy but it’s interesting as heck.
SQL Injection
First off, what is an “SQL injection attack”?
Well, SQL is a programming language commonly used when storing or retrieving data from a database. A lot of businesses, government agencies, blogs, entertainment sites — you name it — use SQL when they’re storing your data or retrieving it.
Let’s say you’re the customer of a website that stores and displays your to-do list items. When you log in, there’ll be a little input field where you type in a new item, right? If you input “get more garbage bags”, the website will send an SQL command to its database that stores “get more garbage bags” as your new item. QED.
So here’s how an SQL injection works.