SQL- - SQL-, "" SQL, -, . ,
"SELECT * FROM `users` WHERE `username` = '$name'";
. "" , . , , , "OR 1 = 1",
"SELECT * FROM `users` WHERE `username` = '' OR 1=1";
1 1, , true , , , . , - . , - - "'; DROP TABLE users"; -,
"SELECT * FROM `users` WHERE `username` = ''; DROP TABLE `users`";--";
, , , ENTIRE users, .
SQL . SQL, -
"SELECT * FROM `users` WHERE `username` = '?'";
(WHERE username ), . , , . , . , .
, .