SQL Injection – a technique where malicious users can inject SQL commands into an SQL statement, via web page input. • SQL Injection Based on 1=1 is Always True • SQL Injection Based on ""="" is Always True • SQL Injection Based on Batched SQL Statements