C#

.NET data access runs through Entity Framework and EF Core. LINQ queries translate to parameterized SQL and are safe; the raw-SQL APIs are where injection enters, and C# string interpolation makes the unsafe form look deceptively similar to the safe one.

The ORM here#

  • Entity Framework: FromSqlRaw and ExecuteSqlRaw fed concatenated or interpolated strings, versus the parameterizing FromSqlInterpolated form.

The shared pattern#

EF Core offers two raw methods that read almost identically: FromSqlInterpolated captures an interpolated string as a parameterized FormattableString and is safe, while FromSqlRaw takes a plain string and runs it verbatim. A developer who builds a $"..." interpolated string and passes it to FromSqlRaw (or concatenates into it) has written injectable code that looks like the safe call. Identifiers are the one case the safe method cannot help with, but it fails closed: FromSqlInterpolated turns each hole into a DbParameter, and since a parameter cannot stand in for a table or column name, an interpolated identifier makes the database reject the query rather than execute it. Identifier injection therefore needs FromSqlRaw, concatenation, or a pre-formatted string. The tell is Raw fed anything the caller influenced, or an identifier built into the SQL text by hand.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more