Typing it in as someone’s name is not a joke either. This is known as an SQL injection attack (named after the popular database system SQL; sometimes pronounced like “sequel”). It involves entering malicious code via the URL of an online form and hoping whoever is in charge of the database has not put enough precautions in place.