← All EJPT Flashcard Decks

Web Application Security & Testing Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Web Application Security & Testing flashcards as text
  1. When performing a web application penetration test, you find the application uses JWT tokens for authentication. What is a common vulnerability to test for?

    Answer: Using the 'none' algorithm to bypass signature verification

    Some JWT libraries accept 'alg: none', removing the signature requirement entirely, allowing attackers to forge tokens by setting the algorithm to none and stripping the signature.

  2. Which technique can be used to test for blind SQL injection when the application produces no visible error messages?

    Answer: Sending time-delay payloads like SLEEP() or WAITFOR DELAY

    Time-based blind SQL injection uses conditional delay functions (e.g., SLEEP(5)) to infer true/false conditions from how long the server takes to respond.

  3. What is 'subdomain takeover' in the context of web application security testing?

    Answer: Claiming an abandoned subdomain's external resource to serve malicious content under the target's domain

    Subdomain takeover occurs when a DNS CNAME points to an external service that has been deprovisioned; an attacker can register that service and serve content under the victim's subdomain.

  4. In a web application test, which HTTP status code suggests that a resource exists but is intentionally hidden or restricted, as opposed to truly not existing?

    Answer: 403 Forbidden

    A 403 Forbidden response confirms the resource exists but access is denied, making it a valuable signal during directory enumeration that something interesting may be behind the restriction.

  5. What is the primary goal of testing for 'business logic flaws' in web applications?

    Answer: Discovering ways to abuse legitimate application functionality to achieve unintended outcomes

    Business logic flaws involve exploiting the intended workflow of an application — such as skipping payment steps or applying discounts multiple times — rather than technical injection vulnerabilities.

  6. During reconnaissance on a web application, which technique involves looking at the website's source HTML, JavaScript files, and comments for sensitive information?

    Answer: Passive information gathering

    Passive information gathering from client-side assets like HTML comments, JS files, and metadata can reveal API keys, internal URLs, developer notes, and hidden endpoints without sending active attack traffic.

  7. Which of the following payloads is most indicative of a Server-Side Template Injection (SSTI) vulnerability?

    Answer: {{7*7}} rendering as 49 in the response

    If the expression {{7*7}} is evaluated and returns 49 in the server's response, it confirms the template engine is executing user-supplied input, indicating SSTI.