Web Application Penetration Testing Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Web Application Penetration Testing flashcards as text
During a web application test, you discover a parameter that reflects user input directly in the HTML response without encoding. Which vulnerability is MOST likely present?
Answer: Reflected XSS
When user input is reflected back in the HTML response without sanitization or encoding, it indicates a Reflected Cross-Site Scripting (XSS) vulnerability.
What does the HTTP response header 'X-Frame-Options: DENY' protect against?
Answer: Clickjacking attacks
X-Frame-Options: DENY prevents the page from being embedded in an iframe, protecting against clickjacking attacks.
An attacker crafts a URL like: http://example.com/page?id=1 UNION SELECT username,password FROM users--. What attack is this?
Answer: Union-based SQL Injection
A UNION SELECT statement appended to a query is the hallmark of Union-based SQL Injection, used to retrieve data from other tables.
Which Burp Suite tool is best for automatically testing all parameters in a web request for common vulnerabilities?
Answer: Burp Scanner
Burp Scanner automatically crawls and audits web applications for a wide range of vulnerabilities across all parameters.
What is the primary purpose of the 'robots.txt' file in web application reconnaissance?
Answer: It can reveal hidden directories and sensitive paths that the admin wants to hide from search engines
robots.txt lists directories the site owner wants search engines to ignore, which often inadvertently reveals sensitive or hidden paths to attackers.
During testing you find the URL: http://site.com/download?file=../../../etc/passwd. What vulnerability does this exploit?
Answer: Local File Inclusion / Directory Traversal
Using ../ sequences to navigate outside the intended directory to access system files is a Directory Traversal (Path Traversal) / Local File Inclusion attack.
Which HTTP method should you test for on web forms to check if the server improperly handles data modification via GET requests?
Answer: GET
Testing whether state-changing actions can be triggered via GET requests is important because it bypasses CSRF protections that rely on POST-only endpoints.