Web Application Penetration Testing Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Web Application Penetration Testing flashcards as text
What is the key difference between Stored XSS and Reflected XSS?
Answer: Stored XSS persists in the database and executes for every visitor; Reflected XSS only executes for the victim who clicks a crafted link
Stored XSS saves the malicious payload server-side (e.g., in a database) so it fires for every user who views the infected page, whereas Reflected XSS is delivered via a crafted URL.
A web application uses MD5 to hash passwords without a salt. Why is this particularly dangerous?
Answer: Unsalted MD5 hashes are vulnerable to rainbow table attacks
Without a salt, identical passwords produce identical MD5 hashes, making them trivially crackable using precomputed rainbow tables.
Which tool is commonly used to perform automated SQL injection detection and exploitation during a penetration test?
Answer: SQLMap
SQLMap is the industry-standard open-source tool for automated detection and exploitation of SQL injection vulnerabilities.
What does CSRF (Cross-Site Request Forgery) primarily exploit?
Answer: The browser's trust in the authenticated user's session cookies
CSRF exploits the fact that browsers automatically include session cookies with every request, tricking an authenticated user's browser into making unauthorized requests.
When testing for Local File Inclusion (LFI), which file is a classic target on Linux systems to confirm successful exploitation?
Answer: /etc/passwd
/etc/passwd is the standard first test for LFI on Linux because it is readable by all users and its content is immediately recognizable.
What is the purpose of using 'null byte injection' (%00) in older web application LFI attacks?
Answer: To terminate a string early in PHP, bypassing file extension checks
In older PHP versions, %00 (null byte) terminates the string, allowing attackers to bypass appended extension checks like .php by making /etc/passwd%00 ignore the forced extension.
During a web app test, you observe a cookie set as: Set-Cookie: sessionid=abc123. What security attribute is critically missing?
Answer: HttpOnly and Secure flags
Missing HttpOnly (prevents JS access) and Secure (ensures HTTPS-only transmission) flags expose the session cookie to XSS theft and network interception respectively.