Web Application Penetration Testing Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Web Application Penetration Testing flashcards as text
During a web application test, you find an input field that passes data to a system command. The input 'test; ls -la' returns a directory listing. What vulnerability is this?
Answer: Remote Code Execution via Command Injection
Command Injection occurs when user input is passed unsanitized to a system shell command, allowing attackers to execute arbitrary OS commands using separators like ; or &&.
What is the OWASP Top 10 and why is it important for web penetration testers?
Answer: A regularly updated list of the most critical web application security risks used as a benchmark for testing
The OWASP Top 10 is a community-maintained document listing the most critical web application security risks, providing penetration testers with a prioritized framework for assessment.
What does 'Content Security Policy' (CSP) primarily defend against?
Answer: XSS by controlling which sources can execute scripts on the page
CSP is an HTTP response header that tells browsers which content sources are trusted, mitigating XSS by blocking execution of scripts from unauthorized origins.
When testing authentication, you notice the application uses Base64-encoded values in a cookie rather than a session ID. Why is this a security concern?
Answer: Base64 is encoding, not encryption — the data can be trivially decoded to reveal sensitive information
Base64 is an encoding scheme, not encryption — anyone who intercepts the cookie can decode it instantly, potentially exposing usernames, roles, or other sensitive data.
Which of the following best describes a 'time-based blind SQL injection' technique?
Answer: Using conditional SQL statements that cause the database to pause (SLEEP/WAITFOR) to infer boolean responses
Time-based blind SQL injection uses functions like SLEEP() or WAITFOR DELAY to cause measurable delays, inferring true/false conditions when no data is returned in the response.
What is the main purpose of the 'Secure' flag on an HTTP cookie?
Answer: Ensures the cookie is only transmitted over HTTPS connections
The Secure flag instructs the browser to only send the cookie over encrypted HTTPS connections, preventing it from being intercepted over plain HTTP.
During a web application test, you find a redirect URL in a parameter: http://example.com/redirect?url=http://evil.com. What vulnerability does this represent?
Answer: Open Redirect
An Open Redirect occurs when an application redirects users to attacker-controlled URLs without validation, commonly used in phishing attacks to exploit trust in the legitimate domain.