Web Application Attacks Flashcards
6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Web Application Attacks flashcards as text
What is the primary goal of directory traversal attacks in web application penetration testing?
Answer: Accessing files and directories outside the web root by manipulating file path variables
Directory traversal (path traversal) exploits insufficient input validation to access files outside the intended directory, such as reading /etc/passwd on Linux.
What does a 'web shell' provide an attacker after successful web application exploitation?
Answer: Remote command execution through an HTTP/HTTPS channel
A web shell is a script uploaded to a compromised web server that provides remote command execution capabilities over HTTP, acting as a backdoor accessible via a browser.
During OSCP, you find a web application with an unrestricted file upload. What is the most effective way to exploit this?
Answer: Upload a malicious web shell script in a language the server executes
Unrestricted file upload vulnerabilities are best exploited by uploading a web shell (e.g., PHP shell on PHP servers) that can then be accessed to execute commands.
What is the difference between reflected and stored Cross-Site Scripting (XSS)?
Answer: Reflected XSS is returned immediately in a response; stored XSS is saved and executed later for all visitors
Reflected XSS requires the victim to click a malicious link, while stored XSS persists in the application (e.g., a database) and executes for every user who views the affected page.
What Nikto command would you use to scan a web server at 192.168.1.10 on port 8080?
Answer: nikto -h 192.168.1.10 -p 8080
The correct Nikto syntax uses -h for the host and -p for the port, so 'nikto -h 192.168.1.10 -p 8080' scans the specified host and port for common vulnerabilities.
What is XML External Entity (XXE) injection and what can it be used for in OSCP?
Answer: Exploiting XML parsers to read local files, perform SSRF, or execute code
XXE injection exploits XML processors that allow external entity references, enabling attackers to read local files, probe internal services, or in some cases achieve remote code execution.