Web Application Attacks Flashcards
6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Web Application Attacks flashcards as text
What does SSRF (Server-Side Request Forgery) allow an attacker to do?
Answer: Make the server send requests to internal or external resources on the attacker's behalf
SSRF tricks the server into making HTTP requests to internal or external resources, potentially exposing internal services not accessible from the internet.
Which header injection vulnerability in HTTP responses can allow an attacker to inject additional HTTP headers or split responses?
Answer: HTTP response splitting
HTTP response splitting injects CRLF (\r\n) characters into user-controlled input that is placed into HTTP headers, allowing attackers to inject additional headers or craft fake responses.
When testing for SQL injection, which character is most commonly the first test to determine if input is vulnerable?
Answer: Single quote (')
A single quote is the most basic SQL injection test because it breaks the SQL string context and causes a syntax error or behavioral change if the input is unsanitized.
What is the purpose of the 'robots.txt' file and why is it relevant during OSCP web enumeration?
Answer: It tells search engine crawlers which pages to avoid, often revealing hidden directories
The robots.txt file instructs web crawlers to skip certain paths, but these disallowed paths often contain sensitive directories that attackers can directly browse.
During OSCP, you identify a PHP application. What common web shell one-liner could you attempt to upload?
Answer:
The PHP one-liner '' executes OS commands passed via the 'cmd' GET parameter, providing remote command execution on PHP servers.
What is the purpose of a Content Security Policy (CSP) header and how does it affect OSCP XSS exploitation?
Answer: It restricts which resources can be loaded and can block or mitigate XSS attacks
CSP is a browser security mechanism that specifies trusted content sources; a strict CSP can prevent XSS payloads from loading external scripts or executing inline JavaScript.