โ† All OSCP Flashcard Decks

Web Application Attacks Flashcards

6 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Web Application Attacks flashcards as text
  1. What type of SQL injection allows an attacker to retrieve data by asking the database true/false questions?

    Answer: Boolean-based blind SQL injection

    Boolean-based blind SQL injection infers data one bit at a time by submitting queries that return different responses based on whether the condition is true or false.

  2. Which SQLmap flag is used to attempt to read files from the target server's filesystem?

    Answer: --file-read

    The --file-read flag in SQLmap attempts to read a file from the database server's filesystem using database functions like LOAD_FILE() in MySQL.

  3. What is a Local File Inclusion (LFI) vulnerability in web applications?

    Answer: An application that allows reading local server files by manipulating file path parameters

    LFI occurs when an application includes files based on user-supplied input without proper validation, allowing an attacker to read sensitive server files using path traversal.

  4. What is the purpose of using Burp Suite's Intruder module during OSCP web application testing?

    Answer: Automated attacks like brute-forcing, fuzzing, and parameter manipulation

    Burp Suite Intruder automates customized attacks against web applications, including credential brute-forcing, parameter fuzzing, and injection payload delivery.

  5. Which HTTP method, if enabled on a web server, can allow an attacker to upload malicious files?

    Answer: PUT

    The HTTP PUT method is designed to upload files to a web server; if improperly enabled, it allows attackers to upload web shells or malicious scripts.

  6. What vulnerability exists when a web application passes user-supplied input directly to a system shell command?

    Answer: OS Command Injection

    OS Command Injection occurs when user input is concatenated into shell commands without sanitization, allowing attackers to execute arbitrary system commands.