โ† All OSCP Flashcard Decks

Web Application Attacks Flashcards

7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Web Application Attacks flashcards as text
  1. Which SQL injection technique retrieves data by asking the database true/false questions when no output is directly visible?

    Answer: Boolean-based blind injection

    Boolean-based blind SQLi infers data by sending queries that return different responses based on true/false conditions, without requiring visible output.

  2. What does the SLEEP() function in a SQL injection payload help an attacker determine?

    Answer: Whether the injection point exists via time delay

    SLEEP() is used in time-based blind SQLi to confirm a vulnerable injection point by causing a measurable delay in the server's response.

  3. Which tool is commonly used in OSCP labs to automate SQL injection discovery and exploitation?

    Answer: SQLmap

    SQLmap is an open-source tool that automates detection and exploitation of SQL injection flaws, widely used during OSCP penetration tests.

  4. In a Local File Inclusion (LFI) vulnerability, which of the following payloads is used to traverse directories and read /etc/passwd?

    Answer: ../../../etc/passwd

    Path traversal sequences (../) are used in LFI to navigate up the directory tree and access files outside the web root such as /etc/passwd.

  5. Which HTTP method is most commonly exploited to upload a malicious web shell to a vulnerable web server?

    Answer: PUT

    The HTTP PUT method allows clients to upload files to a server; if misconfigured, attackers can upload a web shell granting remote code execution.

  6. What is the primary goal of directory brute-forcing with a tool like Gobuster during a web application assessment?

    Answer: Discover hidden directories and files not linked on the site

    Gobuster brute-forces URIs using wordlists to uncover hidden directories, files, and endpoints that may expose sensitive functionality or content.

  7. Which Burp Suite feature allows an attacker to intercept and modify HTTP requests between a browser and a web server?

    Answer: Proxy

    Burp Suite's Proxy intercepts HTTP/HTTPS traffic between the browser and server, allowing the tester to view, modify, and replay requests in real time.