โ† All OSCP Flashcard Decks

Web Application Attacks Flashcards

7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Web Application Attacks flashcards as text
  1. Which vulnerability occurs when user-supplied input is reflected in a web page without proper sanitization and executes in a victim's browser?

    Answer: Cross-Site Scripting (XSS)

    XSS allows attackers to inject malicious scripts into web pages viewed by other users, potentially stealing cookies or performing actions on their behalf.

  2. When exploiting a Remote File Inclusion (RFI) vulnerability, what does the attacker typically host on their server?

    Answer: A malicious PHP web shell

    In RFI attacks, the attacker hosts a malicious script (commonly a PHP web shell) on their server, which the vulnerable application fetches and executes.

  3. What does the '--os-shell' flag in SQLmap attempt to do?

    Answer: Obtain an interactive OS shell via SQL injection

    SQLmap's --os-shell flag attempts to leverage SQL injection to achieve command execution and provide the attacker with an interactive operating system shell.

  4. Which file extension is most commonly associated with a web shell uploaded during a PHP application attack?

    Answer: .php

    PHP web shells use the .php extension so the web server interprets and executes the malicious code when the file is accessed via a browser or HTTP request.

  5. What type of attack involves tricking a victim into sending authenticated requests to a vulnerable web application without their knowledge?

    Answer: CSRF

    Cross-Site Request Forgery (CSRF) forges authenticated requests from a victim's browser to perform unintended actions on a web application where they are logged in.

  6. During a web application assessment, you notice the URL contains 'page=about'. Which vulnerability should you immediately test for?

    Answer: Local File Inclusion (LFI)

    A URL parameter that specifies a file or page name is a classic indicator of a potential LFI vulnerability, where user input directly controls file includes.

  7. Which Burp Suite tool is best suited for fuzzing parameters with multiple payloads to find injection points?

    Answer: Intruder

    Burp Intruder automates customized attacks by fuzzing parameters with payload lists, making it ideal for finding injection vulnerabilities across multiple positions.