Web Application Attacks Flashcards
7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Web Application Attacks flashcards as text
Which vulnerability occurs when user-supplied input is reflected in a web page without proper sanitization and executes in a victim's browser?
Answer: Cross-Site Scripting (XSS)
XSS allows attackers to inject malicious scripts into web pages viewed by other users, potentially stealing cookies or performing actions on their behalf.
When exploiting a Remote File Inclusion (RFI) vulnerability, what does the attacker typically host on their server?
Answer: A malicious PHP web shell
In RFI attacks, the attacker hosts a malicious script (commonly a PHP web shell) on their server, which the vulnerable application fetches and executes.
What does the '--os-shell' flag in SQLmap attempt to do?
Answer: Obtain an interactive OS shell via SQL injection
SQLmap's --os-shell flag attempts to leverage SQL injection to achieve command execution and provide the attacker with an interactive operating system shell.
Which file extension is most commonly associated with a web shell uploaded during a PHP application attack?
Answer: .php
PHP web shells use the .php extension so the web server interprets and executes the malicious code when the file is accessed via a browser or HTTP request.
What type of attack involves tricking a victim into sending authenticated requests to a vulnerable web application without their knowledge?
Answer: CSRF
Cross-Site Request Forgery (CSRF) forges authenticated requests from a victim's browser to perform unintended actions on a web application where they are logged in.
During a web application assessment, you notice the URL contains 'page=about'. Which vulnerability should you immediately test for?
Answer: Local File Inclusion (LFI)
A URL parameter that specifies a file or page name is a classic indicator of a potential LFI vulnerability, where user input directly controls file includes.
Which Burp Suite tool is best suited for fuzzing parameters with multiple payloads to find injection points?
Answer: Intruder
Burp Intruder automates customized attacks by fuzzing parameters with payload lists, making it ideal for finding injection vulnerabilities across multiple positions.