Web Application Attacks Flashcards
7 cards from real OSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Web Application Attacks flashcards as text
In a UNION-based SQL injection attack, what must be true about the injected SELECT statement?
Answer: It must have the same number of columns as the original query
UNION-based SQLi requires the injected SELECT statement to return the same number of columns as the original query so the combined result set is valid.
What is a common technique to bypass file upload filters that block PHP extensions?
Answer: Use double extensions like shell.php.jpg
Using double extensions such as shell.php.jpg can bypass naive file extension checks if the server processes the PHP extension before the final jpg extension.
Which tool is commonly used during OSCP to enumerate web application directories using a wordlist?
Answer: Dirb
Dirb is a web content scanner that uses dictionary-based attacks to brute-force directories and files on web servers, commonly used for web enumeration during OSCP.
What does an attacker gain when they successfully exploit an XML External Entity (XXE) vulnerability?
Answer: Ability to read arbitrary local files or perform SSRF
XXE vulnerabilities allow attackers to define external XML entities that reference local files or internal URLs, enabling file disclosure or Server-Side Request Forgery.
When testing for reflected XSS, which of the following payloads is a basic proof-of-concept?
Answer: alert(1)
The classic XSS PoC payload alert(1) tests whether user input is reflected unsanitized in the page and executes JavaScript in the browser.
What is the purpose of using 'nikto' during a web application penetration test?
Answer: Scan for known web server vulnerabilities and misconfigurations
Nikto is a web server scanner that checks for dangerous files, outdated software, and common misconfigurations, helping identify attack surface quickly.
An attacker discovers a web shell at /uploads/shell.php and sends a GET request with '?cmd=id'. What does this confirm?
Answer: Remote code execution through the uploaded shell is successful
A successful response to ?cmd=id showing the server's user identity confirms remote code execution is working via the uploaded PHP web shell.