CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 14: ECSAV10: EC-Council Certified Security Analyst

James is an attacker who wants to attack XYZ Inc. He has performed reconnaissance over all the publicly available resources of the company and identified the official company website http://xyz.com. He scanned all the pages of the company website to find for any potential vulnerabilities to exploit. Finally, in the us…

Nội dung câu hỏi

James is an attacker who wants to attack XYZ Inc. He has performed reconnaissance over all the publicly available resources of the company and identified the official company website http://xyz.com. He scanned all the pages of the company website to find for any potential vulnerabilities to exploit. Finally, in the user account login page of the company's website, he found a user login form which consists of several fields that accepts user inputs like username and password. He also found than any non-validated query that is requested can be directly communicated to the active directory and enable unauthorized users to obtain direct access to the databases. Since James knew an employee named Jason from XYZ Inc., he enters a valid username `jason` and injects `jason)(&))` in the username field. In the password field, James enters `blah` and clicks Submit button. Since the complete URL string entered by James becomes `(&(USER=jason)(&))(PASS=blah)),` only the first filter is processed by the Microsoft Active Directory, that is, the query `(&(USER=jason)(&))` is processed. Since this query always stands true, James successfully logs into the user account without a valid password of Jason. In the above scenario, identify the type of attack performed by James?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. LDAP injection attack
  2. B. HTML embedding attack — đáp án hiện tại
  3. C. Shell injection attack
  4. D. File injection attack

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề