Web Application Attacks for GIAC Certified Incident Handler (GCIH)
This page covers the Web Application Attacks domain of the GIAC Certified Incident Handler (GCIH) certification. Master Cybersecurity offers 29 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Ryan, a malicious hacker submits Cross-Site Scripting (XSS) exploit code to the Website of Internet forum for online discussion. When a user visits the infected Web page, code gets automatically executed and Ryan can easily perform acts like account hijacking, history theft etc. Which of the following types of Cross-Site Scripting attack Ryan intends to do?- A. Non persistent
- B. Document Object Model (DOM)
- C. SAX
- D. Persistent
Explanation
The correct answer is: D. Persistent.
Submitting exploit code to a discussion forum so that it is stored and then executes for every visitor who views the page is persistent cross-site scripting, also called stored cross-site scripting. The distinguishing feature is that the payload is saved on the server and delivered to victims as part of ordinary content, so no individual has to be tricked into following a crafted link and a single submission can affect everyone who reads the thread. That reach is what makes it the more serious variant. Non-persistent, or reflected, scripting requires the payload to travel in each request, so the attacker must induce every victim to visit a prepared link. A document object model based attack executes entirely through client-side script manipulating the page, without the payload necessarily reaching the server. SAX is an interface for parsing XML documents and is not a category of scripting attack at all.
Question 2
John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. On the We-are-secure login page, he enters ='or''=' as a username and successfully logs in to the user page of the Web site. The we-are-secure login page is vulnerable to a __________.- A. Dictionary attack
- B. SQL injection attack
- C. Replay attack
- D. Land attack
Explanation
The correct answer is: B. SQL injection attack.
The string entered as a username consists of quote and equality characters arranged so that the condition the application builds becomes universally true, and the result is a successful logon without a valid credential. That is SQL injection: because the input is concatenated into the authentication query rather than passed as a parameter, the attacker is able to change the logic of the statement instead of merely supplying a value to it. The remedy is parameterised statements, which send the query structure and the data separately so that no input can alter the structure. The other options do not match what happened. A dictionary attack would submit many candidate passwords and would appear as repeated failures. A replay attack presents a previously captured credential. A land attack sends a packet whose source and destination are the same in order to disturb a network stack, which is a denial of service technique unrelated to authentication logic.
Question 3
John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. He performs Web vulnerability scanning on the We-are-secure server. The output of the scanning test is as follows: C:\whisker.pl -h target_IP_address -- whisker / v1.4.0 / rain forest puppy / www.wiretrip.net -- = - = - = - = - = = Host: target_IP_address = Server: Apache/1.3.12 (Win32) ApacheJServ/1.1 mod_ssl/2.6.4 OpenSSL/0.9.5a mod_perl/1.22 + 200 OK: HEAD /cgi-bin/printenv John recognizes /cgi-bin/printenv vulnerability ('Printenv' vulnerability) in the We_are_secure server. Which of the following statements about 'Printenv' vulnerability are true? Each correct answer represents a complete solution. (Choose all that apply.)- A. This vulnerability helps in a cross site scripting attack.
- B. 'Printenv' vulnerability maintains a log file of user activities on the Website, which may be useful for the attacker.
- C. The countermeasure to 'printenv' vulnerability is to remove the CGI script.
- D. With the help of 'printenv' vulnerability, an attacker can input specially crafted links and/or other malicious scripts.
Explanation
The correct answers are: A. This vulnerability helps in a cross site scripting attack., C. The countermeasure to 'printenv' vulnerability is to remove the CGI script., D. With the help of 'printenv' vulnerability, an attacker can input specially crafted links and/or other malicious scripts..
The scanner has found the printenv script present in the web server's script directory, and the reason that matters is that printenv echoes its input back in the response. Because the returned data is not encoded, an attacker can supply crafted links or script and have it reflected to whoever follows the link, which makes the script a vehicle for cross-site scripting. The countermeasure is straightforward: printenv is a sample script shipped for diagnostic purposes and no production site needs it, so removing it eliminates the exposure entirely rather than attempting to filter what reaches it. The statement that does not hold is the one describing printenv as maintaining a log file of user activity. It keeps no log, since its function is to print the environment variables of the request, and the risk comes from that output being reflected without encoding rather than from any record it retains.
Question 4
John works as a Professional Penetration Tester. He has been assigned a project to test the Website security of www.we-are-secure Inc. On the We-are-secure Website login page, he enters ='or''=' as a username and successfully logs on to the user page of the Web site. Now, John asks the we-aresecure Inc. to improve the login page PHP script. Which of the following suggestions can John give to improve the security of the we-are-secure Website login page from the SQL injection attack?- A. Use the escapeshellarg() function
- B. Use the session_regenerate_id() function
- C. Use the mysql_real_escape_string() function for escaping input
- D. Use the escapeshellcmd() function
Explanation
The correct answer is: C. Use the mysql_real_escape_string() function for escaping input.
The login page concatenated input into its authentication query, which is why quote and equality characters submitted as a username were able to make the condition always true. The appropriate improvement in a script talking to this database is to escape the input with the function provided for that purpose, so that quote characters in the value are neutralised and cannot terminate the literal or alter the structure of the statement. Parameterised statements are the stronger modern answer to the same problem, and escaping is the measure available among these options. The other functions belong to different problems. The two shell escaping functions neutralise metacharacters for a command interpreter, which protects against command injection rather than against a database parser. Regenerating the session identifier is a session management measure used to defeat fixation, and it does nothing about how the authentication query is built.
Question 5
Which of the following functions can be used as a countermeasure to a Shell Injection attack? Each correct answer represents a complete solution. (Choose all that apply.)- A. escapeshellarg()
- B. mysql_real_escape_string()
- C. regenerateid()
- D. escapeshellcmd()
Explanation
The correct answers are: A. escapeshellarg(), D. escapeshellcmd().
Shell injection arises when input is interpolated into a string that is handed to a command interpreter, so the countermeasures are the functions that neutralise the characters a shell treats as syntax. escapeshellarg quotes a value and escapes any embedded quote so the whole thing is delivered as a single argument, and escapeshellcmd escapes the metacharacters a shell would otherwise read as command separators or redirection. Applying the appropriate one before building the command line prevents the input from being taken as anything other than data. The other options belong to different vulnerability classes. The function that escapes strings for a database protects against SQL injection, which is the same idea of neutralising syntax but aimed at a query parser rather than a shell. Regenerating an identifier concerns session management and is used to defeat session fixation, so it has no bearing on how a command line is assembled.
Other GIAC Certified Incident Handler (GCIH) domains
- Exploitation and Privilege Escalation (20 questions)
- Incident Response and Cyber Investigation (57 questions)
- Malware, Persistence, and Covering Tracks (105 questions)
- Network Attacks and Denial of Service (86 questions)
- Password and Credential Attacks (21 questions)
- Reconnaissance, Scanning, and Mapping (86 questions)