CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A security researcher finds that a file-permission-checking function in an application checks whether a user has access to a file, but a brief delay occurs before the file is actually opened. An attacker exploits this delay by swapping the file with a symbolic link to a sensitive file after the check but before the open. Which vulnerability class does this represent?
- ABuffer overflow
- BCross-site request forgery
- CInsecure direct object reference
- DTime-of-check to time-of-use (TOCTOU) race condition
Show answer & explanationAnswer & explanation
Correct answer: D. Time-of-check to time-of-use (TOCTOU) race condition
Exploiting the gap between when a resource is checked and when it is used, by swapping the resource in that window, is the defining characteristic of a TOCTOU race condition.
Why the other options are wrong
- A. Buffer overflow involves memory bounds, not timing between check and use.
- B. CSRF exploits authenticated sessions to force actions, unrelated to timing gaps in file access.
- C. IDOR involves referencing objects directly without authorization checks, not a timing race.
TOCTOU Race Condition
A vulnerability where a resource's state changes between the time it is checked and the time it is used, allowing an attacker to substitute a different resource.
- Common in file-system operations
- Also called a 'check-then-act' flaw
- Mitigated by atomic operations or file locking
Memory trick: Check now, swap fast, use later — the race is won in the gap.