CompTIA CySA+ (CS0-003)Security OperationsMedium
A web application firewall log shows the following request against a public e-commerce site: `192.168.1.15 - - [10/Mar/2024:14:22:07 +0000] "GET /products.php?id=1' UNION SELECT username,password FROM users-- HTTP/1.1" 200 1523` Which type of attack does this log entry MOST likely indicate?
- ACommand injection
- BDirectory traversal
- CSQL injection
- DCross-site scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: C. SQL injection
The request injects a `UNION SELECT` statement into the `id` parameter, attempting to append a second query that pulls usernames and passwords from the `users` table — a textbook SQL injection technique. The trailing `--` comments out the rest of the original query to keep the syntax valid.
Why the other options are wrong
- A. Command injection targets OS shell commands (e.g., ; whoami), not SQL syntax.
- B. Directory traversal uses sequences like ../../ to access files outside the web root.
- D. XSS would involve injected `<script>` tags, not SQL syntax.
SQL Injection Indicator
An attack technique where malicious SQL syntax is inserted into an input field to manipulate backend database queries.
- UNION SELECT combines results from an injected query
- Trailing -- or # comments out remaining original SQL
- Often targets parameters like id, search, or login fields
Memory trick: UNION SELECT unions the attacker with your data.