CompTIA CySA+ (CS0-003)Security OperationsHard

A security analyst is reviewing a custom web application's access logs and identifies the following requests originating from a single IP address (10.10.10.5): ``` GET /api/v1/users?search=admin%27%20OR%20%271%27%3D%271 HTTP/1.1 GET /api/v1/products?category=electronics%27%3B%20WAITFOR%20DELAY%20%270%3A0%3A5%27--%20 HTTP/1.1 GET /api/v1/orders?id=123%20AND%20SUBSTRING%28version%28%29%2C1%2C1%29%3D%275%27 HTTP/1.1 ``` Which type of attack is being attempted, and what specific variant is indicated by the second and third entries?

  1. ACommand Injection; OS Command Injection
  2. BCross-Site Scripting (XSS); Reflected XSS
  3. CXML External Entity (XXE); Out-of-band XXE
  4. DSQL Injection; Time-based Blind SQL Injection
Show answer & explanation

Correct answer: D. SQL Injection; Time-based Blind SQL Injection

The requests show classic SQL injection payloads: `admin' OR '1'='1` (boolean-based), `WAITFOR DELAY` (time-based), and `SUBSTRING(version(),1,1)='5'` (error/boolean-based). Specifically, the `WAITFOR DELAY` command indicates a time-based blind SQL injection, where the attacker infers information based on the server's response time. The `SUBSTRING` query combined with a conditional check also suggests a blind SQL injection variant.

Why the other options are wrong

  • A. Command injection targets the underlying operating system and would use OS commands (e.g., `& dir`, `; ls`), not SQL-specific functions.
  • B. XSS involves injecting client-side scripts, not SQL keywords or database functions. Reflected XSS is a delivery mechanism, not a type of payload.
  • C. XXE attacks involve external XML entities and would manifest as XML payloads, which are not present in these URL parameters.

Blind SQL Injection

Blind SQL Injection (SQLi) is a type of SQL injection where the attacker cannot see the results of their malicious query directly within the application's response. Instead, they infer information by observing the application's behavior (e.g., response times, error messages, or subtle differences in content) to determine if a condition is true or false.

  • No direct data retrieval in the response.
  • Relies on server behavior (time delays, error messages, boolean logic).
  • Includes Boolean-based, Error-based, and Time-based variants.

Memory trick: SQL injection attacks are like secretly talking to the database.

More Security Operations questions