CompTIA CySA+ (CS0-003)Security OperationsEasy

A security analyst is reviewing web server access logs and notices the following entries: ``` 192.168.1.1 - - [26/Oct/2023:10:30:01 +0000] "GET /index.php?id=1 UNION SELECT 1,2,3,4,5-- - HTTP/1.1" 200 1234 192.168.1.1 - - [26/Oct/2023:10:30:02 +0000] "GET /index.php?id=1 AND 1=1-- - HTTP/1.1" 200 1234 192.168.1.1 - - [26/Oct/2023:10:30:03 +0000] "GET /index.php?id=1 AND 1=2-- - HTTP/1.1" 404 98 ``` Which type of attack is being attempted against the web server?

  1. ADirectory Traversal
  2. BCross-Site Scripting (XSS)
  3. CBuffer Overflow
  4. DSQL Injection
Show answer & explanation

Correct answer: D. SQL Injection

The log entries clearly show attempts to manipulate the `id` parameter with SQL keywords like `UNION SELECT`, `AND 1=1`, and `AND 1=2`. These constructs are characteristic of SQL injection attacks, where an attacker tries to inject malicious SQL code into input fields to compromise the database.

Why the other options are wrong

  • A. Directory traversal attempts to access files outside the web root (e.g., `../../etc/passwd`), which is not present in these parameters.
  • B. XSS involves injecting client-side scripts (e.g., JavaScript) into web pages, which would manifest differently in URL parameters (e.g., `<script>alert(1)</script>`).
  • C. Buffer overflows exploit memory management vulnerabilities and are typically not performed directly via URL parameters in this manner, nor would they generate these specific log entries.

SQL Injection

SQL injection is a web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. This can enable the attacker to view, modify, or delete data, execute administrative operations, or recover the contents of any file present on the database server.

  • Exploits improper input validation in web applications.
  • Uses SQL keywords (e.g., UNION, SELECT, AND) in user input.
  • Can lead to data compromise, unauthorized access, or remote code execution.

Memory trick: Web app attacks target the weakest links in the chain.

More Security Operations questions