CompTIA CySA+ (CS0-003)Security OperationsMedium

A security analyst is reviewing web server access logs and notices the following entries originating from a single IP address (192.168.1.10) targeting a login page: ``` 192.168.1.10 - - [10/Nov/2023:10:30:01 +0000] "GET /login.php?username=admin' OR 1=1--&password=password HTTP/1.1" 200 4567 192.168.1.10 - - [10/Nov/2023:10:30:02 +0000] "GET /login.php?username=test'%20OR%20'a'='a&password=test HTTP/1.1" 200 4567 ``` What type of attack is indicated by these log entries?

  1. ASQL Injection
  2. BCommand Injection
  3. CCross-Site Scripting (XSS)
  4. DCross-Site Request Forgery (CSRF)
Show answer & explanation

Correct answer: A. SQL Injection

The log entries show crafted inputs in the `username` parameter that include SQL syntax like `' OR 1=1--` and `' OR 'a'='a`. These are classic SQL injection payloads designed to manipulate the database query and bypass authentication by making the `WHERE` clause always true. The `--` is used to comment out the rest of the original query.

Why the other options are wrong

  • B. Command injection targets the execution of OS commands, not database queries, and would use different syntax (e.g., `&`, `|`, `;`).
  • C. XSS involves injecting client-side scripts, typically JavaScript, into web pages, not manipulating database queries via login parameters.
  • D. CSRF tricks a victim into sending an authenticated request, not directly manipulating input parameters with SQL syntax.

SQL Injection

A web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database, often to gain unauthorized access or extract data.

  • Exploits improper input validation in web applications.
  • Common payloads include `OR 1=1--`, `UNION SELECT`, `SLEEP()`, `WAITFOR DELAY`.
  • Can lead to authentication bypass, data exfiltration, or remote code execution.

Memory trick: Web apps have flaws; SQL injection talks to the database.

More Security Operations questions