CompTIA CySA+ (CS0-003)Security OperationsMedium
A security analyst is reviewing web server access logs and notices the following entries originating from a single IP address (192.168.1.10) targeting a login page: ``` 192.168.1.10 - - [10/Nov/2023:10:30:01 +0000] "GET /login.php?username=admin' OR 1=1--&password=password HTTP/1.1" 200 4567 192.168.1.10 - - [10/Nov/2023:10:30:02 +0000] "GET /login.php?username=test'%20OR%20'a'='a&password=test HTTP/1.1" 200 4567 ``` What type of attack is indicated by these log entries?
- ASQL Injection
- BCommand Injection
- CCross-Site Scripting (XSS)
- DCross-Site Request Forgery (CSRF)
Show answer & explanationAnswer & explanation
Correct answer: A. SQL Injection
The log entries show crafted inputs in the `username` parameter that include SQL syntax like `' OR 1=1--` and `' OR 'a'='a`. These are classic SQL injection payloads designed to manipulate the database query and bypass authentication by making the `WHERE` clause always true. The `--` is used to comment out the rest of the original query.
Why the other options are wrong
- B. Command injection targets the execution of OS commands, not database queries, and would use different syntax (e.g., `&`, `|`, `;`).
- C. XSS involves injecting client-side scripts, typically JavaScript, into web pages, not manipulating database queries via login parameters.
- D. CSRF tricks a victim into sending an authenticated request, not directly manipulating input parameters with SQL syntax.
SQL Injection
A web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database, often to gain unauthorized access or extract data.
- Exploits improper input validation in web applications.
- Common payloads include `OR 1=1--`, `UNION SELECT`, `SLEEP()`, `WAITFOR DELAY`.
- Can lead to authentication bypass, data exfiltration, or remote code execution.
Memory trick: Web apps have flaws; SQL injection talks to the database.