CompTIA CySA+ (CS0-003)Incident Response and ManagementEasy

A security analyst is reviewing logs from a web server after an alert for unusual activity. They find the following entries: ``` [10/Oct/2023:14:35:01 +0000] "GET /index.php HTTP/1.1" 200 1234 "-" "Mozilla/5.0" [10/Oct/2023:14:35:05 +0000] "GET /admin/login.php HTTP/1.1" 200 5678 "-" "Mozilla/5.0" [10/Oct/2023:14:35:08 +0000] "POST /admin/login.php HTTP/1.1" 302 0 "-" "Mozilla/5.0" [10/Oct/2023:14:35:10 +0000] "GET /admin/dashboard.php HTTP/1.1" 200 9876 "-" "Mozilla/5.0" [10/Oct/2023:14:35:12 +0000] "GET /admin/users.php?id=1' UNION SELECT @@version -- - HTTP/1.1" 400 150 "-" "SQLi_Scanner/1.0" [10/Oct/2023:14:35:13 +0000] "GET /admin/users.php?id=1' ORDER BY 100 -- - HTTP/1.1" 400 150 "-" "SQLi_Scanner/1.0" ``` Which type of attack is clearly indicated by the log entries starting at 14:35:12?

  1. ACross-Site Scripting (XSS)
  2. BDirectory Traversal
  3. CSQL Injection (SQLi)
  4. DDenial of Service (DoS)
Show answer & explanation

Correct answer: C. SQL Injection (SQLi)

The log entries at 14:35:12 and 14:35:13 clearly show attempts to inject SQL commands into the `id` parameter, using keywords like `UNION SELECT`, `@@version`, `ORDER BY`, and SQL comment delimiters (`-- -`). These are classic indicators of a SQL Injection (SQLi) attack.

Why the other options are wrong

  • A. XSS involves injecting client-side scripts, typically JavaScript, which would appear in request parameters or body, but not with SQL keywords.
  • B. Directory traversal attempts involve manipulating paths (e.g., `../`, `..\`) to access restricted files outside the intended web root.
  • D. DoS attacks aim to make a service unavailable, often through high traffic volumes, not specific crafted SQL queries.

SQL Injection (SQLi)

A web security vulnerability that allows an attacker to interfere with the queries an application makes to its database.

  • Achieved by injecting SQL commands into input fields.
  • Can lead to data theft, alteration, or denial of service.
  • Common keywords: UNION, SELECT, ORDER BY, @@version.

Memory trick: URL parameters tell tales: 'quotes' are SQL, '<scripts>' are XSS, '..slashes..' are Directory Traversal.

More Incident Response and Management questions