CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium
A security analyst is reviewing logs from a web application firewall (WAF) and notices the following entries: ``` TIME SRC_IP METHOD URI UA 14:05:12 10.0.0.5 GET /search?q=test%27+OR+1%3D1-- Mozilla/5.0 14:05:13 10.0.0.5 POST /login.php Mozilla/5.0 14:05:14 10.0.0.5 GET /products?category=electronics%27+UNION+SELECT+null,version(),database()-- Mozilla/5.0 ``` Which type of attack is indicated by these log entries?
- ADenial of Service (DoS)
- BCross-Site Scripting (XSS)
- CSQL Injection
- DDirectory Traversal
Show answer & explanationAnswer & explanation
Correct answer: C. SQL Injection
The log entries show specific SQL syntax, such as `OR 1=1--` and `UNION SELECT null,version(),database()--`, embedded within URL parameters. These are classic indicators of SQL Injection attempts, where an attacker tries to manipulate database queries.
Why the other options are wrong
- A. DoS attacks aim to overwhelm a service with traffic, not to inject specific code into URL parameters.
- B. XSS attacks involve injecting client-side scripts, typically HTML/JavaScript, into web pages, not directly manipulating database queries with SQL syntax.
- D. Directory Traversal attempts to access files outside the intended web root, often using `../` sequences, not SQL syntax.
SQL Injection (SQLi)
A web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often by injecting malicious SQL code into input fields.
- Exploits improper input validation.
- Can lead to data exfiltration, modification, or deletion.
- Common payloads include `OR 1=1`, `UNION SELECT`, `DROP TABLE`.
Memory trick: Look for code snippets in unexpected places, especially in parameters.