CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium

A security analyst is reviewing logs from a web application firewall (WAF) and notices the following entries: ``` TIME SRC_IP METHOD URI UA 14:05:12 10.0.0.5 GET /search?q=test%27+OR+1%3D1-- Mozilla/5.0 14:05:13 10.0.0.5 POST /login.php Mozilla/5.0 14:05:14 10.0.0.5 GET /products?category=electronics%27+UNION+SELECT+null,version(),database()-- Mozilla/5.0 ``` Which type of attack is indicated by these log entries?

  1. ADenial of Service (DoS)
  2. BCross-Site Scripting (XSS)
  3. CSQL Injection
  4. DDirectory Traversal
Show answer & explanation

Correct answer: C. SQL Injection

The log entries show specific SQL syntax, such as `OR 1=1--` and `UNION SELECT null,version(),database()--`, embedded within URL parameters. These are classic indicators of SQL Injection attempts, where an attacker tries to manipulate database queries.

Why the other options are wrong

  • A. DoS attacks aim to overwhelm a service with traffic, not to inject specific code into URL parameters.
  • B. XSS attacks involve injecting client-side scripts, typically HTML/JavaScript, into web pages, not directly manipulating database queries with SQL syntax.
  • D. Directory Traversal attempts to access files outside the intended web root, often using `../` sequences, not SQL syntax.

SQL Injection (SQLi)

A web security vulnerability that allows an attacker to interfere with the queries an application makes to its database, often by injecting malicious SQL code into input fields.

  • Exploits improper input validation.
  • Can lead to data exfiltration, modification, or deletion.
  • Common payloads include `OR 1=1`, `UNION SELECT`, `DROP TABLE`.

Memory trick: Look for code snippets in unexpected places, especially in parameters.

More Incident Response and Management questions