CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard
A penetration tester is evaluating a web application that uses a search function. They notice that when they input `<script>alert('XSS')</script>` into the search box and submit, a pop-up window appears with 'XSS', and the malicious script is directly displayed in the browser's response without being stored on the server. Which type of attack has the tester identified?
- AStored Cross-Site Scripting (XSS)
- BDOM-based Cross-Site Scripting (XSS)
- CReflected Cross-Site Scripting (XSS)
- DServer-Side Request Forgery (SSRF)
Show answer & explanationAnswer & explanation
Correct answer: C. Reflected Cross-Site Scripting (XSS)
This scenario describes a Reflected XSS vulnerability. The malicious script is not stored on the server but is immediately reflected back in the HTTP response and executed by the user's browser. The key indicator is the immediate execution and the lack of server-side persistence.
Why the other options are wrong
- A. Stored XSS (Persistent XSS) involves the malicious script being saved on the server and served to other users later, which is not the case here.
- B. DOM-based XSS occurs when the client-side script (often JavaScript) processes user input and writes it to the DOM without proper sanitization, leading to script execution.
- D. SSRF involves the server making requests on behalf of the attacker, which is unrelated to client-side script execution in the browser.
Reflected Cross-Site Scripting (XSS)
A web security vulnerability where malicious script injected by an attacker is immediately reflected back from the server in an HTTP response and executed by the user's browser. The script is not stored on the server.
- Script is reflected directly in the response.
- Not stored on the server (non-persistent).
- Requires user interaction (e.g., clicking a malicious link).
Memory trick: XSS: Store it, Reflect it, DOM it – three ways to inject client-side code.