Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringEasy
A security operations center (SOC) analyst is reviewing alerts from the SIEM. One alert indicates 'Multiple failed attempts to access a critical database using SQL queries containing 'UNION SELECT' and 'pg_sleep()'. The source IP is from an external, untrusted network. Which vulnerability is the attacker most likely attempting to exploit?
- ASQL Injection
- BBuffer Overflow
- CCross-Site Request Forgery (CSRF)
- DDirectory Traversal
Show answer & explanationAnswer & explanation
Correct answer: A. SQL Injection
The presence of 'UNION SELECT' and 'pg_sleep()' within SQL queries is a classic signature of SQL injection attempts. 'UNION SELECT' is used to extract data, and 'pg_sleep()' is often used for time-based blind SQL injection.
Why the other options are wrong
- B. Buffer overflow exploits memory management vulnerabilities, not SQL query logic.
- C. CSRF exploits trust in a user's browser, not through direct SQL query manipulation.
- D. Directory traversal attempts to access files outside the intended directory, not through SQL queries.
SQL Injection Signatures
SQL injection signatures are specific keywords, functions, or patterns found within attacker-crafted SQL queries that indicate an attempt to exploit database vulnerabilities.
- Common keywords: 'UNION SELECT', 'OR 1=1', 'DROP TABLE'.
- Functions for enumeration: '@@version', 'user()', 'database()'.
- Functions for timing attacks: 'SLEEP()', 'pg_sleep()'.
- Often seen in web application logs targeting input fields.
Memory trick: Web app attacks are like trying to break into a house through its windows, some target specific flaws.