Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
A security analyst observes numerous attempts to access a specific URL parameter with various SQL commands (e.g., 'UNION SELECT', 'OR 1=1--'). These attempts are coming from a single IP address over a short period. Which host-based intrusion analysis technique would be most effective in confirming if the web application is vulnerable to this attack?
- AAnalyzing network flow data for bandwidth anomalies.
- BChecking the operating system's event viewer for system shutdowns.
- CExamining CPU utilization graphs on the database server.
- DReviewing web server access logs for HTTP request details and responses.
Show answer & explanationAnswer & explanation
Correct answer: D. Reviewing web server access logs for HTTP request details and responses.
SQL injection attempts are typically visible in web server access logs, showing the full HTTP request including the malicious URL parameters. Analyzing these logs, along with corresponding application audit logs, can confirm if the application processed the malicious input and how it responded, indicating vulnerability.
Why the other options are wrong
- A. Bandwidth anomalies are too broad and might not specifically confirm a SQL injection vulnerability.
- B. System shutdowns are not a direct indicator of SQL injection vulnerability; they might be a consequence of a successful, severe attack, but not the primary confirmation method.
- C. CPU utilization alone doesn't confirm SQL injection; while a successful attack might impact CPU, it's not specific enough to the vulnerability itself.
SQL Injection Analysis
The process of examining web server and application logs to identify and confirm attempts to exploit SQL injection vulnerabilities.
- Look for SQL keywords (e.g., UNION, SELECT, OR, AND) in URL parameters or POST data.
- Analyze HTTP response codes for unusual errors or data leakage.
- Correlate with database logs for unauthorized queries.
Memory trick: To confirm an attack, look at the host's track!