EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy
A security analyst is reviewing web server logs and notices an unusually high number of GET requests to a specific static resource, `example.com/images/logo.png`, originating from a single IP address within a very short timeframe. The requests appear legitimate but are far more frequent than expected for typical user behavior. What type of web server attack is most likely occurring?
- AWeb Cache Deception
- BDenial of Service (DoS)
- CHTTP Parameter Pollution
- DSession Fixation
Show answer & explanationAnswer & explanation
Correct answer: B. Denial of Service (DoS)
An unusually high number of requests to a specific resource from a single IP address in a short timeframe, exceeding normal user behavior, is a classic indication of a Denial of Service (DoS) attack. The goal is to overwhelm the server or consume resources, making the service unavailable.
Why the other options are wrong
- A. Web Cache Deception involves tricking a web cache into storing sensitive user information.
- C. HTTP Parameter Pollution involves manipulating how a web application processes multiple parameters with the same name.
- D. Session Fixation tricks a user into authenticating with a pre-determined session ID, not high request volume.
Denial of Service (DoS)
An attack aimed at making a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.
- Can target network bandwidth, server resources, or applications.
- Distinguished from DDoS by originating from a single source.
- Common methods include SYN floods, ICMP floods, and HTTP floods.
Memory trick: Too many requests will deny service.