EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy

A security analyst is reviewing web server logs and notices an unusually high number of GET requests to a specific static resource, `example.com/images/logo.png`, originating from a single IP address within a very short timeframe. The requests appear legitimate but are far more frequent than expected for typical user behavior. What type of web server attack is most likely occurring?

  1. AWeb Cache Deception
  2. BDenial of Service (DoS)
  3. CHTTP Parameter Pollution
  4. DSession Fixation
Show answer & explanation

Correct answer: B. Denial of Service (DoS)

An unusually high number of requests to a specific resource from a single IP address in a short timeframe, exceeding normal user behavior, is a classic indication of a Denial of Service (DoS) attack. The goal is to overwhelm the server or consume resources, making the service unavailable.

Why the other options are wrong

  • A. Web Cache Deception involves tricking a web cache into storing sensitive user information.
  • C. HTTP Parameter Pollution involves manipulating how a web application processes multiple parameters with the same name.
  • D. Session Fixation tricks a user into authenticating with a pre-determined session ID, not high request volume.

Denial of Service (DoS)

An attack aimed at making a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.

  • Can target network bandwidth, server resources, or applications.
  • Distinguished from DDoS by originating from a single source.
  • Common methods include SYN floods, ICMP floods, and HTTP floods.

Memory trick: Too many requests will deny service.

More Web Application Hacking questions