Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium
A security analyst is investigating a suspected data breach where an attacker exfiltrated sensitive customer information. The post-incident analysis reveals that the attacker gained access through a web application vulnerability that allowed them to execute arbitrary commands on the underlying server. Which type of attack did the attacker most likely use to achieve this?
- ACross-Site Scripting (XSS)
- BDenial of Service (DoS)
- CCommand Injection
- DCross-Site Request Forgery (CSRF)
Show answer & explanationAnswer & explanation
Correct answer: C. Command Injection
Command injection occurs when an attacker can execute arbitrary commands on the host operating system through a vulnerable application. This directly matches the scenario where an attacker used a web application vulnerability to 'execute arbitrary commands on the underlying server' to exfiltrate data.
Why the other options are wrong
- A. XSS allows attackers to inject malicious client-side scripts into web pages, affecting users, not directly executing commands on the server.
- B. DoS attacks aim to make a service unavailable, not to gain command execution for data exfiltration.
- D. CSRF forces an end-user to execute unwanted actions on a web application in which they're currently authenticated, not server command execution.
Command Injection
A web application vulnerability that allows an attacker to execute arbitrary operating system commands on the server hosting the application.
- Occurs when an application passes user-supplied data to a system shell without proper sanitization.
- Can lead to full system compromise and data exfiltration.
- Mitigated by strict input validation and avoiding system calls with user input.
Memory trick: Command Injection: The attacker's 'remote control' for your server.