Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium
A security incident response team is analyzing a breach where an attacker exploited a vulnerability in a web application to gain unauthorized database access. The team determines that the vulnerability was due to improper input validation, allowing malicious SQL commands to be executed. Which type of attack occurred?
- ADenial of Service (DoS)
- BSQL Injection
- CCross-Site Scripting (XSS)
- DBuffer Overflow
Show answer & explanationAnswer & explanation
Correct answer: B. SQL Injection
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. It typically occurs when an application uses user-supplied input in SQL queries without properly sanitizing or validating it, allowing malicious SQL commands to be executed.
Why the other options are wrong
- A. DoS attacks aim to make a service unavailable, not to exploit input validation for database access.
- C. XSS allows attackers to inject client-side scripts into web pages, not to execute SQL commands against a database.
- D. Buffer overflow exploits memory management errors, typically leading to code execution or system crashes, not directly to SQL command execution via web input validation.
SQL Injection
A web security vulnerability that allows attackers to interfere with the queries an application makes to its database, often by inserting malicious SQL code into input fields.
- Occurs due to improper input validation.
- Can lead to unauthorized data access, modification, or deletion.
- Mitigated by prepared statements and input sanitization.
Memory trick: SQL Injections Steal Secret Queries.