Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is investigating a web server that has been defaced. During the forensic analysis of web server logs, they find entries indicating unusual requests containing snippets of SQL code, such as 'UNION SELECT' or 'OR 1=1--'. These requests appear to be attempting to manipulate the underlying database queries. What type of attack is indicated by these log entries?

  1. ACross-Site Scripting (XSS)
  2. BCommand injection
  3. CDirectory traversal
  4. DSQL injection
Show answer & explanation

Correct answer: D. SQL injection

SQL injection attacks involve inserting or 'injecting' malicious SQL statements into an entry field for execution by the backend database. The log entries containing 'UNION SELECT' and 'OR 1=1--' are classic payloads used in SQL injection to bypass authentication, extract data, or manipulate database queries.

Why the other options are wrong

  • A. XSS injects client-side scripts into web pages, not SQL code for database manipulation.
  • B. Command injection executes arbitrary system commands on the server, typically through shell commands, not SQL statements.
  • C. Directory traversal attempts to access files and directories outside the web server's root directory, not by injecting SQL code.

SQL Injection

A code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution by the backend database.

  • Can lead to data theft, data modification, or complete system compromise.
  • Often uses payloads like 'UNION SELECT', 'OR 1=1--', or 'SLEEP()'.
  • Prevention includes parameterized queries, input validation, and least privilege for database accounts.

Memory trick: Web attacks exploit weaknesses in how apps talk to users and databases.

More Network Intrusion Analysis questions