Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A security analyst is reviewing logs from a web application firewall (WAF) and notices a high volume of requests containing unusual characters and syntax in the URL parameters, specifically single quotes, double dashes, and 'OR 1=1' constructions. These requests are directed at a login page. What type of attack is the WAF most likely detecting?
- ADenial of Service (DoS)
- BCross-Site Request Forgery (CSRF)
- CSession Hijacking
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: D. SQL Injection
The presence of characters like single quotes, double dashes, and 'OR 1=1' in URL parameters is a classic signature of SQL injection attempts, where an attacker tries to manipulate backend database queries.
Why the other options are wrong
- A. DoS attacks aim to overwhelm a service with traffic, not to inject malicious syntax into parameters.
- B. CSRF involves tricking a logged-in user into performing an unwanted action, not direct manipulation of URL parameters with SQL syntax.
- C. Session hijacking involves stealing a user's session token, not injecting SQL syntax into web requests.
SQL Injection
SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g., to dump database content to the attacker).
- Targets web applications with databases
- Injects malicious SQL code into input fields or URL parameters
- Common payloads include 'OR 1=1 --
- Can lead to data leakage, data modification, or remote code execution
Memory trick: Web attacks are like 'Tricks on a Website' to get unauthorized access or data.