EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingHard

A penetration tester is analyzing a web application that stores user preferences in a cookie. The cookie value is base64 encoded and contains a serialized object with user settings, including an 'isAdmin' boolean flag. The tester decodes the cookie, changes 'isAdmin' from 'false' to 'true', re-encodes it, and sends the modified cookie with the next request. The application then grants administrative privileges. This scenario describes an exploitation of which common web application vulnerability?

  1. ABroken Authentication
  2. BInsecure Deserialization
  3. CSession Fixation
  4. DCross-Site Scripting (XSS)
Show answer & explanation

Correct answer: B. Insecure Deserialization

The scenario involves modifying a serialized object (containing the 'isAdmin' flag) which is then deserialized by the application, leading to privilege escalation. This is a classic example of Insecure Deserialization.

Why the other options are wrong

  • A. Broken Authentication is a broader category; Insecure Deserialization is a specific flaw that can lead to it.
  • C. Session Fixation involves forcing a user into a known session ID, not manipulating serialized objects.
  • D. XSS involves injecting client-side scripts, which is not what is described here.

Insecure Deserialization

Insecure Deserialization is a vulnerability where an application deserializes untrusted data, allowing an attacker to manipulate objects or inject malicious code.

  • Can lead to remote code execution, privilege escalation, or denial of service.
  • Occurs when an application reconstructs an object from a data stream without verifying its integrity.
  • Prevented by not deserializing untrusted data or using secure serialization formats/libraries.

Memory trick: Data Transforms, Dangers Lurk.

More Web Application Hacking questions