EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingHard
A penetration tester is analyzing a web application that stores user preferences in a cookie. The cookie value is base64 encoded and contains a serialized object with user settings, including an 'isAdmin' boolean flag. The tester decodes the cookie, changes 'isAdmin' from 'false' to 'true', re-encodes it, and sends the modified cookie with the next request. The application then grants administrative privileges. This scenario describes an exploitation of which common web application vulnerability?
- ABroken Authentication
- BInsecure Deserialization
- CSession Fixation
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. Insecure Deserialization
The scenario involves modifying a serialized object (containing the 'isAdmin' flag) which is then deserialized by the application, leading to privilege escalation. This is a classic example of Insecure Deserialization.
Why the other options are wrong
- A. Broken Authentication is a broader category; Insecure Deserialization is a specific flaw that can lead to it.
- C. Session Fixation involves forcing a user into a known session ID, not manipulating serialized objects.
- D. XSS involves injecting client-side scripts, which is not what is described here.
Insecure Deserialization
Insecure Deserialization is a vulnerability where an application deserializes untrusted data, allowing an attacker to manipulate objects or inject malicious code.
- Can lead to remote code execution, privilege escalation, or denial of service.
- Occurs when an application reconstructs an object from a data stream without verifying its integrity.
- Prevented by not deserializing untrusted data or using secure serialization formats/libraries.
Memory trick: Data Transforms, Dangers Lurk.