EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy

A web administrator is configuring a new e-commerce application. To enhance security, they want to prevent attackers from manipulating price parameters in HTTP requests before they reach the server. Which of the following countermeasures would be most effective in addressing this specific concern?

  1. AImplementing client-side JavaScript validation for all price inputs.
  2. BDeploying a Web Application Firewall (WAF) to filter out malicious SQL injection attempts.
  3. CPerforming server-side validation of all price parameters received from client requests.
  4. DEncrypting all HTTP traffic using TLS 1.3.
Show answer & explanation

Correct answer: C. Performing server-side validation of all price parameters received from client requests.

Server-side validation is crucial for preventing parameter tampering and other input-based attacks. Client-side validation can be easily bypassed, and while WAFs and TLS are important, they don't directly address the manipulation of specific parameters like price.

Why the other options are wrong

  • A. Client-side validation can be easily bypassed by an attacker.
  • B. A WAF primarily protects against broader attack categories like SQL injection, not specific parameter tampering without custom rules.
  • D. TLS encrypts communication but does not prevent a malicious client from sending tampered data to the server.

Server-Side Validation

The process of validating user input on the server, after it has been submitted by the client. This is a critical security measure as client-side validation can be bypassed.

  • Occurs on the server after submission.
  • Essential for security, unlike client-side validation.
  • Prevents various input-based attacks.

Memory trick: Validate on the server, or attackers will conquer.

More Web Application Hacking questions