EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy

A penetration tester is evaluating a web application that allows users to submit feedback through a form. The form includes a text area for comments and a hidden field for a 'category' value. The tester intercepts the request and modifies the hidden 'category' field from 'General' to 'Admin'. Upon submission, the feedback is processed with administrative privileges, allowing the tester to view sensitive internal system logs. Which type of vulnerability has been exploited?

  1. ABroken Authentication
  2. BCross-Site Scripting (XSS)
  3. CParameter Tampering
  4. DSQL Injection
Show answer & explanation

Correct answer: C. Parameter Tampering

The scenario describes an attacker modifying a request parameter (the hidden 'category' field) to bypass application logic and gain unauthorized access to functionality or data. This is a classic example of Parameter Tampering.

Why the other options are wrong

  • A. Broken Authentication refers to flaws in authentication mechanisms, not the modification of request parameters after authentication.
  • B. XSS involves injecting client-side scripts into web pages, which is not the vulnerability described.
  • D. SQL Injection involves injecting malicious SQL queries, which is not what happened here.

Parameter Tampering

Parameter Tampering is a web-based attack where an attacker manipulates parameters exchanged between the client and server to modify application data or logic.

  • Involves altering URL query strings, form fields, or HTTP headers.
  • Can lead to unauthorized access, privilege escalation, or data manipulation.
  • Often targets hidden fields, prices, or user IDs.

Memory trick: Parameters Play Perilously, Prompting Protection.

More Web Application Hacking questions