EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy

An ethical hacker is performing a vulnerability assessment on a web server. They use a tool that sends specially crafted HTTP requests to the server and analyzes the responses for common web application vulnerabilities like SQL injection and Cross-Site Scripting (XSS). Which category of vulnerability analysis tools is being utilized?

  1. AOperating System Vulnerability Scanner
  2. BNetwork Vulnerability Scanner
  3. CWeb Application Vulnerability Scanner
  4. DPort Scanner
Show answer & explanation

Correct answer: C. Web Application Vulnerability Scanner

The scenario explicitly mentions targeting a 'web server' and looking for 'web application vulnerabilities' like SQL injection and XSS. This directly points to a Web Application Vulnerability Scanner, which is designed to interact with web applications via HTTP/S to find such flaws.

Why the other options are wrong

  • A. OS vulnerability scanners focus on operating system configurations and patches.
  • B. Network vulnerability scanners focus on network devices and services, not specifically web application logic.
  • D. Port scanners identify open ports, not application-level vulnerabilities.

Web Application Vulnerability Scanner

Automated tools designed to discover security flaws within web applications, including common vulnerabilities like SQL injection, XSS, and broken authentication.

  • Interacts with web applications via HTTP/S.
  • Identifies vulnerabilities in application code and configuration.
  • Examples include Burp Suite, OWASP ZAP, Acunetix.

Memory trick: To 'scan' for 'web' flaws, use a 'web app' specific tool.

More System Hacking Phases and Attack Techniques questions