EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy
An ethical hacker is performing a vulnerability assessment on a web server. They use a tool that sends specially crafted HTTP requests to the server and analyzes the responses for common web application vulnerabilities like SQL injection and Cross-Site Scripting (XSS). Which category of vulnerability analysis tools is being utilized?
- AOperating System Vulnerability Scanner
- BNetwork Vulnerability Scanner
- CWeb Application Vulnerability Scanner
- DPort Scanner
Show answer & explanationAnswer & explanation
Correct answer: C. Web Application Vulnerability Scanner
The scenario explicitly mentions targeting a 'web server' and looking for 'web application vulnerabilities' like SQL injection and XSS. This directly points to a Web Application Vulnerability Scanner, which is designed to interact with web applications via HTTP/S to find such flaws.
Why the other options are wrong
- A. OS vulnerability scanners focus on operating system configurations and patches.
- B. Network vulnerability scanners focus on network devices and services, not specifically web application logic.
- D. Port scanners identify open ports, not application-level vulnerabilities.
Web Application Vulnerability Scanner
Automated tools designed to discover security flaws within web applications, including common vulnerabilities like SQL injection, XSS, and broken authentication.
- Interacts with web applications via HTTP/S.
- Identifies vulnerabilities in application code and configuration.
- Examples include Burp Suite, OWASP ZAP, Acunetix.
Memory trick: To 'scan' for 'web' flaws, use a 'web app' specific tool.