EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard
A penetration tester is evaluating a web application that handles sensitive customer data. They identify an input field that is vulnerable to SQL injection, allowing them to extract database schema information. However, the web application firewall (WAF) blocks direct attempts to use SQL keywords like 'UNION SELECT'. To bypass this WAF, the tester encodes the SQL injection payload using URL encoding and character obfuscation. This technique is an example of which aspect of vulnerability analysis and exploitation?
- AError-based SQL Injection
- BTime-based SQL Injection
- CBlind SQL Injection
- DPayload Obfuscation
Show answer & explanationAnswer & explanation
Correct answer: D. Payload Obfuscation
The scenario describes the tester encoding the SQL injection payload using URL encoding and character obfuscation 'to bypass this WAF'. This modification of the payload to evade detection without changing its core functionality is known as payload obfuscation, a common technique to circumvent security controls.
Why the other options are wrong
- A. Error-based SQL injection relies on database error messages to extract information.
- B. Time-based SQL injection is a type of blind SQLi that infers data based on response times.
- C. Blind SQL injection relies on true/false responses or time delays, not on WAF bypass techniques.
Payload Obfuscation
The technique of altering the appearance of a malicious payload (e.g., by encoding, encryption, or character manipulation) to evade detection by security mechanisms like WAFs or antivirus software, while retaining its original malicious functionality.
- Aims to bypass signature-based detection.
- Commonly uses encoding (URL, Base64), encryption, or string concatenation.
- Crucial for advanced exploitation against robust defenses.
Memory trick: To 'hide' your 'attack', you need to 'disguise' the payload.