An attacker, in an attempt to exploit the vulnerability in the dynamically generated welcome page, inserted code at the end of the company's URL as follows:http://technosoft.com.com/alert("WARNING: The application has encountered an error");. Identify the attack demonstrated in the above scenario.
An attacker, in an attempt to exploit the vulnerability in the dynamically generated welcome page, inserted code at the end of the company's URL as follows:
I'm not entirely sure, but it seems like it could also be an SQL Injection Attack? I remember something about code being inserted, but this looks different.
I think this is a Cross-site Scripting Attack since the attacker is injecting a script into the URL. It reminds me of a practice question we did on XSS.
Wait, I'm a little confused. I thought the traffic-table was more for monitoring and analyzing traffic, not for actually setting the parameters. I'll need to double-check my notes to make sure I'm remembering this correctly.
Hmm, I'm not entirely sure about the answer here. I'll need to think through the different options and try to eliminate the ones that don't seem right.
upvoted 0
times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Kathryn
10 months agoTammy
10 months agoLavera
10 months agoMariann
10 months agoCaitlin
11 months agoOretha
11 months agoChana
11 months agoJoaquin
11 months agoKanisha
11 months agoEveline
11 months agoMelynda
11 months agoDaniela
11 months ago