Question 25 of 270 from exam CAS-003: CompTIA CASP+

Question 25 of 270 from exam CAS-003: CompTIA CASP+

Question

An internal penetration tester was assessing a recruiting page for potential issues before it was pushed to the production website.

The penetration tester discovers an issue that must be corrected before the page goes live.

The web host administrator collects the log files below and gives them to the development team so improvements can be made to the security design of the website.

[00:00:09] “GET /cgi-bin/forum/commentary-pl/noframes/read/209 HTTP/1.1”
200 6863

“http: //search.company.
t=0ghits=10eswitch=0e
“Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Hotbar 4.4
[00:00:12] “GET /js/master.js HTTP/1.1” 200 2263

“http: / /www. company. com/cqi-bin/forum/commentary.pl/noframes/read/209”
“Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Hotbar 4.4.7.0)”
[00:00:22] “GET /internet/index.html HTTP/1.1” 200 6792

“http://www. company.com/video/streaming/http. html”

“Mozilla/S.0 (X11; U; Linux i686; es-ES; rv:1.6) Gecko/20040413
Debian/1.6-5”

[00:00:25] “GET /showFile.action?£ileNam
occurred, please send your username and password to me@example.com”)
</script> 200

[00:00:27] “GET /contacts-html HTTP/1.0” 200 4595 *-" “FAS?-
WebCrawler/2.1-pre2 (ashen@company.net)”

[00:00:29] “GET /news/news.html HPTP/1.0” 200 16716 *-* “FAST-
WebCrawler/2.1-pre2 (ashen@company.net)”

[00:00:29] “GET /download/windows/asctab31.zip HTTP/1.0” 200 1540096
“http://www. company .com/downloads/freeware/webdevelopment/15.htm1”
“Mozilla/4.7 [en]C-SYMPA (Win95; U)”

[00:00:30] “GET /pics/wpaper.gif HTTP/1.0” 200 6248

“http://www. comptia.com/asctort£/” “Mozilla/4.05 (Macintosh; 1; PPC)”

m/search/cgi/search.cgi?qs=download=sdom=ssofise

0)”

script> alert ("an error has

Which of the following types of attack vectors did the penetration tester use?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D. E.

B.