ExamGecko
Question list
Search
Search

Related questions











Question 370 - 312-50v12 discussion

Report
Export

Attempting an injection attack on a web server based on responses to True/False

A.
Compound SQLi
Answers
A.
Compound SQLi
B.
Blind SQLi
Answers
B.
Blind SQLi
C.
Classic SQLi
Answers
C.
Classic SQLi
D.
DMS-specific SQLi
Answers
D.
DMS-specific SQLi
Suggested answer: B

Explanation:

https://en.wikipedia.org/wiki/SQL_injection#Blind_SQL_injection

Blind SQL injection is used when a web application is vulnerable to an SQL injection but the results of the injection are not visible to the attacker. The page with the vulnerability may not be one that displays data but will display differently depending on the results of a logical statement injected into the legitimate SQL statement called for that page. This type of attack has traditionally been considered time-intensive because a new statement needed to be crafted for each bit recovered, and depending on its structure, the attack may consist of many unsuccessful requests. Recent advancements have allowed each request to recover multiple bits, with no unsuccessful requests, allowing for more consistent and efficient extraction.

asked 18/09/2024
Shane Behrendt
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first