ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 51 - PT0-002 discussion

Report
Export

A penetration tester is testing input validation on a search form that was discovered on a website.

Which of the following characters is the BEST option to test the website for vulnerabilities?

A.
Comma
Answers
A.
Comma
B.
Double dash
Answers
B.
Double dash
C.
Single quote
Answers
C.
Single quote
D.
Semicolon
Answers
D.
Semicolon
Suggested answer: C

Explanation:

A single quote (') is a common character used to test for SQL injection vulnerabilities, which occur when user input is directly passed to a database query. A single quote can terminate a string literal and allow an attacker to inject malicious SQL commands. For example, if the search form uses the query SELECT * FROM products WHERE name LIKE '%user_input%', then entering a single quote as user input would result in an error or unexpected behavior

asked 02/10/2024
carlos salgado
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first