ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 366 - PT0-002 discussion

Report
Export

A penetration tester is reviewing the logs of a proxy server and discovers the following URLs:

https://test.comptia.com/profile.php?userid=1546

https://test.cpmptia.com/profile.php?userid=5482

https://test.comptia.com/profile.php?userid=3618

Which of the following types of vulnerabilities should be remediated?

A.
Insecure direct object reference
Answers
A.
Insecure direct object reference
B.
Improper error handling
Answers
B.
Improper error handling
C.
Race condition
Answers
C.
Race condition
D.
Weak or default configurations
Answers
D.
Weak or default configurations
Suggested answer: A

Explanation:

Insecure Direct Object Reference (IDOR) occur when an application provides direct access to objects based on user-supplied input. In the provided URLs, the userid parameter is directly referenced, which can allow attackers to manipulate these references to access unauthorized data. This vulnerability can lead to unauthorized access to other users' profiles by simply changing the userid parameter value. The other vulnerabilities listed (Improper error handling, Race condition, Weak or default configurations) do not directly relate to the issue demonstrated by the URLs.

asked 02/10/2024
Ero Hiiesalu
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first