โ† All CHFI Flashcard Decks

Investigating Web Attacks Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Investigating Web Attacks flashcards as text
  1. During a web attack investigation, you find the string `' OR '1'='1` in server logs. What type of attack does this indicate?

    Answer: SQL injection

    The string `' OR '1'='1` is a classic SQL injection payload used to bypass authentication by making a WHERE clause always evaluate to true.

  2. Which HTTP response code in web server logs most strongly indicates a successful directory traversal attack?

    Answer: 200 OK with unexpected file content

    A 200 OK response to a traversal-style request (e.g., `../../etc/passwd`) confirms the server served a file outside the web root.

  3. A forensic investigator notices repeated POST requests to `/wp-login.php` with hundreds of different passwords. What attack type is this?

    Answer: Brute-force attack

    Repeated login attempts against a single account with many passwords characterizes a brute-force attack.

  4. What artifact would BEST help determine whether an attacker successfully exploited a web shell uploaded to a server?

    Answer: Web server access logs showing GET/POST requests to the shell file

    Access log entries showing requests to the web shell file with resulting 200 responses confirm the shell was accessed and used.

  5. Which tool is primarily used by forensic analysts to reconstruct and replay HTTP sessions captured in a PCAP file?

    Answer: Wireshark's Follow TCP Stream

    Wireshark's Follow TCP Stream feature allows analysts to reconstruct and review full HTTP conversations from packet captures.

  6. An attacker sends the payload `` in a comment field that is rendered on a public page. This is an example of which XSS variant?

    Answer: Stored XSS

    Stored (persistent) XSS occurs when malicious script is saved to the server (e.g., a database) and later rendered to other users.

  7. In web attack forensics, what does the presence of `%2e%2e%2f` in a URL request indicate?

    Answer: URL-encoded directory traversal (`../`)

    `%2e%2e%2f` is the URL-encoded form of `../`, used in directory traversal attacks to escape the web root.