โ† All CHFI Flashcard Decks

Investigating Web Attacks Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Investigating Web Attacks flashcards as text
  1. A CHFI analyst is reviewing Apache logs and sees a User-Agent string containing `sqlmap/1.6`. What should the analyst conclude?

    Answer: An automated SQL injection tool targeted the application

    SQLMap is an open-source automated SQL injection tool, and its presence in the User-Agent field confirms it was used against the application.

  2. Which log file on a Linux Apache server would contain evidence of a PHP web shell being executed?

    Answer: /var/log/apache2/error.log and access.log

    Apache's access.log records every request including to uploaded PHP shells, while error.log may show PHP execution errors triggered by the attacker.

  3. During investigation of a web compromise, the analyst finds `/etc/passwd` content in a server response. Which vulnerability was likely exploited?

    Answer: Local file inclusion (LFI)

    Local File Inclusion (LFI) allows an attacker to read arbitrary files on the server, such as `/etc/passwd`, by manipulating file path parameters.

  4. What is the forensic significance of the `Referer` HTTP header found in web server logs?

    Answer: It shows the URL from which the request originated, helping trace attack navigation paths

    The Referer header shows what page or resource the request came from, helping investigators trace how an attacker navigated through an application.

  5. An investigator finds that an attacker used `UNION SELECT NULL, username, password FROM users--` in a web request. What is this technique called?

    Answer: UNION-based SQL injection

    UNION-based SQL injection appends a UNION SELECT statement to extract data from other database tables into the application's response.

  6. Which forensic artifact is MOST useful for identifying the geographic origin of a web attack?

    Answer: Source IP address in access logs correlated with GeoIP databases

    The source IP address recorded in access logs can be queried against GeoIP databases to approximate the attacker's geographic location.

  7. A web application firewall (WAF) log shows a block event for a request containing `SLEEP(5)` in a parameter. What attack technique was attempted?

    Answer: Time-based blind SQL injection

    Time-based blind SQL injection uses functions like `SLEEP()` to cause database delays, inferring information based on response time when no data is returned directly.