โ† All CHFI Flashcard Decks

Investigating Web Attacks Flashcards

7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Investigating Web Attacks flashcards as text
  1. During a web forensics investigation, an analyst discovers requests to `/admin/../../../etc/shadow`. What evasion technique is the attacker using?

    Answer: Path traversal disguised within a valid-looking path

    The attacker embeds `../` sequences within an apparently legitimate path to evade simple blacklist filters that only check the beginning of the URL.

  2. What does a `403 Forbidden` response to automated scanner requests in web logs typically indicate from a forensic perspective?

    Answer: Access controls blocked the request, but the target resource exists

    A 403 response means the server understood the request but refused it due to access controls, confirming the resource exists but was protected.

  3. Which field in an IIS web server log records the action method used in an HTTP request (GET, POST, PUT, etc.)?

    Answer: cs-method

    The `cs-method` field in IIS W3C logs records the HTTP method (verb) used in the client's request.

  4. An attacker injected `; ls -la` into a web form parameter that is passed to a system command. What type of attack is this?

    Answer: OS command injection

    OS command injection occurs when user-supplied input is incorporated into a system shell command, allowing the attacker to execute arbitrary OS commands.

  5. In a web attack investigation, what is the purpose of correlating web server logs with database query logs?

    Answer: To match malicious HTTP requests with the actual database queries they generated

    Correlating web and database logs links specific HTTP requests to the database queries they triggered, confirming whether an injection attack reached and affected the database.

  6. A forensic analyst finds that an attacker sent an HTTP request with the header `X-Forwarded-For: 127.0.0.1`. What was the attacker trying to achieve?

    Answer: Spoof the source IP to appear as localhost and bypass IP-based access controls

    By forging the `X-Forwarded-For` header to `127.0.0.1`, attackers attempt to trick applications into treating the request as coming from localhost, bypassing IP allowlists.

  7. Which OWASP tool is specifically designed for intercepting and modifying HTTP/HTTPS traffic during web application security testing and forensic analysis?

    Answer: OWASP ZAP (Zed Attack Proxy)

    OWASP ZAP is an open-source web proxy tool used to intercept, inspect, and modify HTTP/HTTPS traffic for security testing and forensic purposes.