Investigating Web Attacks Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Investigating Web Attacks flashcards as text
A forensic investigator finds that attacker requests used chunked transfer encoding with abnormal chunk sizes. What might this indicate?
Answer: An attempt to evade WAF/IDS signature detection by obfuscating the payload
Attackers sometimes use chunked transfer encoding to split malicious payloads across chunks, evading WAF and IDS signatures that inspect full request bodies.
During investigation, logs show the attacker's session cookie was identical across 20 different IP addresses. What attack scenario does this MOST likely indicate?
Answer: Session hijacking — the attacker stole and reused a victim's session token
A single session cookie appearing from multiple IPs indicates the attacker stole a legitimate session token and used it from different hosts or proxies.
What is the forensic significance of finding `null bytes (%00)` in web server log entries?
Answer: They may be used to truncate file extensions or bypass input validation filters
Null byte injection (`%00`) was historically used to truncate strings in C-based languages, tricking the application into treating a file like `shell.php%00.jpg` as a PHP file.
An analyst examining a compromised web server finds an `.htaccess` file modified to redirect all traffic to an external malicious site. What type of attack occurred?
Answer: Web server configuration tampering / malicious redirect
Modifying `.htaccess` to redirect visitors to a malicious site is a web defacement/compromise technique used after gaining write access to the server.
Which forensic technique involves reviewing the `Last-Modified` and `ETag` HTTP response headers to establish a timeline of web content changes?
Answer: Cache-based temporal analysis
Cache-related headers like `Last-Modified` and `ETag` reflect when server-side content was last changed, helping investigators establish a timeline of modifications.
A web attack investigation reveals the server was sending `HTTP 301` redirects to users visiting certain pages. What should the forensic analyst check?
Answer: Whether the redirect destination was altered by an attacker post-compromise
Attackers who gain server access sometimes inject 301 redirects in web configs or CMS settings to redirect users to phishing or malware delivery sites.
In CHFI investigations of web attacks, what is the PRIMARY purpose of hashing web server log files upon collection?
Answer: To ensure the integrity of log evidence and detect any post-collection tampering
Hashing log files (e.g., with SHA-256) at the time of collection creates a verifiable integrity record, proving the evidence has not been altered since acquisition.