EC-Council
412-79V10 · Question #314
James, a penetration tester, was performing a penetration test for an application, and he was able to gain access to the database. Since James knew an employee named Jason from XYZ Inc., he enters a…
The correct answer is A. LDAP injection attack. See the full explanation below for the reasoning.
Question
James, a penetration tester, was performing a penetration test for an application, and he was able to gain access to the database. Since James knew an employee named Jason from XYZ Inc., he enters a valid username "jason" and injects 'jason')&((j%3d'jason')||(1%3d1))%23 in the password field to access the database. However, James successfully logs into the user account without a valid password of Jason. In the above scenario, identify the type of attack performed by James?
Options
- ALDAP injection attack
- BHTML code injection attack
- CShell injection attack
- DFile injection attack
How the community answered
(25 responses)- A72% (18)
- B16% (4)
- C8% (2)
- D4% (1)
Community Discussion
No community discussion yet for this question.