nerdexam
EC-Council

412-79V10 · Question #314

James, a penetration tester, was performing a penetration test for an application, and he was able to gain access to the database. Since James knew an employee named Jason from XYZ Inc., he enters a…

The correct answer is A. LDAP injection attack. See the full explanation below for the reasoning.

Question

James, a penetration tester, was performing a penetration test for an application, and he was able to gain access to the database. Since James knew an employee named Jason from XYZ Inc., he enters a valid username "jason" and injects 'jason')&((j%3d'jason')||(1%3d1))%23 in the password field to access the database. However, James successfully logs into the user account without a valid password of Jason. In the above scenario, identify the type of attack performed by James?

Options

  • ALDAP injection attack
  • BHTML code injection attack
  • CShell injection attack
  • DFile injection attack

How the community answered

(25 responses)
  • A
    72% (18)
  • B
    16% (4)
  • C
    8% (2)
  • D
    4% (1)

Community Discussion

No community discussion yet for this question.

Full 412-79V10 Practice