nerdexam
EC-Council

412-79V10 · Question #84

Sam is building a web application for SQL injection vulnerabilities. During the testing, Sam discovered that the web application is vulnerable to SQL injection. He soon discovered that the web…

The correct answer is C. Sam is using inline comments to bypass WAF. See the full explanation below for the reasoning.

Question

Sam is building a web application for SQL injection vulnerabilities. During the testing, Sam discovered that the web application is vulnerable to SQL injection. He soon discovered that the web application had UNION with UNION based SQL queries, however, he realized that the underlying WAF is blocking the requests. To avoid this, Sam is trying the following query Which of the following evasion techniques is Sam using?

Options

  • ASam is using char encoding to bypass WAF
  • BSam is using hex encoding to bypass WAF
  • CSam is using inline comments to bypass WAF
  • DSam is manipulating white spaces to bypass WAF

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    11% (3)
  • C
    78% (21)
  • D
    4% (1)

Community Discussion

No community discussion yet for this question.

Full 412-79V10 Practice