nerdexam
GAQM

CPEH-001 · Question #1012

Calvin, a grey-hat hacker, targets a web application that has design flaws in its authentication mechanism. He enumerates usernames from the login form of the web application, which requests users…

The correct answer is B. Verbose failure messages. See the full explanation below for the reasoning.

Question

Calvin, a grey-hat hacker, targets a web application that has design flaws in its authentication mechanism. He enumerates usernames from the login form of the web application, which requests users to feed data and specifies the incorrect field in case of invalid credentials. Later, Calvin uses this information to perform social engineering. Which of the following design flaws in the authentication mechanism is exploited by Calvin?

Options

  • AInsecure transmission of credentials
  • BVerbose failure messages
  • CUser impersonation
  • DPassword reset mechanism

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    81% (13)
  • D
    13% (2)

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice