nerdexam
EC-Council

EC0-350 · Question #309

An attacker has been successfully modifying the purchase price of items purchased on the company's web site. The security administrators verify the web server and Oracle database have not been…

The correct answer is B. By changing hidden form values. See the full explanation below for the reasoning.

Question

An attacker has been successfully modifying the purchase price of items purchased on the company's web site. The security administrators verify the web server and Oracle database have not been compromised directly. They have also verified the Intrusion Detection System (IDS) logs and found no attacks that could have caused this. What is the mostly likely way the attacker has been able to modify the purchase price?

Options

  • ABy using SQL injection
  • BBy changing hidden form values
  • CBy using cross site scripting
  • DBy utilizing a buffer overflow attack

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    77% (34)
  • C
    5% (2)
  • D
    11% (5)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice