nerdexam
EC-Council

EC0-350 · Question #691

You are conducting pen-test against a company's website using SQL Injection techniques. You enter "anuthing or 1=1-" in the username filed of an authentication form. This is the output returned from…

The correct answer is A. Identify the user context of the web application by running_. See the full explanation below for the reasoning.

Question

You are conducting pen-test against a company's website using SQL Injection techniques. You enter "anuthing or 1=1-" in the username filed of an authentication form. This is the output returned from the server. What is the next step you should do?

Exhibit

EC0-350 question #691 exhibit

Options

  • AIdentify the user context of the web application by running_
  • BIdentify the database and table name by running:
  • CFormat the C: drive and delete the database by running:
  • DReboot the web server by running:

How the community answered

(19 responses)
  • A
    79% (15)
  • B
    5% (1)
  • C
    11% (2)
  • D
    5% (1)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice