CompTIA
PT0-002 · Question #22
A penetration tester is testing a web application that is hosted by a public cloud provider. The tester is able to query the provider's metadata and get the credentials used by the instance to…
The correct answer is B. Server-side request forgery. https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
Attacks and Exploits
Question
A penetration tester is testing a web application that is hosted by a public cloud provider. The tester is able to query the provider's metadata and get the credentials used by the instance to authenticate itself. Which of the following vulnerabilities has the tester exploited?
Options
- ACross-site request forgery
- BServer-side request forgery
- CRemote file inclusion
- DLocal file inclusion
How the community answered
(53 responses)- A6% (3)
- B74% (39)
- C13% (7)
- D8% (4)
Explanation
https://owasp.org/www-community/attacks/Server_Side_Request_Forgery
Topics
#Server-side request forgery#Cloud security#Metadata service exploitation#Credential theft
Community Discussion
No community discussion yet for this question.