11.07.2015 Views

VIDEO Intypedia007en EXERCISES AUTHOR: Chema ... - Criptored

VIDEO Intypedia007en EXERCISES AUTHOR: Chema ... - Criptored

VIDEO Intypedia007en EXERCISES AUTHOR: Chema ... - Criptored

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>VIDEO</strong> <strong>Intypedia007en</strong>LESSON 7: WEB APPLICATION SECURITY - INTRODUCTION TO SQL INJECTION TECHNIQUES<strong>EXERCISES</strong><strong>AUTHOR</strong>: <strong>Chema</strong> AlonsoSecurity Consultant at Informatica 64. Microsoft MVP Enterprise SecurityEXERCISE 1SQL Injection vulnerabilities are caused by:a) Bugs in the firewall settingsb) Bugs in the application that creates the queriesc) Bugs in the database settingsd) Bugs in the parameter filtering of the browserEXERCISE 2What happens in an inbound SQL injection attack?a) The SQL injection occurs within a queryb) The query results are obtained from the returned HTML pagec) The SQL injection is performed from the outside towards the insided) The firewall allows you to include the results in the SQL queryExercises <strong>Intypedia007en</strong> 1


EXERCISE 3What is a blind attack?a) An injection in which the attacker doesn't see the SQL query that is being madeb) An attack in which the response time should be measuredc) An attack in which you infer the results because you can't see themd) An injection in which the parameters are blindEXERCISE 4How can you recognize a True result in a blind attack?a) There will be a True when you remove the ID from the database on screenb) By the identifier of the process that generates the queryc) By a keyword in the search results paged) By the response timeEXERCISE 5Which of the following is an effective way to avoid SQL injection vulnerability?a) Filtering quotes in all the queriesb) Filtering quotes and blank spacesc) Avoiding the concatenation of strings of commands and parametersd) Using a firewall to publish web applicationsExercises <strong>Intypedia007en</strong> 2


ANSWERS1. b2. b3. c4. c and d5. cMadrid, Spain. May 2011http://www.intypedia.comhttp://twitter.com/intypediaExercises <strong>Intypedia007en</strong> 3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!