Unit 5: Session Hijacking, Web Servers and Applications, SQL Injection - Practice Quiz

INT244 — Securing Computing Systems 50 Questions
0 Correct 0 Wrong 50 Left
0/50

1 What is the primary definition of Session Hijacking?

A. The exploitation of a valid computer session to gain unauthorized access to information or services
B. Phishing a user to obtain their login credentials via email
C. Crashing a web server by sending too many requests
D. Unauthorized encrypted communication between two servers

2 Which of the following is a key difference between Session Hijacking and IP Spoofing?

A. IP Spoofing takes over an active session; Hijacking initiates a new one
B. Session Hijacking takes over an ongoing authenticated session; IP Spoofing creates unauthorized packets with a false source IP
C. There is no difference; they are synonymous
D. Session Hijacking only works on UDP; IP Spoofing works on TCP

3 In the context of TCP Session Hijacking, what must an attacker successfully predict to inject packets?

A. The User ID
B. The Sequence Number (SEQ)
C. The MAC address
D. The DNS server IP

4 What is 'Session Fixation'?

A. A method of fixing a static IP address to a session
B. An attack where the attacker fixes the server errors
C. A defense mechanism to keep sessions stable
D. An attack where the attacker sets a user's session ID to one known to the attacker before the user logs in

5 Which attack vector is commonly used to steal Session IDs stored in cookies?

A. Buffer Overflow
B. SQL Injection
C. Ping of Death
D. Cross-Site Scripting (XSS)

6 Which of the following acts as a countermeasure against Session Hijacking by encrypting data in transit?

A. Using simple HTTP
B. Disabling cookies
C. Using Telnet
D. Using SSL/TLS (HTTPS)

7 What is the purpose of the 'HttpOnly' flag in a Set-Cookie header?

A. To ensure the cookie is only sent over HTTP, not HTTPS
B. To prevent client-side scripts (like JavaScript) from accessing the cookie
C. To allow the cookie to be shared across different domains
D. To ensure the cookie expires immediately

8 In a Man-in-the-Middle (MITM) attack used for session hijacking, what tool is often used to manipulate the ARP cache?

A. Traceroute
B. Ping
C. Nmap
D. ARP Spoofing/Poisoning

9 Passive Session Hijacking involves:

A. Monitoring and capturing traffic without altering it
B. Resetting the connection
C. Injecting malicious packets into the stream
D. Crashing the server

10 A good defensive strategy regarding Session IDs after a successful login is to:

A. Keep the same Session ID used before login
B. Make the Session ID static for 24 hours
C. Use the user's username as the Session ID
D. Regenerate a new Session ID

11 In the Client-Server relationship, which entity is responsible for initiating the request?

A. Database
B. Client
C. Firewall
D. Server

12 Which HTTP method is generally considered less secure for transmitting sensitive data because parameters are shown in the URL?

A. HEAD
B. GET
C. POST
D. CONNECT

13 What is 'Directory Traversal' in the context of web server vulnerabilities?

A. Indexing the website on a search engine
B. Accessing files outside the web root folder by manipulating input (e.g., ../)
C. Traversing the network topology
D. Moving files from one folder to another

14 Which of the following is a common vulnerability where a web application fails to properly filter user input before sending it to a database?

A. Denial of Service
B. Session Timeout
C. DNS Spoofing
D. SQL Injection

15 Web Parameter Tampering involves:

A. Deleting web server logs
B. Updating the web browser version
C. Modifying data within form fields, URLs, or cookies to manipulate application behavior
D. Changing the physical server hardware

16 Which tool is commonly used for vulnerability scanning of web applications?

A. Photoshop
B. Nikto or OWASP ZAP
C. Windows Media Player
D. Microsoft Word

17 Why are hidden form fields dangerous if not validated by the server?

A. They cannot be seen by the browser
B. They make the HTML code messy
C. Users can view source, modify the hidden values, and submit them
D. They slow down the website

18 What does SQL stand for?

A. Standard Query List
B. Structured Question Language
C. Structured Query Language
D. Simple Query Logic

19 The core root cause of SQL Injection vulnerabilities is:

A. Using a firewall
B. Trusting user input and mixing code with data
C. The database is too slow
D. The web server is running Linux

20 In a SQL Injection attack, what is the significance of the single quote (') character?

A. It encrypts the password
B. It starts a comment
C. It deletes the database
D. It is used to delimit strings; inserting it can break the query structure

21 What does the injection OR 1=1 typically achieve in a login bypass attack?

A. It deletes the user account
B. It causes a syntax error
C. It creates a condition that is always true, bypassing the password check
D. It sets the password to 1

22 Which SQL comment symbol is often used to ignore the remainder of the original query in MySQL?

A. %%
B. # or --
C. <!-- -->
D. //

23 What is 'Blind SQL Injection'?

A. An attack where the database is offline
B. An attack where the attacker cannot see the screen
C. An attack using invisible ink
D. An attack where the database does not return data/errors to the screen, so the attacker infers data based on server behavior

24 Which SQL command is most dangerous regarding data loss if injected successfully?

A. SELECT
B. UNION
C. INSERT
D. DROP TABLE

25 What is a UNION-based SQL injection?

A. Creating a labor union for DBAs
B. Joining two databases physically
C. Using the UNION operator to combine the results of the original query with the results of an injected query
D. Injecting into the Union Bank website

26 What is the most effective defense against SQL Injection?

A. Hiding the database name
B. Parameterized Queries (Prepared Statements)
C. Input Sanitization only
D. Using complex passwords

27 How does 'Error-based SQL Injection' help an attacker?

A. It provides details about the database structure via verbose error messages
B. It creates a backup of the database
C. It crashes the server immediately
D. It fixes errors in the code

28 Which technique allows an attacker to evade basic pattern-matching detection systems (IDS) during SQL injection?

A. Using a faster internet connection
B. URL Encoding or Hex Encoding
C. Writing the query in capital letters
D. Sending the query via email

29 What is the 'Principle of Least Privilege' in the context of database security?

A. Blocking all users from the database
B. Ensuring the database application connects with an account that has only the minimum necessary permissions
C. Giving every user admin rights
D. Using the oldest version of SQL

30 What is the role of a Web Application Firewall (WAF) regarding SQL Injection?

A. It inspects incoming HTTP traffic and blocks patterns that look like SQL injection attacks
B. It encrypts the database
C. It fixes the code automatically
D. It creates user backups

31 When testing for SQL injection, what is 'Fuzzing'?

A. Downloading the database
B. Encrypting the connection
C. Sending random, invalid, or unexpected data to inputs to see how the application reacts
D. Cleaning the screen

32 Which of the following represents a 'Time-based' Blind SQL Injection?

A. DROP TABLE Users
B. UNION ALL SELECT
C. WAITFOR DELAY '0:0:10'
D. SELECT * FROM Users

33 In a web application, what is Input Validation?

A. Ensuring input data meets expected criteria (type, length, format) before processing
B. Validating the server license
C. Validating that the keyboard is connected
D. Checking if the user is an admin

34 What is the danger of enabling 'xp_cmdshell' in MS SQL Server?

A. It changes the language to Spanish
B. It allows the execution of Operating System commands via SQL
C. It slows down queries
D. It prevents tables from being created

35 Which character is often used to chain multiple SQL queries together in a single injection (Stacking Queries)?

A. Semicolon (;)
B. Period (.)
C. Comma (,)
D. Colon (:)

36 What is Whitespace Manipulation in the context of evading SQLi detection?

A. Deleting all spaces in the code
B. Using a larger monitor
C. Replacing spaces with other whitespace characters (like tabs or newlines) to bypass filters
D. Adding spaces to make the website look better

37 Which of the following is an example of an 'In-band' SQL Injection?

A. The attacker uses a different channel to retrieve data
B. The attack relies solely on time delays
C. The data is retrieved using the same channel (e.g., displayed on the webpage)
D. The attack is performed over the phone

38 What is a 'stored' SQL injection?

A. The code is stored in the browser cache
B. The injection only happens once
C. The injection is stored on a USB drive
D. The malicious code is permanently stored in the database (e.g., in a forum post) and executes later

39 To secure cookies against session hijacking, the 'Secure' flag should be set to:

A. Encrypt the cookie content with ROT13
B. Make the cookie invisible
C. Ensure cookies are sent only over encrypted (HTTPS) connections
D. Allow the cookie on HTTP only

40 Which of these is NOT a valid method to test for SQL Injection?

A. Inputting a single quote into a search box
B. Inputting 1=1 logic
C. Physical inspection of the server hard drive
D. Running a vulnerability scanner

41 In a client-server architecture, where should security validation be most rigorously applied?

A. Neither
B. On the router only
C. Client-side only (JavaScript)
D. Server-side

42 How can 'Stored Procedures' help prevent SQL Injection?

A. They encrypt the hard drive
B. They encapsulate queries and can accept parameters, functioning similarly to parameterized queries
C. They delete all data periodically
D. They make the database slower

43 What does an attacker typically look for in a URL to attempt SQL Injection?

A. Query strings with parameters (e.g., ?id=5)
B. Static HTML pages
C. CSS files
D. Images (.jpg)

44 Which of the following best describes 'Session Timeout' as a defensive strategy?

A. Closing the session automatically after a period of inactivity
B. Turning off the server at night
C. Banning the user forever
D. Slowing down the internet connection

45 What is the risk of having 'Verbose Error Messages' enabled on a live production server?

A. It looks unprofessional
B. It fills up the hard drive
C. It aids attackers in understanding the technology stack and database structure (Information Leakage)
D. It uses too much bandwidth

46 Why is 'Allow-listing' (White-listing) input validation superior to 'Block-listing' (Black-listing)?

A. Block-listing is illegal
B. Allow-listing accepts everything
C. Block-listing often fails because attackers can find variations or encodings that aren't on the list
D. It is faster to write

47 In network session hijacking, what is 'Ack Storm'?

A. A weather condition affecting Wi-Fi
B. A burst of traffic caused by desynchronized sequence numbers where devices repeatedly try to synchronize
C. A hacking tool
D. A type of firewall

48 Using an ORM (Object-Relational Mapping) framework generally reduces SQL injection risks because:

A. It doesn't use SQL
B. It automatically uses parameterized queries under the hood
C. It requires biometric authentication
D. It uses a special firewall

49 Which header helps protect against clickjacking, which can be related to session manipulation?

A. Content-Type
B. X-Frame-Options
C. User-Agent
D. Host

50 When an attacker uses HAVING 1=1 in an injection, they are often trying to:

A. Login as admin
B. Speed up the query
C. Force an error to reveal the table or column name in the error message
D. Delete the table