Free Certified Ethical Hacker (CEH v13) practice — 6 questions on Web Application Hacking, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Web Application Hacking
A penetration tester is testing a search parameter on a web application for SQL injection. Error messages are fully suppressed by the application, and the page content does not visibly change regardless of whether a true or false condition is injected. Which technique should the tester use to confirm the presence of SQL injection?
Time-based blind SQLi injects conditional statements that cause a measurable delay in the server response (e.g., IF(condition, SLEEP(5), 0)). Because it relies only on response timing rather than visible content differences or error output, it is the only listed technique that works when both content-based and error-based signals are unavailable.
Question 2 of 6 · Web Application Hacking
A web application lets users submit a URL, which the server then fetches server-side to generate an image thumbnail. An attacker submits a URL pointing to the cloud instance metadata service and retrieves sensitive internal data through the thumbnail response. Which remediation BEST addresses this Server-Side Request Forgery (SSRF) vulnerability?
SSRF is remediated by strictly controlling which destinations the server is permitted to reach — an allowlist of approved domains/IP ranges combined with explicit blocking of loopback, link-local (169.254.0.0/16), and private RFC1918 ranges prevents the server from being used as a proxy to reach internal resources.
Question 3 of 6 · Web Application Hacking
A SOAP-based web service parses XML input from clients. A tester submits an XML document containing a DOCTYPE declaration that defines an external entity referencing the local file /etc/passwd, and the parsed response reflects the file's contents back to the tester. Which vulnerability is being exploited?
XXE occurs when a poorly configured XML parser resolves external entities defined in a DOCTYPE declaration, allowing an attacker to read local files, perform SSRF, or cause denial of service. The DOCTYPE/external-entity file-disclosure pattern described is the textbook signature of XXE.
Question 4 of 6 · Web Application Hacking
A REST API validates JWT bearer tokens for authentication. A tester intercepts a valid token, modifies the header's "alg" field to "none", strips the signature segment entirely, and resubmits the token — the API accepts it as authenticated. Which server-side misconfiguration allowed this attack?
The classic "alg:none" JWT attack succeeds because the server's verification logic reads the algorithm from the attacker-controlled header instead of enforcing a fixed, expected algorithm server-side, and accepts tokens with no signature at all. The fix is to explicitly whitelist and enforce the expected algorithm and reject 'none'.
Question 5 of 6 · Web Application Hacking
An e-commerce application lets authenticated users view order details via /orders?id=1234. A tester changes the id value to another customer's order number and successfully views that customer's private order data without any additional authorization check occurring. Which remediation BEST addresses this vulnerability?
This is Insecure Direct Object Reference (IDOR), a form of broken access control. The root cause is the missing server-side ownership/authorization check on the requested object. The only durable fix is to verify, on every request, that the authenticated user is authorized to access the specific order referenced — independent of how the identifier is represented.
Question 6 of 6 · Web Application Hacking
Which statement correctly differentiates HTTP Parameter Pollution (HPP) from Cross-Site Request Forgery (CSRF)?
HPP submits the same parameter name multiple times (e.g., in query string, body, or across GET/POST) to exploit inconsistent parsing between the front-end and back-end, altering application logic such as bypassing filters or overriding values. CSRF, by contrast, tricks a victim's browser into submitting a state-changing request using their already-authenticated session, with no need to steal credentials or manipulate parameter parsing.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code SECPREP34 — valid through Oct 11.