WorksheetsLesson 5 - Output Handling
Total questions: 10
Worksheet time: 20mins
Which of the following statements is incorrect in XSS attack?
A
B
C
D
Cross-site Scripting may be used to hijack cookie-based sessions.
True
False
What is the first step in simplest possible session hijacking using Cross-site Scripting?
A
B
C
D
What is the main task of injected script by attacker in XSS-based session hijacking?
A
B
C
D
In a XSS session hijacking, the attacker connects directly to the web site, he can get victim's unique cookie, _______________.
only if the victim is logged in
only if the victim is logged out
and does not matter victim is logged in or not
but he has no full access at the same level of victim
Attacker used a script to change data displayed to bank clerk for manual inspection. This can be successful because of __________________.
vulnerability in the bank database
inappropriate output handling in web application
not escaping shell meta-characters
careless manual inspection by clerk
In general, Cross-site Scripting is a _______________.
network layer problem
input validation problem
shell problem
metacharacter problem
For what specific attack, the script below can be used?
Session Hijacking
SQL Injection
Text Modification
All the above attacks
As _____________ are available to a script, Cross-site Scripting may be used to hijack cookie-based sessions.
cookies
sessions
HTTP requests
Shell commands
In HTML Cross-site Scripting, the most appropriate time to deal with data passing problem is whenever application ____________________.
generates some input
generates some output
passes data to the database
sends HTTP requests
