Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Lesson 5 - Output Handling

Total questions: 10

Worksheet time: 20mins

Name
Class
Date
1.

Which of the following statements is incorrect in XSS attack?

a)

A

b)

B

c)

C

d)

D

2.

Cross-site Scripting may be used to hijack cookie-based sessions.

a)

True

b)

False

3.

What is the first step in simplest possible session hijacking using Cross-site Scripting?

a)

A

b)

B

c)

C

d)

D

4.

What is the main task of injected script by attacker in XSS-based session hijacking?

a)

A

b)

B

c)

C

d)

D

5.

In a XSS session hijacking, the attacker connects directly to the web site, he can get victim's unique cookie, _______________.

a)

only if the victim is logged in

b)

only if the victim is logged out

c)

and does not matter victim is logged in or not

d)

but he has no full access at the same level of victim

6.

Attacker used a script to change data displayed to bank clerk for manual inspection. This can be successful because of __________________.

a)

vulnerability in the bank database

b)

inappropriate output handling in web application

c)

not escaping shell meta-characters

d)

careless manual inspection by clerk

7.

In general, Cross-site Scripting is a _______________.

a)

network layer problem

b)

input validation problem

c)

shell problem

d)

metacharacter problem

8.

For what specific attack, the script below can be used?

a)

Session Hijacking

b)

SQL Injection

c)

Text Modification

d)

All the above attacks

9.

As _____________ are available to a script, Cross-site Scripting may be used to hijack cookie-based sessions.

a)

cookies

b)

sessions

c)

HTTP requests

d)

Shell commands

10.

In HTML Cross-site Scripting, the most appropriate time to deal with data passing problem is whenever application ____________________.

a)

generates some input

b)

generates some output

c)

passes data to the database

d)

sends HTTP requests