security Online Quiz - 9

security Online Quiz - 9

20 Questions Published

Questions

Question 1 Multiple Choice (Single Answer)

Data returned by which of the following methods should be validated before using it

  1. getParameter ()
  2. getQueryString ()
  3. getCookies ()
  4. getHeaders ()
  1. 1
  2. 1 and 2
  3. 1,2 and 3
  4. 1,2,3 and 4
Question 2 Multiple Choice (Single Answer)

Which of the following are countermeasures for XSS

  1. Releasing Resources after use
  2. Input Validation
  3. Running with least privilege
  4. URL based access control
  5. Output Encoding
  1. 1 and 4
  2. 2 and 4
  3. 2 and 5
  4. 3 and 5
Question 3 Multiple Choice (Single Answer)

The following code is part of a system daemon that is run with elevated privileges. It opens a temp file in /tmp directory as a cache. Is there an issue in this code sample? Please assume that filling up /tmp is not an issue here.

int outfile = fopen(“/tmp/cache_data”, O_WRONLY | O_CREAT | O_TRUNC, 0600);
  1. Since the file name is hard coded, fopen() will fail if the file already exists.
  2. 0600 is not a secure option. The parameter 0600 should be changed to 0666
  3. Attackers can exploit by creating a symboling link /tmp/cache_data that points to a system file.
  4. Attackers can exploit the application's cache by writing directly to /tmp/cache_data
Question 4 Multiple Choice (Single Answer)

Is writing to an already freed memory a vulnerability?

x = malloc(200); /* do something with x */ 
free (x); /* do something else */  
strcpy(x, “somedata”);  
  1. Overwriting freed memory is a security vulnerability
  2. Depends on the application and how important “somedata” is
  3. This will result in a buffer overflow since the freed memory location cannot handle 8 characters of data “somedata”
  4. strcpy() will fail as it cannot write to already freed memory, and the application will crash.
Question 5 Multiple Choice (Single Answer)

In the following code, which is the location of vulnerability?

1  bIsAdmin = true; 
2  try  
3  { 
4  function (); 
5   bIsAdmin = isAdminUser(userName); 
6  } 
7  catch (Exception ex)  
8  { 
9   log.write(ex.toString()); 
10 }
  1. Line 9
  2. Line 5
  3. Line 7
  4. Line 1
Question 6 Multiple Choice (Single Answer)

In the following code, which is the location of vulnerability?

1 String username = req.getParameter("loginID"); 
2 String password = req.getParameter("loginPassword"); 
3 String sql = "SELECT UserID from Employee WHERE Emp_ID = ? AND Password=?"; 
4 pstmt = con.prepareStatement(sql); 
5 pstmt.setString(1,username); 
6 pstmt.setString(2,password); 
7 pstmt.execute(); 
8 user = pstmt.getResultSet(); 
9 if(user!=null)  
10 { 
11  while (user.next()) 
12  { 
13   userInfo.add(user.getString(1)); 
14  }  
15 } 
16 else 
17 { 
18  log.debug(“Invalid Login: Login ID-”+ username+” Password-”+ password); 
19 }
  1. Line 5
  2. Line 4
  3. Line 18
  4. Line 11
Question 7 Multiple Choice (Single Answer)

Identify the line on which the vulnerability exists:

1 public class performSearchAction extends HttpServlet{ 
2 // Servlet for Search Action  
3  public void doPost(HttpServletRequest req, HttpServletResponse res)  
4  { 
5  	try 
6  	{ 
7  		ArrayList arrSearch =  Util.performSearchAction(req, res); 
8  		req.setAttribute(“SearchResults”,arrSearch); 
9  		RequestDispatcher rd = getServletContext().getRequestDispatcher("/SearchResult.jsp"); 
10  	rd.forward(req,res); 
11  } catch (Exception e) { 
12               log.debug(“Exception occurred:”+e); 
13               } 
14  } //End of doPost method 
15  public void doGet(HttpServletRequest req, HttpServletResponse res) 
16  { 
17    doPost(req,res); 
18  } //End of doGet method 
19 } //End of Class
  1. Line # 12
  2. Line # 9
  3. Line # 17
  4. Line # 8
Question 8 Multiple Choice (Single Answer)

Give the name of the vulnerability resides in the below code:

... 
Runtime rt = Runtime.getRuntime(); 
Process proc = rt.exec("cmd.exe /c type "+request.getParameter("path")); //path is an Input Parameter and contains the file name. 
InputStream stdin = proc.getInputStream(); 
InputStreamReader isr = new InputStreamReader(stdin); 
BufferedReader br = new BufferedReader(isr);              
...
  1. Race Condition
  2. Command Injection
  3. Denial of Service
  4. Cross Site Request Forgery
Question 9 Multiple Choice (Single Answer)

Are there any memory issues in the following code? Please assume that variable inputsize has the correct size.

int add_num_array(int inputsize, int num) {
	int *newnum = malloc (inputsize * sizeof(int));  /* 1 */
	int i;   
	for (i=0; i<n;i++) {     /* 2 */   
	newnum[i] += num;      /* 3 */  
	} 
}
  1. No vulnerabilities are present
  2. Line 1 should only use malloc(inputsize);
  3. Line 2 should be for (i=0; i<=n, i++)
  4. Line 1 should use calloc() instead of malloc()
Question 10 Multiple Choice (Single Answer)

What is the vulnerability in this code?

	char output[20];  
	/*   Assume data is a character array with value %200d asdf   */  
	sprintf(output, data);
  1. Buffer overflow
  2. Off by one error
  3. Format string vulnerability
  4. No vulnerabilities are present in this code
Question 11 Multiple Choice (Single Answer)

What is the vulnerability in this code?

int main(int argc, char * argv[]) {   
	printf (argv[1]);  
}
  1. Buffer overflow
  2. Off by one error
  3. Format string vulnerability
  4. No vulnerabilities are present in this code
Question 12 Multiple Choice (Single Answer)

What is the possible vulnerability in this code?

	unsigned int total, userinput1, userinput2;  
	userinput1 = receiveInput();  
	userinput2 = receiveInput();  
	total = userinput1 + userinput2;
  1. Integer overflow
  2. Buffer overflow
  3. Stack overflow
  4. Data type mismatch
Question 13 Multiple Choice (Single Answer)

Which Compilation switch will you use to check Buffer Overflows?

  1. /GS on Visual C++ and -fmudflap -fmudflapth -fmudflapir on GCC
  2. /O in Vc++ and -O2 in GCC
  3. /S in Vc++ and -fcrossjumping in GCC
  4. /S in VC++ and -fno-function-cse in GCC
Question 14 Multiple Choice (Single Answer)

What can go wrong in following code?

#include <stdio.h>  
int main(int argc, char *argv[]) {

if(argc != 3) {
		printf("usage: %s [source] [dest]\n", argv[0]);
		exit(1);

	}
 
	char x;
	FILE *file[2];
	file[0] = fopen(argv[1],"r+");
	file[1] = fopen(argv[2],"w+");
	for(x = 0; x < 2; x++) {	
		if(file[x] == NULL) {
			printf("error opening file.\n");
			exit(1);
		}
	}
	
	do {
		x = fgetc(file[0]);
		fputc(x,file[1]);
	} while(x != EOF);
	
	 for(x = 0; x < 2; x++)
		fclose(file[x]);
	 return 0; 
}
  1. SQL Injection
  2. Arc Injection
  3. Buffer Overflow
  4. both 2 and 3
Question 15 Multiple Choice (Single Answer)

Which compilation switch should be enabled for stack protection? Choose the best and most secure option.

  1. fstack-protector
  2. fstack-protector-all
  3. fdelete-null-pointer-checks
  4. Both a and b
Question 16 Multiple Choice (Single Answer)

unsigned char j,k; j=getchar(); k=getchar(); unsigned char result = j + k; What vulnerability is present in this code:

  1. Heap Overflow
  2. Integer overflow
  3. Buffer overflow
  4. No Vulnerability
Question 17 Multiple Choice (Single Answer)

Which statement creates a buffer over flow? (Line numbers are marked using comments /* */)

#include <iostream.h>  
#include <stdio.h>  
#include <string.h>  
int main (int argc, char *argv[])  {   
	int i=0,j=1;   
	char ipstring[80];   
	for (;i<=3;i++){    
		cout<<"\n entering a new character\n";    
		j=getchar();/*1*/     
		cout<<”enter a string”;    
		gets(ipstring);/*2*/    
		cout<<j<<"\n";    
	}   
	return 0;  
}  
```	
  1. 1
  2. 2
  3. Both
  4. None
Question 18 Multiple Choice (Single Answer)

What is the vulnerability ?

int main (int argc, char *argv[]) { 
     char k[3]; 
	 int i=0,j=1; 
	 char buffer[50]; 
	 strncpy(buffer, argv[1], sizeof(buffer) - 1); 
	 buffer[49]='/0'; 
	 unsigned char ch='a'; 
	 k[0]=1; 
	 do{   
		i++;   
		k[i]=ch+i; 
	} while(i<3); 
	
	return 0; 
}  
  1. Heap overflow
  2. Integer overflow
  3. Off by one error
  4. None of the above
Question 19 Multiple Choice (Single Answer)

Which attack(s) are possible in the below code:

<% response.sendRedirect("/with_lang.jsp?lang="+request.getParameter("language")); %>
  1. Content Spoofing
  2. HTTP Response Splitting
  3. Directory Listing
  4. a & b
Question 20 Multiple Choice (Single Answer)

Identify the name of the vulnerability exist in the below code:

1 ...   
2 public class ShowUserDetailsAction extends HttpServlet   
3 {   
4 private String currentUser;     
5 public void doPost(HttpServletRequest req, HttpServletResponse res)   
6 {   
7 try   
8 {   
9  currentUser = req.getParameter("userID");  
10  RequestDispatcher rd = getServletContext().getRequestDispatcher ("/ShowDetails.jsp");  
11  if (!"".equals(currentUser))  
12  {  
13     
14   ArrayList userInfo = new ArrayList();  
15   LoginDAO objLoginDAO = new LoginDAO();  
16   userInfo = objLoginDAO.getUserInfo(currentUser);  
17     
18   if (userInfo!=null && (userInfo.size()!= 0))  
19   {  
20    req.setAttribute("UserInfo", userInfo);  
21   }  
22   else  
23   {  
24    req.setAttribute("NoUser", "true");  
25   }  
26  }  
27  rd.forward(req,res);  
28 } catch (Exception e)  
29 {  
30  log.debug(“Error Occurred:”+ e);  
31 }  
32 }  
33 }   
34 ...
  1. URL Tampering
  2. Brute Forcing
  3. Race Condition
  4. HTML Injection