PrepAway - Latest Free Exam Questions & Answers

How would you protect from these attacks?

Take a look at the following attack on a Web Server using obstructed URL:

How would you protect from these attacks?

PrepAway - Latest Free Exam Questions & Answers

A.
Configure the Web Server to deny requests involving “hex encoded” characters

B.
Create rules in IDS to alert on strange Unicode requests

C.
Use SSL authentication on Web Servers

D.
Enable Active Scripts Detection at the firewall and routers

8 Comments on “How would you protect from these attacks?

    1. Eddie Guerrero says:

      You’re right and there are a few I’ve seen like this, where it’s really a matter of the ‘best’ answer out of all, and the fault is the actual wording of the questions. lol I don’t like this one.

      Even if your server could block hex characters, who’s to say that the web server is not simple vulnerable to any kind of ‘information disclosure’ vulnerabilities or directory traversal vulnerabilities anyway, which would allow the attacker to type normal text and grab the /etc/password file, by doing dot dot slash methods? That’s not hex encoded so A wouldn’t stop the underlying problem with the web server allowing traversal. Then you’d need a WAF or IPS to actually STOP this.

  1. Unethica says:

    You can’t deny all requests with “hex encoded” characters because that would limit functionality. You can’t just broadly disable features because they MIGHT be exploited.

  2. B says:

    There are IDSs out there that detect traffic and also react accordingly. Its all about the type of IDS installed. However, you are right in that this question is a bit unclear! I choose C!


Leave a Reply