PrepAway - Latest Free Exam Questions & Answers

which of the following attacks?

A web application is configured to target browsers and allow access to bank accounts to siphon money to a foreign account. This is an example of which of the
following attacks?

PrepAway - Latest Free Exam Questions & Answers

A.
SQL injection

B.
Header manipulation

C.
Cross-site scripting

D.
Flash cookie exploitation

Explanation:
Say you set your browser to fully trust your bank’s site and allow it to run scripts in your browser.
On the other hand, you deny that privilege from the rest of the sites you visit.
If the bank’s site is vulnerable to XSS, when you click on a malformed URL that was presented to you at hacker.com, you will be redirected to your banks site
(which you previously granted scripting rights) and the malicious script written by someone at hacker.com will run. XSS in that manner is an easy way to run scripts
on cautious clients that allow only very specific sites to send them scripts.


Leave a Reply