eh eh eh eh eh eh
MPLETE SOLUTIONS
eh
boundsehcheckingeh-ehcorrectehanswereh✔✔
toehsetehaehlimitehonehtheehamountehofehdataehweehexpectehtoehreceiveehtoehsetehasideehstorageehforehthate
hdata
*requiredehinehmostehprogrammingehlanguages
*ehpreventsehbufferehoverflows
raceehconditionseh-ehcorrectehanswereh✔✔
Aehtypeehofehsoftwareehdevelopmentehvulnerabilityehthatehoccursehwhenehmultipleehprocessesehorehmulti
pleehthreadsehwithinehaehprocessehcontrolehorehshareehaccessehtoehaehparticularehresource,ehandehtheehcorr
ectehhandlingehofehthatehresourceehdependsehonehtheehproperehorderingehorehtimingehofehtransactions
inputehvalidationeh-ehcorrectehanswereh✔✔
aehtypeehofehattackehthatehcanehoccurehwhenehweehfailehtoehvalidateehtheehinputehtoehourehapplicationsehor
ehtakeehstepsehtoehfilterehoutehunexpectedehorehundesirableehcontent
formatehstringehattackeh-ehcorrectehanswereh✔✔
aehtypeehofehinputehvalidationehattacksehinehwhichehcertainehprintehfunctionsehwithinehaehprogrammingehla
nguageehcanehbeehusedehtoehmanipulateehorehviewehtheehinternalehmemoryehofehanehapplication
authenticationehattackeh-ehcorrectehanswereh✔✔
Aehtypeehofehattackehthatehcanehoccurehwhenehweehfailehtoehuseehstrongehauthenticationehmechanismsehfo
rehourehapplications
authorizationehattackeh-ehcorrectehanswereh✔✔
Aehtypeehofehattackehthatehcanehoccurehwhenehweehfailehtoehuseehauthorizationehbestehpracticesehforehoure
happlications
,cryptographicehattackeh-ehcorrectehanswereh✔✔
Aehtypeehofehattackehthatehcanehoccurehwhenehweehfailehtoehproperlyehdesignehourehsecurityehmechanismse
hwhenehimplementingehcryptographicehcontrolsehinehourehapplications
client-sideehattackeh-ehcorrectehanswereh✔✔
Aehtypeehofehattackehthatehtakesehadvantageehofehweaknessesehinehtheehsoftwareehloadedehonehclientehma
chinesehorehoneehthatehusesehsocialehengineeringehtechniquesehtoehtrickehusehintoehgoingehalongehwithehth
eehattack
XSSeh(CrossehSiteehScripting)eh-ehcorrectehanswereh✔✔
anehattackehcarriedehoutehbyehplacingehcodeehinehtheehformehofehaehscriptingehlanguageehintoehaehwebehpag
eehorehotherehmediaehthatehisehinterpretedehbyehaehclientehbrowser
XSRFeh(cross-siteehrequestehforgery)eh-ehcorrectehanswereh✔✔
anehattackehinehwhichehtheehattackerehplacesehaehlinkehonehaehwebehpageehinehsuchehaehwayehthatehitehwilleh
beehautomaticallyehexecutedehtoehinitiateehaehparticularehactivityehonehanotherehwebehpageehorehapplicati
onehwhereehtheehuserehisehcurrentlyehauthenticated
clickjackingeh-ehcorrectehanswereh✔✔
Anehattackehthatehtakesehadvantageehofehtheehgraphicalehdisplayehcapabilitiesehofehourehbrowserehtoehtrick
ehusehintoehclickingehonehsomethingehweehmightehnotehotherwise
server-sideehattackeh-ehcorrectehanswereh✔✔
Aehtypeehofehattackehonehtheehwebehserverehthatehcanehtargetehvulnerabilitiesehsuchehasehlackehofehinputehv
alidation,ehimproperehorehinadequateehpermissions,ehorehextraneousehfilesehleftehonehtheehserverehfromeht
heehdevelopmentehprocess
Protocolehissues,ehunauthenticatedehaccess,eharbitraryehcodeehexecution,ehandehprivilegeehescalationeh-
ehcorrectehanswereh✔✔Nameehtheeh4ehmainehcategoriesehofehdatabaseehsecurityehissues
webehapplicationehanalysisehtooleh-ehcorrectehanswereh✔✔
Aehtypeehofehtoolehthatehanalyzesehwebehpagesehorehweb-
,basedehapplicationsehandehsearchesehforehcommonehflawsehsuchehasehXSSehorehSQLehinjectionehflaws,ehand
ehimproperlyehsetehpermissions,ehextraneousehfiles,ehoutdatedehsoftwareehversions,ehandehmanyehmoreehs
uchehitems
protocolehissueseh-ehcorrectehanswereh✔✔
unauthenticatedehflawsehinehnetworkehprotocols,ehauthenticatedehflawsehinehnetworkehprotocols,ehflawseh
inehauthenticationehprotocols
arbitraryehcodeehexecutioneh-ehcorrectehanswereh✔✔
Anehattackehthatehexploitsehanehapplicationsehvulnerabilityehintoehallowingehtheehattackerehtoehexecuteehc
ommandsehonehaehuser'sehcomputer.
*eharbitraryehcodeehexecutionehinehintrinsicehorehsecurableehSQLehelements
PrivilegeehEscalationeh-ehcorrectehanswereh✔✔
Anehattackehthatehexploitsehaehvulnerabilityehinehsoftwareehtoehgainehaccessehtoehresourcesehthatehtheehuse
rehnormallyehwouldehbeehrestrictedehfromehaccessing.
*ehviaehSQLehinjectionehorehlocalehissues
validatingehuserehinputseh-ehcorrectehanswereh✔✔aehsecurityehbestehpracticeehforehallehsoftware
*ehtheehmosteheffectiveehwayehofehmitigatingehSQLehinjectionehattacks
Niktoeh(andehWikto)eh-ehcorrectehanswereh✔✔
Aehwebehserverehanalysisehtoolehthatehperformsehchecksehforehmanyehcommonehserver-
sideehvulnerabilitieseh&ehcreatesehanehindexehofehallehtheehfilesehandehdirectoriesehitehcanehseeehonehtheeht
argetehwebehservereh(aehprocessehknownehasehspidering)
burpehsuiteeh-ehcorrectehanswereh✔✔Aehwell-
knownehGUIehwebehanalysisehtoolehthatehoffersehaehfreeehandehprofessionalehversion;ehtheehproehversionehi
ncludesehadvancedehtoolsehforehconductingehmoreehin-depthehattacks
, fuzzereh-ehcorrectehanswereh✔✔
Aehtypeehofehtoolehthatehworksehbyehbombardingehourehapplicationsehwithehallehmannerehofehdataehandehin
putsehfromehaehwideehvarietyehofehsources,ehinehtheehhopeehthatehweehcanehcauseehtheehapplicationehtoehf
ailehorehtoehperformehinehunexpectedehways
MiniFuzzehFileehFuzzereh-ehcorrectehanswereh✔✔
AehtoolehdevelopedehbyehMicrosoftehtoehfindehflawsehinehfile-handlingehsourceehcode
BinScopeehBinaryehAnalyzereh-ehcorrectehanswereh✔✔
AehtoolehdevelopedehbyehMicrosoftehtoehexamineehsourceehcodeehforehgeneralehgoodehpractices
SDLehRegexehFuzzereh-ehcorrectehanswereh✔✔
AehtoolehdevelopedehbyehMicrosoftehforehtestingehcertainehpattern-
matchingehexpressionsehforehpotentialehvulnerabilities
goodehsourcesehofehsecureehcodingehguidelineseh-ehcorrectehanswereh✔✔
CERT,ehNISTeh800,ehBSI,ehanehorganization'sehinternalehcodingehguidelines
OSehhardeningeh-ehcorrectehanswereh✔✔
theehprocessehofehreducingehtheehnumberehofehavailableehavenuesehthroughehwhichehourehOSehmightehbee
hattacked
attackehsurfaceeh-ehcorrectehanswereh✔✔
Theehtotalehofehtheehareasehthroughehwhichehourehoperatingehsystemehmightehbeehattacked
6ehmainehhardeningehcategorieseh-ehcorrectehanswereh✔✔1.ehRemovingehunnecessaryehsoftware
2.ehRemovingehorehturningehoffehunessentialehservices
3.ehMakingehalterationsehtoehcommonehaccounts
4.ehApplyingehtheehprincipleehofehleastehprivilege