Q: 7
A service is designed to respond to an error condition by issuing a message containing detailed error
information. This message includes connection information for a database that is shared by
numerous services within the service inventory. An attacker intentionally sends an invalid message to
the service in order to trigger an error and receive the connection information. The attacker then
proceeds to connect to the database and issues a series of malicious SQL queries that make the
database non-responsive. As a result, a number of services within the service inventory are disabled.
Which of the following types of attacks were successfully carried out?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.