Chapter 15: Web Application Vulnerabilities
1. Does placing a Web server in a DMZ protect it from network-borne threats?
2. What are the five classes of attack possible on a Web server?
3. If cookies are so dangerous, why don’t valid Web servers discontinue their use?
4. Can a Web server session ID be stolen over the Internet?
5. Is there any valid reason for servers to collect information about their visitors?
Indicate whether the sentence or statement is true or false.
6. ______ Wget is a tool that can be used to retrieve HTTP, HTTPS, and FTP files over the Internet.
7. ______ Namedroppers is a tool that can be used to capture Web server information and possible
vulnerabilities in a Web site’s pages that could allow exploits such as SQL injection and buffer
overflows.
8. ______ Some cookies can cause security issues because unscrupulous people might store
personal information in cookies that can be used to attack a computer or server.
9. ______ To limit the amount of information a company makes public, you should have a good
understanding of what a competitor would do to discover confidential information.