Reader small image

You're reading from  CompTIA CASP+ CAS-004 Certification Guide

Product typeBook
Published inMar 2022
PublisherPackt
ISBN-139781801816779
Edition1st Edition
Right arrow
Author (1)
Mark Birch
Mark Birch
author image
Mark Birch

Mark Birch is an experienced courseware developer and teacher in both information systems and cyber-security. Mark has been developing content and teaching CompTIA A+ classes for more than 20 years and understands the subject area in great depth. Mark began his career working within the aerospace industry (for a major defense contractor) and has over 30 years' experience consulting, engineering, and deploying secure information systems. He has spent over 20 years working with the United States Military and United Kingdom Armed Forces, helping many students attain their learning goals. Mark has ensured that soldiers, officers, and civilians have had the best opportunities to gain cyber-security accreditation.
Read more about Mark Birch

Right arrow

Recognizing common attacks

Attacks against systems and software are a real threat, based on the fact that systems need to be made accessible to business users and customers. For web applications, the typical scenario is a customer-facing application server behind a firewall, able to communicate with intranet-based services. A typical deployment can be seen in Figure 7.7, where the inputs will be through web-based forms run on the client browser and the results forwarded to the web application server:

Figure 7.7 – Web application server located in DMZ

When we secure our networks using secured firewalls, it is difficult to attack the intranet services directly, so it is the web application server that is targeted. This is where the attacker will direct the attacks. In this section, we will focus on attacks that use the model shown in Figure 7.7.

Directory traversal

Directory traversal is when an attacker can input syntax that allows them to move...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
CompTIA CASP+ CAS-004 Certification Guide
Published in: Mar 2022Publisher: PacktISBN-13: 9781801816779

Author (1)

author image
Mark Birch

Mark Birch is an experienced courseware developer and teacher in both information systems and cyber-security. Mark has been developing content and teaching CompTIA A+ classes for more than 20 years and understands the subject area in great depth. Mark began his career working within the aerospace industry (for a major defense contractor) and has over 30 years' experience consulting, engineering, and deploying secure information systems. He has spent over 20 years working with the United States Military and United Kingdom Armed Forces, helping many students attain their learning goals. Mark has ensured that soldiers, officers, and civilians have had the best opportunities to gain cyber-security accreditation.
Read more about Mark Birch