Solved

Dylan Found a Vulnerability on a Web Application That Let

Question 40

Multiple Choice

Dylan found a vulnerability on a web application that let him copy the sessionID out of a local cookie and place it into another cookie, therefore assuming the identity of the original user. The problem is that the server also associates the originating IP address. Dylan simply spoofs that address but he then finds he cannot establish an interactive session with the server. Why?


A) The attack should work as stated.
B) There is a NAT firewall preventing this activity
C) Dylan cannot spoof his address over HTTP
D) The server will send all replies back to the spoofed IP.

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions

Unlock this Answer For Free Now!

View this answer and more for free by performing one of the following actions

qr-code

Scan the QR code to install the App and get 2 free unlocks

upload documents

Unlock quizzes for free by uploading documents