
sapt_cern
Quiz by Michael Kirchner
Tag the questions with any skills you have. Your dashboard will track each student's mastery of each skill.
The pentest target of the course is
Is "maps.web.cern.ch" a valid target for this pentest? Take your time to do the actual research.
Is "cerncourier.com" a valid target for this pentest? Take your time to do the actual research.
How can you lower the probability to cause a denial of service situation while testing a target system?
You found a SQL injection vulnerability in a web site operated by CERN. You can read internal information that is not visible on the web site. The next steps you do are:
The allowed timeframe to conduct security tests against the CERN infrastructure ...
You found a cross-site request forgery vulnerability in a CERN system that you were analyzing. The attack works the following way: If a legit administrator visits a link that you have prepared, a request is sent in the background that promotes your regular system user to an administrator user. Overall, the legitimate administrator will not notice what is going on, as the request is sent in the background. You see the administrator's e-mail address on the affected web site and send her/him an e-mail with the prepared link inside. Is this procedure in line with the rules of engagement of this course?
When working on the CERN pentest while being on-site at University of Applied Sciences St.Pölten, the following networks should be used as the source of your activities.
You found a user registration feature on a CERN website that is in scope of the pentest. Trying to register a new user account is fine.
You found information about the CERN IT infrastructure on a web site that is not allowed to be tested by the rules of engagement of this course. Using this information for your further testing activities is fine, as long as you do not actively test systems that are out of scope.