Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilWeb Application Hacking and Security

Domain 8Objective 1

Authentication Bypass WAHS Practice Questions (Page 4)

Part of the Authentication and Session Management domain, which makes up ~17% of our current practice bank. EC-Council does not publish an official question count, but from its 360-minute exam (~145–240 total, ~25–41 in this domain), expect 8–14 from this objective — we provide 75 practice questions to prepare you well beyond it. (estimate)

75questions here
15free pages
20concepts

Questions 16–20

  1. 16application · medium

    A password reset link contains a token that is generated using the user's email address and a fixed secret key. The token does not expire. What is the most likely attack?

    Select an answer first
  2. 17foundation · easy

    How can an attacker exploit client-side scripts to bypass authentication?

    Select an answer first
  3. 18application · medium

    A web application uses JavaScript to disable the submit button on a login form until the user enters a valid email format. A penetration tester uses a proxy to intercept the request and modifies the email parameter to an invalid format, then forwards it to the server. The server accepts the request and logs the tester in. Which vulnerability is being exploited?

    Select an answer first
  4. 19application · medium

    A mobile application communicates with a backend API. The API has an endpoint /api/user/profile that returns user data. The mobile app includes a token in the Authorization header, but the API also accepts requests without any token if the request comes from a certain IP range. An attacker discovers this and accesses other users' profiles by changing the user_id parameter. Which two vulnerabilities are present?

    Select an answer first
  5. 20application · medium

    A web application uses OAuth 2.0 with a third-party provider for login. The application only verifies that the OAuth response contains an email address, but does not verify the token's signature or issuer. What is the most likely attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “WAHS” is a trademark of its owner, used for identification only.