A service is designed to respond to an error condition by issuing a message containing detailed error information. This message includes connection information for a database that is shared by numerous services within the service inventory. An attacker intentionally sends an invalid message to the service in order to trigger an error and receive the connection information. The attacker then proceeds to connect to the database and issues a series of malicious SQL queries that make the database non-responsive. As a result, a number of services within the service inventory are disabled. Which of the following types of attacks were successfully carried out?
Answer : B, C
When considering the ESB as providing intermediary logic, which of the following types of subject confirmation methods relate to its access control issues?
Answer : B
Which of the following statements is true?
Answer : D
Service A's logic has been implemented using unmanaged code. An attacker sends a message to Service A that contains specially crafted data capable of manipulating the quoting within a particular XPath expression. This results in the release of confidential information. Service A is a victim of which kind of attack?
Answer : C
The use of parameterized expressions can help avoid which type of attack?
Answer : C
A denial of service attack can be the byproduct of an insufficient authorization attack.
Answer : A
The Exception Shielding pattern can be applied together with the Trusted Subsystem pattern.
Answer : A