Skip to content
ScopefileGet the app

Module 14Domain 5 of 9Web Application Hacking

Web application threats and the methodology CEH tests

Hacking web applications, CEH Module 14, is about flaws in an application's own code and logic: who may reach which data, what the app does with untrusted input, what runs in a visitor's browser, and how APIs, webhooks and planted scripts widen the attack surface. Sort each scenario by where trust broke, and the matching defense sits in the same row of the table below.

Exam
312-50
Domain
5 of 9
Domain weight
14%
This file
~5%
Targets
17

The attack classes, by effect and by weakness

Broken access control
A user reaches records or functions outside their permissions. It relies on a server that trusts the client's claims (a hidden form field, a role flag kept in the browser) instead of checking authorization on every request.
Injection
Untrusted input ends up interpreted as part of a command, query or expression. It relies on code that builds instructions by concatenating data into them: SQL, OS command, LDAP and XML injection share one family and one cure.
Cross-site scripting (XSS)
Script supplied by an outsider executes in another visitor's browser as if the site had sent it. It relies on pages that write untrusted data into HTML or JavaScript without encoding it for that context.
Cross-site request forgery (CSRF)
A signed-in user's browser is made to submit a state-changing request the user never chose. It relies on an application that treats the session cookie alone as proof the user meant the action.
Server-side request forgery (SSRF)
The application server is made to fetch an address an outsider picked, often one only the server can reach. It relies on URL-fetching features with no allowlist of destinations.
Path traversal and file inclusion
A file parameter reaches files outside the intended folder (traversal) or makes the app load and run one (inclusion). Both rely on paths built from input without canonicalizing or allowlisting.
Authentication failures
Logins, password recovery or session handling can be defeated. They rely on single-factor logins, no throttling and sessions that are not renewed or ended properly.
Business logic flaws
Legitimate features used in an order the designers never expected, such as skipping a workflow step. They rely on missing server-side checks of the process, so scanners rarely find them.
Web shell
A script planted on the web server that gives an outsider ongoing remote control. It relies on a server where new executable content can appear in served directories without anyone noticing.
Web API and webhook risks
APIs hand data and functions straight to other programs, so retired or undocumented versions that still answer widen the exposure. Webhooks are inbound callbacks that rely on the receiver not verifying who sent them.

What the analyst sees, and the control that closes it

Module 14 threats with the observable clue, the matching control and the OWASP home in each edition
ThreatClues in a scenarioControl that closes itOWASP 2021 / 2025
Broken access controlOrdinary roles reaching admin pages or functions; permission checks that exist only in client-side codeServer-side authorization on every request, deny by defaultA01 / A01
InjectionDatabase or interpreter errors in responses; WAF alerts on query or shell syntax in form fieldsParameterized queries, allowlist validation, least-privilege accountsA03 / A05
XSSMarkup or script stored in comment and profile fields; Content-Security-Policy violation reportsContext-aware output encoding, input validation, a strict Content-Security-PolicyA03 / A05
CSRFAccount changes the user denies making, with an Origin or Referer from an unrelated siteAnti-CSRF tokens, SameSite cookies, re-authentication for sensitive actionsA01 / A01
SSRFThe app server opening connections to internal-only hosts; egress firewall hitsDestination allowlists, blocking internal ranges, egress filteringA10 / A01
Path traversal, file inclusionRequests for system files in access logs; file parameters full of encoded slashesCanonicalize paths, map IDs to an allowlist of files, run with least privilegeA01 / A01
Authentication failuresFailed logins spread thinly across many accounts from many sourcesMFA, breached-password checks, throttling, new session ID at loginA07 / A07
Web shellNew script files in the web root; the web server process starting shells or calling outFile integrity monitoring, alerts on child processes of the web server, a locked-down service accountNot a category

OWASP homes checked on owasp.org on Oct 11, 2026. Web shells have no category of their own in either list.

What Module 14 owns, and what it leaves to its neighbors

Module 14 is one of three modules in Domain 5, Web Application Hacking, which carries 14% of the exam per EC-Council's exam blueprint v5.0 (checked Oct 11, 2026). The other two are web server hacking, which owns the server software and its patching, and the SQL injection module, which owns the database flaw in depth. Keep that boundary and you stop spending Module 14 time on points graded elsewhere.

The high-yield core is the table above: one clue type and one control per threat. Next come the OWASP editions (see the trap below) and the API list. Tool rosters and scanner feature lists are the tail: learn what each tool is for, then move on.

Neighboring terms, told apart

  • XSS vs CSRF vs SSRF: decide whose machine sends the harmful request, the victim's browser or the server. The full split is on the XSS, CSRF and SSRF comparison.
  • Authentication vs access control: authentication answers who you are; access control answers what that identity may touch.
  • Path traversal vs file inclusion vs command injection: traversal reads a file, inclusion loads and runs one, command injection hands input to the operating system shell.
  • Session theft vs CSRF: theft takes the token and uses it elsewhere; CSRF never sees the token and rides the victim's browser instead. Token theft belongs to the session hijacking module.

Name the weakness, then the fix

Expect a mix of definitions and short incident scenarios. Match each one to its row in the threat table, then hold its control column against the options.

Answered 0/17Hits 0

T-01

An API authentication logs show user Alice (tenant_id=5) successfully authenticated with a valid JWT and accessed /api/documents/8471. The database shows document 8471 belongs to tenant_id=12. The API returned HTTP 200 with the document content. Which vulnerability is MOST likely present and what is the primary control failure?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ASession fixation forces a victim to use a session ID the attacker chose; here Alice used her own valid token, and the failure is what she was allowed to read.
  2. BAlgorithm confusion would mean a forged or tampered token, but the log shows a valid JWT for Alice, so signature checks are not where the control failed.
  3. CCredential stuffing reuses leaked passwords; the log shows genuine authentication with a valid JWT, so this is an authorization problem, not a login one.
  4. DCorrect: the API checked who Alice was but not whether document 8471 belonged to her tenant, which is Broken Object Level Authorization, first in the OWASP API Top 10 2023.
T-02

You have been assigned to assess the security of a web application but have limited financial resources. Which of the following open-source tools would you MOST LIKELY use to perform this task?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: ZAP is a free, open-source web application scanner and intercepting proxy, originally an OWASP project and now maintained independently as ZAP, which suits a limited budget.
  2. BAcunetix is a commercial, paid web vulnerability scanner; capable, but not open source and not the budget choice.
  3. CNetsparker, now sold as Invicti, is a commercial scanner with proof-based scanning; it requires a paid license rather than being open source.
  4. DBurp Suite Professional is a widely used commercial tool; only the limited Community edition is free, and neither edition is open source.
T-03

An XSS vulnerability allows script injection on a banking site that sets session cookies with HttpOnly and Secure flags and enforces a strict Content-Security-Policy. An attacker successfully injects a script. What action can the injected script MOST reliably perform despite these protections?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AHttpOnly prevents scripts from reading cookies through document.cookie, so stealing the session cookie value this way is exactly what that flag blocks.
  2. BCorrect: injected script runs in the victim's page with their session, so it can send same-origin requests the browser authenticates automatically; CSRF tokens do not stop same-origin script.
  3. CScripts cannot clear the Secure flag on an existing HttpOnly cookie; the browser controls those attributes, so downgrading cookie transport this way is not possible.
  4. DA strict Content-Security-Policy is designed to block loading scripts from unapproved domains, so this is the action the policy most reliably prevents.
T-04

You are analyzing the security of a web application and need to perform file enumeration. Which of the following tools is NOT suitable for file enumeration?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: PuTTY is an SSH and Telnet client for remote terminal sessions; it has no feature for discovering files or directories on a web server.
  2. BDirBuster discovers hidden files and directories by requesting names from wordlists, so it is suited to file enumeration; defenders spot it by bursts of 404 responses.
  3. CNikto scans web servers for known dangerous files, default content and misconfigurations, so it does perform file enumeration as part of its checks.
  4. DGobuster is a fast command-line tool for discovering directories, files and subdomains from wordlists, which makes it suitable for file enumeration.
T-05

An API experiences outages when bots scrape a specific resource-intensive endpoint. The current defense uses a load balancer to blindly drop traffic exceeding a global threshold, inadvertently blocking legitimate users. Which mitigation is BEST?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ARaising timeouts just lets more scraper requests pile up on an already expensive endpoint, worsening the outage instead of separating abusive clients from real users.
  2. BSource-network blocking still treats traffic coarsely; scrapers rotate addresses easily, while users behind shared networks or carrier NAT get caught in the same block.
  3. CCorrect: limits tied to each API key and each endpoint throttle the specific clients hammering the costly resource, leaving legitimate users and cheaper endpoints unaffected.
  4. DBlocking residential proxy ranges is incomplete and error-prone, since scrapers can use other infrastructure and many real customers browse from residential addresses.
T-06

What type of OWASP Top 10 web server attack occurs when a hacker exploits the failure to adequately validate or sanitize user input on a web application?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ABroken Access Control, first in the 2021 OWASP list, is about users acting outside their permissions, not about unvalidated input reaching an interpreter.
  2. BXSS does stem from unsanitized input, but in the 2021 OWASP list it is grouped inside the Injection category, which is the broader answer the question asks for.
  3. CCSRF abuses a victim's authenticated session to send unwanted requests; it is prevented with anti-forgery tokens and SameSite cookies, not with input sanitization.
  4. DCorrect: Injection, A03 in the 2021 OWASP Top 10 and still in the 2025 edition, covers untrusted input reaching an interpreter; validation and parameterized queries prevent it.
T-07

What type of attack involves an attacker enticing a user into clicking on a malicious link leading to unauthorized actions on a trusted site?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: cross-site request forgery makes a logged-in user's browser send an unwanted request to a trusted site; anti-CSRF tokens and SameSite cookies are the main defenses.
  2. BA man-in-the-middle attack intercepts or alters traffic between two parties; it does not depend on a user clicking a link that triggers actions on a trusted site.
  3. CPhishing may deliver the link, but it names the social-engineering lure; the attack that turns the click into unauthorized actions on the trusted site has its own name.
  4. DSQL injection manipulates database queries through crafted input; it targets the server's data layer rather than abusing a victim's authenticated browser session.
T-08

An enterprise application currently uses unsigned JSON Web Tokens (JWTs) for authorization. A developer proposes enforcing strict HTTPS as the sole mechanism to prevent users from maliciously elevating their privilege claims. Why is this mitigation insufficient?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATLS is terminated before the application processes the request, so the backend reads token contents normally; encryption in transit does not hide data from the server.
  2. BCorrect: TLS protects the token on the wire, but the user holds it and can edit unsigned claims before sending; only a server-verified signature detects such tampering.
  3. CHTTPS indeed does not stop XSS, but that is a separate weakness; the core problem here is that the server trusts claims it never verifies.
  4. DHTTPS does authenticate the server with certificates, and outsiders cannot simply forge them; the gap is the token holder altering claims, not external certificate forgery.
T-09

A malicious user has successfully compromised a web-based email service and has planted scripts that execute when other users open their email. Which attack method is MOST LIKELY responsible for this?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AA buffer overflow corrupts memory in a program to run code on that system; it does not explain scripts that run in other users' browsers when they view messages.
  2. BCorrect: this is stored XSS; script saved in message content runs in each reader's browser, and output encoding plus content sanitization and a strict CSP are the defenses.
  3. CSQL injection alters database queries and could expose or change stored data, but it is not the mechanism that makes script execute in other users' browsers.
  4. DCSRF forces a victim's browser to send requests to a site where they are logged in; it does not plant script that runs when other users open their mail.
T-10

You suspect a blind Server-Side Request Forgery vulnerability exists within a web application's image upload function. The server consistently returns identical HTTP 200 responses regardless of the provided input URL. Which approach most reliably confirms the vulnerability?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: when responses reveal nothing, out-of-band confirmation works best; a DNS lookup or callback to an external domain proves the server made the request itself.
  2. BTiming differences can hint at internal reachability, but they are noisy and easily confused with network jitter, so they confirm blind SSRF far less reliably.
  3. CVerbose errors would help if the application showed them, but the scenario says responses are identical regardless of input, so no stack trace will appear.
  4. DError codes cannot be analyzed when the server always returns the same 200 response, and probing metadata services is riskier than needed just to confirm the flaw.
T-11

John is an ethical hacker employed by TechCorp to assess their new web application's security. What is the FIRST action John should take in the web app hacking methodology?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACode review is valuable when source is available, but the methodology starts by learning what infrastructure and technologies are in place before analyzing the application itself.
  2. BCorrect: the methodology begins with footprinting the web infrastructure, identifying servers, versions, services and hidden content that shape the rest of the assessment.
  3. CAttempting to break in comes later, after footprinting and analysis show which weaknesses exist; starting here would be unplanned and risky for the client's systems.
  4. DEvading defenses is a later concern once testing is under way; it cannot be the first step because the tester does not yet know what defenses exist.
T-12

A vulnerability scan identifies a visually prominent Reflected XSS on a static marketing page and a complex blind SSRF within a cloud metadata API. How should the remediation be correctly prioritized?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ACorrect: an SSRF reaching a cloud metadata API can expose instance credentials and lead to wider infrastructure compromise, which outweighs reflected XSS on a static page.
  2. BBrand damage matters, but reflected XSS on a static marketing page has limited impact, typically no session data or sensitive functions, compared with backend compromise.
  3. CEase of exploitation is only one input; impact dominates here, and a cloud credential exposure through SSRF is far more severe than this XSS.
  4. DThe two findings do not carry identical risk simply because both are reachable from outside; risk-based remediation orders them by impact and exploitability.
T-13

What type of assessment can be conducted to identify vulnerabilities in a web application's authentication mechanism?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AUnit testing checks individual functions against expected behavior during development; it is not designed to probe an authentication mechanism the way an adversary would.
  2. BCorrect: penetration testing evaluates authentication from an attacker's perspective, looking for weak credential handling, session flaws and bypasses so they can be fixed.
  3. CSmoke testing is a quick check that a build's basic functions work at all; it does not attempt to find security weaknesses in authentication.
  4. DIntegration testing confirms that components work together correctly; it verifies functionality rather than actively seeking ways to defeat the login mechanism.
T-14

An attacker wants to identify the Content Management System (CMS) being used on a website. Which of the following tools can provide this information most efficiently?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AHydra is an online password-guessing tool for network logins; it tests credentials and does nothing to identify which CMS a site runs.
  2. BWireshark captures and analyzes network packets; it could show headers in traffic, but it is not an efficient way to fingerprint a website's CMS.
  3. CCorrect: WhatWeb fingerprints websites, identifying the CMS, server software, frameworks and plugins from headers and page content; trimming version banners reduces what it reveals.
  4. DJohn the Ripper is an offline password-hash cracker used to audit password strength; it has no role in identifying the technologies behind a website.
T-15

During an assessment, a tester intercepts a JSON Web Token, changes the header to {'alg':'none'}, removes the signature portion, and successfully accesses another account. Which flaw enabled this token forgery?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. ATransport encryption protects tokens in transit, but this tester already held the token; TLS cannot stop a client from editing a token it possesses.
  2. BPassword complexity affects how hard credentials are to guess, but no password was involved here; the account was reached by presenting an altered token.
  3. CCorrect: the server accepted an unsigned token and trusted the algorithm named in its header; validators should enforce an expected algorithm and reject 'none'.
  4. DThe JWT payload is normally encoded, not encrypted, and the issue is missing signature enforcement rather than an outdated encryption standard.
T-16

What web application security issue occurs when attackers are able to upload malicious files that can be executed on the server?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AContent spoofing tricks users by injecting misleading text or content into a trusted page, but it does not place executable files on the server.
  2. BPath disclosure leaks internal file system paths through errors or responses; it aids reconnaissance but does not let anyone store and run files.
  3. CClickjacking hides a legitimate page under a decoy so users click things unknowingly; it is a client-side UI trick, not a server-side upload flaw.
  4. DCorrect: unrestricted file upload means the server accepts files without validating type and content or storing them outside executable paths, so a planted script can run.
T-17

What type of attack involves submitting unexpected or malicious data to a web service API that expects XML?

Make the call. Every option has a note waiting here.

Notes on all 4 options
  1. AAPI hijacking is a loose term for taking over API sessions or keys; it does not specifically describe malformed input sent to an XML-based service.
  2. BCorrect: SOAP injection inserts unexpected XML elements or values into SOAP messages, and schema validation plus strict parsing on the service side are the main defenses.
  3. CService wrapping is not a standard attack name; the closely related XML signature wrapping abuses signed SOAP messages rather than general input validation flaws.
  4. DREST hooking is not an established attack term, and REST services typically exchange JSON rather than the XML envelopes the stem describes.

Module 14, asked and answered

Why are APIs, webhooks and web shells part of this module?

Blueprint v5.0 lists web APIs, webhooks and web shells as Module 14 topics (checked Oct 11, 2026). Each is a place where an application trusts too much: an API version nobody inventoried, a callback nobody verifies, a script file nobody saw arrive. Their controls follow: API inventory and gateway policy, signature checks on incoming webhook calls, file integrity monitoring on the web root.

Do I learn the 2021 or the 2025 OWASP codes?

Learn the 2021 names and codes, because the CEH v13 course outline cites that edition (checked Oct 11, 2026). Then learn the handful of moves into the 2025 list so a modern label does not throw you, and keep the API Security Top 10 2023 as its own list.

Can a scanner find business logic flaws?

Rarely. A logic flaw is a process the server never checks, such as a skipped checkout step, so the requests look normal to automated tools. Defenders treat it as a design problem: server-side workflow checks, threat modeling and manual review inside an authorized scope.

Can I practice these attacks on live websites?

Only on systems you own or have written permission to test. Use intentionally vulnerable training applications in an isolated lab; testing someone else's site without authorization is what separates an attack from an engagement, in professional practice and in law.

Sources