Courseiva
Web Application Attacks →mediumMultiple Choice

PEN-200 Web Application Attacks Practice Question

During an authorized penetration test of a PHP e-commerce site, you discover that the 'remember me' cookie is created with the following code: setcookie('auth', base64_encode($user_id . ':' . $role), time()+2592000); The cookie value is 'MTIzNDp1c2Vy'. You decode it to '123:user'. The application trusts this cookie for authentication on subsequent requests. What is the MOST direct way to escalate privileges to administrator?

⚠ Common exam trap

The trap here is assuming that base64 encoding provides security or that the cookie is a random session token, when it is actually a predictable, reversible encoding of authorization data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the cookie value to base64_encode('123:admin') and set it in your browser.

The cookie contains base64-encoded user ID and role with no signature or encryption. Decoding reveals the format, allowing an attacker to change the role to 'admin' and re-encode. The application trusts the cookie for authorization, so this directly escalates privileges. Other methods like SQL injection or CSRF are not indicated by the scenario and would not be as straightforward.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Brute-force the base64-encoded cookie to discover the administrator's session identifier.

    Why it's wrong here

    Brute-forcing is unnecessary because the cookie is not a random session ID; it is a predictable encoding of user ID and role. Decoding it immediately reveals the structure. Brute-force would be inefficient and unlikely to succeed without knowing the format, which is already known from the source code.

  • ✗

    Use SQL injection on the login form to extract the administrator password hash.

    Why it's wrong here

    While SQL injection is a common web attack, the scenario does not indicate a SQL injection vulnerability. The cookie is already decoded and shows a predictable structure. Attempting SQL injection would be a detour and may not be possible if input is properly sanitized. The direct path is cookie manipulation.

  • ✗

    Perform a cross-site request forgery (CSRF) attack to change the administrator's password.

    Why it's wrong here

    CSRF requires the victim to be authenticated and to visit a malicious page. Here, you are the attacker and already have a valid session cookie. CSRF would not help you escalate your own privileges because it targets another user's session. The vulnerability lies in the cookie's lack of integrity protection, not in CSRF.

  • ✓

    Modify the cookie value to base64_encode('123:admin') and set it in your browser.

    Why this is correct

    The cookie stores user ID and role in plaintext after base64 decoding. By changing the role to 'admin' and re-encoding, you forge a valid cookie. The server does not verify integrity, so it accepts the tampered value, granting administrative access. This is a classic insecure direct object reference combined with cookie tampering.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.