Web › Module 5 › Lesson 5
Quiz — Injection
10 APPLY on A05: SQLi, XSS, families, demo http://192.168.0.1/ ethics.
Opening
Injection — Module Quiz
Ten APPLY items on OWASP Top 10:2025 A05: SQL concatenation vs parameterized queries, XSS as browser-origin injection with encoding/CSP, other families (command, LDAP, template, header/log), local bind+escape lab under $HOME/cyberlium-lab chmod 600.
Knowledge Check
APPLY: sku glued into SQL with +. Mechanism and THE fix?
Multiple choice
Knowledge Check
APPLY: True or False: Client-side filtering fully remediates SQLi.
True or False
Knowledge Check
APPLY: Untrusted HTML written via innerHTML — what is it?
Multiple choice
Knowledge Check
APPLY: True or False: BeEF cookie-steal kits are required Cyberlium XSS homework.
True or False
Knowledge Check
APPLY: Name reflected vs stored XSS at literacy level.
Multiple choice
Knowledge Check
APPLY: User string passed to bash -c — family and habit?
Multiple choice
Knowledge Check
APPLY: True or False: SSTI kits against random sites are in-scope for this module.
True or False
Knowledge Check
APPLY: curl http://192.168.0.1/ shows a TP-Link/Netgear “Router Admin” login. What do you do?
Multiple choice
Knowledge Check
APPLY: ORM uses an f-string to build SQL. Still injection risk?
Multiple choice
Knowledge Check
APPLY: You finish A05. What opens next?
Multiple choice
Answer all 10 knowledge checks to continue. (0/10 answered)