QuestionQ592

Exploiting Insecure Web Application References

A widely used forum where ICS professionals discuss techniques loads scripts and advertisements from several external sites. How could an adversary use this forum to compromise targets in the ICS industry?

  • A Watering-hole
  • B SQL injection
  • C Denial of Service
  • D typo-squatting
Explanation

A watering-hole attack targets a community by compromising, or delivering malicious content through, a website that its members routinely visit. Third-party scripts or advertisements on an ICS-focused forum can provide a path to expose its industry visitors to malicious code.

Community Discussion

No comments yet. Be the first to start the discussion!