Filter interviews by
I applied via Recruitment Consulltant and was interviewed before Oct 2023. There were 2 interview rounds.
Top trending discussions
posted on 19 Feb 2023
I applied via Naukri.com and was interviewed in Jan 2023. There were 3 interview rounds.
Blind XSS is a type of XSS attack where the attacker does not receive the output of the injected script.
Blind XSS is also known as non-persistent XSS.
It is difficult to detect as the attacker does not receive any feedback.
One technique to find Blind XSS is to use a tool like Burp Suite to inject a payload and monitor the server response.
Another technique is to use a third-party service like XSS Hunter to track the payl...
My favorite vulnerability is SQL injection.
SQL injection is a type of attack where an attacker injects malicious SQL code into a database query.
It can be used to steal sensitive information, modify or delete data, or even take control of the entire database.
Preventing SQL injection involves using parameterized queries, input validation, and proper error handling.
Examples of high-profile SQL injection attacks include th...
CRLF stands for Carriage Return Line Feed. It is a sequence of characters used to represent a line break in text files.
CRLF consists of two ASCII control characters: CR (carriage return) and LF (line feed).
It is commonly used in HTTP headers to separate lines of text.
CRLF can be exploited by attackers to inject malicious code or perform attacks such as HTTP response splitting.
To prevent such attacks, input validation a...
There are numerous types of XSS attacks. Mitigation involves input validation and output encoding.
There are three main types of XSS attacks: stored, reflected, and DOM-based.
Mitigation involves input validation to ensure that user input is safe and output encoding to prevent malicious code from being executed.
Examples of input validation include limiting the length of input and restricting the types of characters that ...
SQLi is a type of injection attack where an attacker injects malicious SQL code into a vulnerable application to gain unauthorized access to sensitive data.
SQLi involves exploiting vulnerabilities in web applications that allow user input to be executed as SQL commands
Attackers can use SQLi to bypass authentication, access sensitive data, modify or delete data, and even take control of the entire database
Mitigation tec...
CSRF is a type of attack where a malicious website tricks a user into performing an action on a different website.
The attacker creates a website with a form that submits a request to the target website
The user visits the attacker's website and submits the form, unknowingly performing an action on the target website
The target website cannot distinguish between a legitimate request and the forged request from the attacke...
The best way to send CSRF token in client-server communication is through HTTP headers.
HTTP headers are the most secure way to send CSRF tokens.
The token should be sent in the 'X-CSRF-Token' header.
The header should be set to 'SameSite=Strict' to prevent cross-site request forgery attacks.
The token should be regenerated for each session to prevent replay attacks.
Options to take over a higher-privilege account with an existing lower-privilege account.
Use privilege escalation techniques to gain higher privileges
Exploit vulnerabilities in the system to gain access to higher-privilege accounts
Use social engineering to obtain login credentials for higher-privilege accounts
Use brute-force attacks to crack passwords for higher-privilege accounts
XSS or Cross-Site Scripting is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Reflected XSS: The attacker injects a script that is reflected back to the user through a search query or form input.
Stored XSS: The attacker injects a script that is stored on the server and executed whenever the user visits the affected page.
DOM-based XSS: The attacker...
posted on 11 Aug 2021
I applied via Referral and was interviewed in Jul 2021. There was 1 interview round.
An IP address is a unique numerical identifier assigned to every device connected to the internet.
IP stands for Internet Protocol
It consists of four sets of numbers separated by dots
There are two types of IP addresses: IPv4 and IPv6
IPv4 addresses are 32-bit numbers and IPv6 addresses are 128-bit numbers
Examples of IP addresses are 192.168.1.1 and 2001:0db8:85a3:0000:0000:8a2e:0370:7334
File sharing can be done through various methods.
One can use cloud storage services like Google Drive, Dropbox, etc.
File transfer protocols like FTP, SFTP, etc. can be used.
Peer-to-peer file sharing can be done through applications like BitTorrent.
File sharing can also be done through network file sharing services like SMB, NFS, etc.
IP addresses can be assigned manually or automatically using DHCP.
To assign an IP address manually, go to network settings and enter the IP address, subnet mask, default gateway, and DNS server.
To assign an IP address automatically, enable DHCP on the network and the device will receive an IP address from the DHCP server.
IP addresses can also be assigned using command line tools such as ipconfig or ifconfig.
Creating a bootable drive involves formatting the drive and copying the operating system files onto it.
Insert a USB drive or DVD into the computer
Format the drive using a tool like Rufus or Disk Utility
Copy the operating system files onto the drive
Set the computer to boot from the drive in BIOS or UEFI settings
A switch is a networking device that connects devices together on a local area network (LAN) and forwards data packets between them.
Switches operate at the data link layer of the OSI model.
They use MAC addresses to forward data to the correct destination device.
Switches can improve network performance by reducing network congestion and collisions.
Examples of switches include Cisco Catalyst switches and Netgear ProSAFE
To configure a router, access its web interface and enter the necessary settings.
Connect to the router's network
Open a web browser and enter the router's IP address
Enter the login credentials
Navigate to the settings page and configure as needed
Save the changes and restart the router if necessary
posted on 16 Sep 2021
I applied via Referral and was interviewed in Aug 2021. There was 1 interview round.
based on 1 review
Rating in categories
Technical Resource Specialist
26
salaries
| ₹2.6 L/yr - ₹4.5 L/yr |
Business Development Manager
22
salaries
| ₹2.8 L/yr - ₹7.2 L/yr |
Senior Software Engineer
19
salaries
| ₹4.2 L/yr - ₹13.2 L/yr |
Software Engineer
19
salaries
| ₹4.7 L/yr - ₹15.3 L/yr |
Graphic Designer
17
salaries
| ₹2.9 L/yr - ₹4.8 L/yr |
TCS
Infosys
Wipro
HCLTech