Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 312-39 Topic 7 Question 72 Discussion

Actual exam question for Eccouncil's 312-39 exam
Question #: 72
Topic #: 7
[All 312-39 Questions]

Identify the attack when an attacker by several trial and error can read the contents of a password file present in the restricted etc folder just by manipulating the URL in the browser as shown:

http://www.terabytes.com/process.php./../../../../etc/passwd

Show Suggested Answer Hide Answer
Suggested Answer: A


Contribute your Thoughts:

Cortney
3 months ago
Wait, wait, wait... Is the attacker trying to find the password to the vending machine in the break room? Clearly a Form Tampering Attack!
upvoted 0 times
Aron
1 months ago
Exactly, by manipulating the URL to access sensitive files like password files.
upvoted 0 times
...
Linwood
1 months ago
Oh, I see. So the attacker is trying to access files outside of the web root directory.
upvoted 0 times
...
Aliza
1 months ago
No, it's actually a Directory Traversal Attack.
upvoted 0 times
...
...
Clarence
3 months ago
Haha, Denial-of-Service Attack? Really? That's like using a bazooka to swat a fly. This is clearly a Directory Traversal Attack.
upvoted 0 times
Earleen
2 months ago
B) SQL Injection Attack
upvoted 0 times
...
Annmarie
2 months ago
I agree, it's definitely a Directory Traversal Attack.
upvoted 0 times
...
Natalya
2 months ago
A) Directory Traversal Attack
upvoted 0 times
...
...
Rosio
3 months ago
Come on, this is way too obvious. It's definitely a Directory Traversal Attack. The attacker is just climbing up the directory tree to reach the sensitive /etc/passwd file.
upvoted 0 times
Mitzie
1 months ago
That's a common vulnerability that attackers exploit.
upvoted 0 times
...
Mitzie
1 months ago
Yeah, the attacker is manipulating the URL to access the password file.
upvoted 0 times
...
Mitzie
1 months ago
I agree, it's a Directory Traversal Attack.
upvoted 0 times
...
Valentin
1 months ago
It's important to secure file paths to prevent such attacks.
upvoted 0 times
...
Valentin
2 months ago
Yeah, the attacker is exploiting the vulnerability to access the password file.
upvoted 0 times
...
Valentin
2 months ago
I agree, it's a Directory Traversal Attack.
upvoted 0 times
...
...
Deeanna
3 months ago
Hmm, I'm not sure. Could it be a SQL Injection Attack? Manipulating the URL to access the password file seems like a database-related issue.
upvoted 0 times
...
Shaun
3 months ago
I think this is clearly a Directory Traversal Attack. The URL manipulation allows the attacker to access restricted files outside the web root.
upvoted 0 times
...
Ceola
3 months ago
I agree with both of you, it's definitely a Directory Traversal Attack.
upvoted 0 times
...
Una
3 months ago
I think it's A too, because the URL manipulation allows the attacker to access files outside the web root directory.
upvoted 0 times
...
Cyndy
4 months ago
A) Directory Traversal Attack
upvoted 0 times
...

Save Cancel