Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GAQM CPEH-001 Exam - Topic 2 Question 131 Discussion

The following excerpt is taken from a honeypot log that was hosted at lab.wiretrip.net. Snort reported Unicode attacks from 213.116.251.162. The file Permission Canonicalization vulnerability (UNICODE attack) allows scripts to be run in arbitrary folders that do not normally have the right to run scripts. The attacker tries a Unicode attack and eventually succeeds in displaying boot.ini.He then switches to playing with RDS, via msadcs.dll. The RDS vulnerability allows a malicious user to construct SQL statements that will execute shell commands (such as CMD.EXE) on the IIS server. He does a quick query to discover that the directory exists, and a query to msadcs.dll shows that it is functioning correctly. The attacker makes a RDS query which results in the commands run as shown below:What can you infer from the exploit given?
C) The attack is a remote exploit and the hacker downloads three files.
A) It is a local exploit where the attacker logs in using username johna2k.
B) There are two attackers on the system -- johna2k and haxedj00.
D) The attacker is unsuccessful in spawning a shell as he has specified a high end UDP port.

GAQM CPEH-001 Exam - Topic 2 Question 131 Discussion

Actual exam question for GAQM's CPEH-001 exam
Question #: 131
Topic #: 2
[All CPEH-001 Questions]

The following excerpt is taken from a honeypot log that was hosted at lab.wiretrip.net. Snort reported Unicode attacks from 213.116.251.162. The file Permission Canonicalization vulnerability (UNICODE attack) allows scripts to be run in arbitrary folders that do not normally have the right to run scripts. The attacker tries a Unicode attack and eventually succeeds in displaying boot.ini.

He then switches to playing with RDS, via msadcs.dll. The RDS vulnerability allows a malicious user to construct SQL statements that will execute shell commands (such as CMD.EXE) on the IIS server. He does a quick query to discover that the directory exists, and a query to msadcs.dll shows that it is functioning correctly. The attacker makes a RDS query which results in the commands run as shown below:

What can you infer from the exploit given?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Annamaria
3 days ago
This question is tricky.
upvoted 0 times
...
Ailene
9 days ago
I thought RDS vulnerabilities were patched ages ago!
upvoted 0 times
...
Kaycee
14 days ago
High end UDP port doesn't mean failure, could be a red herring.
upvoted 0 times
...
Paris
19 days ago
Wait, are we sure he didn't succeed in spawning a shell?
upvoted 0 times
...
Monte
24 days ago
Definitely two attackers involved, johna2k and haxedj00.
upvoted 0 times
...
Lorean
29 days ago
Looks like a remote exploit to me.
upvoted 0 times
...
Silvana
1 month ago
I think option D is unlikely because high UDP ports are often used for other purposes, but I’m not completely sure how that affects shell spawning.
upvoted 0 times
...
Lyndia
1 month ago
I feel like the mention of RDS and SQL commands suggests a remote exploit, but I can't recall if the attacker actually downloaded files.
upvoted 0 times
...
Buddy
1 month ago
This kind of scenario reminds me of practice questions where we had to identify multiple attackers. I think option B could be a possibility.
upvoted 0 times
...
Jordan
2 months ago
I remember discussing how Unicode attacks can lead to unauthorized access, but I'm not sure if this is a local or remote exploit.
upvoted 0 times
...

Save Cancel