If you find the 111/TCP port open on a Unix system, what is the next logical step to take?
Port 111/TCP is the default port for the RPC (Remote Procedure Call) portmapper service on Unix systems, which registers and manages RPC services.
Why A is correct: Running rpcinfo -p <hostname> queries the portmapper to list all registered RPC services, their programs, versions, and associated ports. This is a logical next step during a security audit or penetration test to identify potential vulnerabilities (e.g., NFS or NIS services). CNSP recommends this command for RPC enumeration.
Why other options are incorrect:
B . Telnet to the port to look for a banner: Telnet might connect, but RPC services don't typically provide a human-readable banner, making this less effective than rpcinfo.
C . Telnet to the port, send 'GET / HTTP/1.0' and gather information from the response: Port 111 is not an HTTP service, so an HTTP request is irrelevant and will likely fail.
D . None of the above: Incorrect, as A is a valid and recommended step.
Sherron
7 months agoDesiree
7 months agoRasheeda
7 months agoBernardo
7 months agoMona
8 months agoYuonne
8 months agoRikki
8 months agoHildegarde
8 months agoKris
8 months agoHubert
9 months agoMarquetta
9 months agoShanda
9 months agoAmalia
9 months agoMertie
11 months agoElli
10 months agoThersa
11 months agoErick
10 months agoElroy
11 months ago