PrepAway - Latest Free Exam Questions & Answers

Category: 312-50 (CEH v6)

Exam 312-50: Ethical Hacking and Countermeasures (CEH v6)

What is the mostly likely way the attacker has been able to modify the price?

An attacker has been successfully modifying the purchase price of items purchased at a web site. The security administrators verify the web server and Oracle database have not been compromised directly. They have also verified the IDS logs and found no attacks that could have caused this. What is the mostly likely way the attacker has been able to modify the price?

How would you protect information systems from these attacks?

Take a look at the following attack on a Web Server using obstructed URL:

http://www.example.com/script.ext?template%2e%2e%2e%2e%2e%2f%2e%2f%65%74%63%2f %70%61%73%73%77%64

The request is made up of:

– %2e%2e%2f%2e%2e%2f%2e%2f% = ../../../
– %65%74%63 = etc
– %2f = /
– %70%61%73%73%77%64 = passwd

How would you protect information systems from these attacks?


Page 102 of 125« First...102030...100101102103104...110120...Last »