A security analyst has uncovered a suspicious request in the logs for a web application. Given the following URL: http:www.company-site.com/about.php?i=_V_V_V_V_VetcVpasswd Which of the following attack types is MOST likely to be the vulnerability?
Maybe: A. Directory traversal ?
I don't think those are supposed to be "V"s but rather forward slash next to a back slash: \/ not V. Take a look at examtopic question 114.
Agree with you. This is taken from PenTest+ Practice Tests Book:
http://www.companysite.com/about.php?i=../../../etc/passwd
In this scenario, the .. operators are the revealing giveaway that the attacker was attempting to conduct a directory traversal attack. This particular attack sought to break out of the web server’s root directory and access the /etc/passwd file on the server. A directory traversal attack is an HTTP attack that allows attackers to access restricted directories and execute commands outside of the web server’s root directory.
Answer is B Cross-site scripting (XSS) is a type of security vulnerability typically found in web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy. Cross-site scripting, commonly referred to as XSS, occurs when hackers execute malicious JavaScript within a victim’s browser. What can directory traversal do to a server?
An attacker may use directory traversal to download server configuration files, which contain sensitive information and potentially expose more server vulnerabilities. Ultimately, the attacker may access confidential information or even get full control of the server.
They are clearly going after the passwd file is what, but you go ahead and do B and I'll do A
upvoted 8 times
...
...
This section is not available anymore. Please use the main Exam Page.PT0-001 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
boblee
Highly Voted 4Â years, 10Â months agoD1960
Highly Voted 5Â years, 2Â months agomr_robot
5Â years, 1Â month agonadarajabs
3Â years, 8Â months agomiabe
Most Recent 2Â years, 10Â months agoCock
3Â years, 2Â months agoDohJayVeh
3Â years, 5Â months agorunagerj
3Â years, 7Â months agomar7865p123
4Â years agoade2901296
4Â years agox0hmei
3Â years, 11Â months ago