Click the exhibit button. Given the Nikto vulnerability, scan output shown in the exhibit, which of the following exploitation techniques might be used to exploit the target system? (Choose two.)
A. and B. - According to Wikipedia, XST can be used to get cookies. Cookies can be exploited in session hijacking. "XST scripts exploit ActiveX, Flash, or any other controls that allow executing an HTTP TRACE request. The HTTP TRACE response includes all the HTTP headers, including authentication data and HTTP cookie contents, which are then available to the script. In combination with cross-domain access flaws in web browsers, the exploit can collect the cached credentials of any website, including those utilizing SSL.
- https://en.wikipedia.org/wiki/Cross-site_tracing
Cross-Site Tracing (XST):
- https://owasp.org/www-community/attacks/Cross_Site_Tracing
- https://capec.mitre.org/data/definitions/107.html
Arbitrary code execution:
- https://www.kb.cert.org/vuls/id/520827/
Answer is BD,because:
A. Arbitrary code execution ---> OSVDB-:/dvwa/?-s
B. Session hijacking ---> OSVDB-877 OSVDB-12184
C. SQL injection ---> OSVDB-:/dvwa/?-s
D. Login credential brute-forcing ---> many OSVDB (dictionary and login page)
E. Cross-site request forgery ---> OSVDB-:/dvwa/?-s
I don't see anything that indicates session hijacking, brute force I can see since there is a login page but I'd say the next one would be code execution since it appears the php source code can be viewed which "may allow command execution"
D due to the admin login page
Example:
https://securitytutorials.co.uk/brute-forcing-web-logins-with-dvwa/
upvoted 2 times
...
...
...
This section is not available anymore. Please use the main Exam Page.PT0-001 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
miabe
2 years, 10 months agoCock
3 years, 2 months agoSciBer
3 years, 6 months agoAriel235788
3 years, 4 months agoversun
3 years, 10 months agohellobob
3 years, 11 months agodyers
3 years, 12 months agoCapCrunch
3 years, 10 months agoCapCrunch
3 years, 10 months ago