CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 44: ECSAV10: EC-Council Certified Security Analyst

George, a freelance Security Auditor and Penetration Tester, was working on a pen testing assignment for Xsecurity. George is an ESCA certified professional and was following the LPT methodology in performing a comprehensive security assessment of the company. After the initial reconnaissance, scanning and enumeration…

Nội dung câu hỏi

George, a freelance Security Auditor and Penetration Tester, was working on a pen testing assignment for Xsecurity. George is an ESCA certified professional and was following the LPT methodology in performing a comprehensive security assessment of the company. After the initial reconnaissance, scanning and enumeration phases, he successfully recovered a user password and was able to log on to a Linux machine located on the network. He was also able to access the /etc/passwd file; however, the passwords were stored as a single `x` character. What will George do to recover the actual encrypted passwords?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. George will perform sniffing to capture the actual passwords
  2. B. George will perform replay attack to collect the actual passwords
  3. C. George will escalate his privilege to root level and look for /etc/shadow file — đáp án hiện tại
  4. D. George will perform a password attack using the pre-computed hashes also known as a rainbow attack

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề