CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 28: ECSAV10: EC-Council Certified Security Analyst

Richard, a penetration tester was asked to assess a web application. During the assessment, he discovered a file upload field where users can upload their profile pictures. While scanning the page for vulnerabilities, Richard found a file upload exploit on the website. Richard wants to test the web application by uplo…

Nội dung câu hỏi

Richard, a penetration tester was asked to assess a web application. During the assessment, he discovered a file upload field where users can upload their profile pictures. While scanning the page for vulnerabilities, Richard found a file upload exploit on the website. Richard wants to test the web application by uploading a malicious PHP shell, but the web page denied the file upload. Trying to get around the security, Richard added the `˜jpg' extension to the end of the file. The new[1]successfully upload the PHP shell. Which of the following techniques has Richard implemented to upload the PHP shell?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Session stealing
  2. B. Cookie tampering
  3. C. Cross site scripting
  4. D. Parameter tampering — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề