CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 217: GCIH: GIAC Certified Incident Handler

John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. He performs Web vulnerability scanning on the We-are-secure server. The output of the scanning test is as follows:C:\whisker.pl -h target_IP_address-- whisker / v1.4.0 / rain forest puppy / www.wi…

Nội dung câu hỏi

John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. He performs Web vulnerability scanning on the We-are-secure server. The output of the scanning test is as follows:C:\whisker.pl -h target_IP_address-- whisker / v1.4.0 / rain forest puppy / www.wiretrip.net -- = - = - = - = - == Host: target_IP_address= Server: Apache/1.3.12 (Win32) ApacheJServ/1.1mod_ssl/2.6.4 OpenSSL/0.9.5a mod_perl/1.22+ 200 OK: HEAD /cgi-bin/printenvJohn recognizes /cgi-bin/printenv vulnerability ('Printenv' vulnerability) in the We_are_secure server. Which of the following statements about 'Printenv' vulnerability are true?Each correct answer represents a complete solution. (Choose all that apply.)

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. This vulnerability helps in a cross site scripting attack. — đáp án hiện tại
  2. B. 'Printenv' vulnerability maintains a log file of user activities on the Website, which may be useful for the attacker.
  3. C. The countermeasure to 'printenv' vulnerability is to remove the CGI script. — đáp án hiện tại
  4. D. With the help of 'printenv' vulnerability, an attacker can input specially crafted links and/or other malicious scripts. — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề