โ† All EJPT Flashcard Decks

Attacks and Exploits Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Attacks and Exploits flashcards as text
  1. Which tool is commonly used to perform a man-in-the-middle attack on a local network by poisoning ARP tables?

    Answer: Arpspoof / ettercap

    Tools like arpspoof (from dsniff) and ettercap are specifically designed to poison ARP caches and perform MITM attacks on LAN segments.

  2. What is a cross-site scripting (XSS) attack primarily used to steal?

    Answer: Session cookies

    XSS attacks inject malicious scripts into web pages viewed by other users, most commonly to steal session cookies and hijack authenticated sessions.

  3. In the context of eJPT, what does 'pivoting' refer to?

    Answer: Using a compromised host to attack other systems on internal networks

    Pivoting uses a compromised machine as a relay to reach and attack systems on network segments that are not directly accessible to the attacker.

  4. Which Nmap script category is most useful for detecting known vulnerabilities on open services?

    Answer: vuln

    The `vuln` NSE script category includes scripts that check for specific known vulnerabilities on detected services.

  5. What is the Metasploit command to set up a listener that catches reverse shell connections?

    Answer: use exploit/multi/handler

    `exploit/multi/handler` is the generic Metasploit listener used to catch incoming connections from reverse shell payloads.

  6. Which type of XSS attack stores the malicious script on the server and executes it for every visitor?

    Answer: Stored (Persistent) XSS

    Stored XSS saves the malicious payload in the server's database and delivers it to every user who views the affected page.

  7. What does the Metasploit `sessions -i ` command do?

    Answer: Interacts with (connects to) an existing session

    `sessions -i ` interacts with an existing Meterpreter or shell session, bringing it to the foreground for command input.