โ† All EJPT Flashcard Decks

Attacks and Exploits Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Attacks and Exploits flashcards as text
  1. Which protocol is most commonly exploited by the EternalBlue vulnerability (MS17-010)?

    Answer: SMB

    EternalBlue exploits a buffer overflow vulnerability in Microsoft's SMBv1 protocol, enabling unauthenticated remote code execution.

  2. What is the purpose of the `john` tool in a penetration test?

    Answer: Password hash cracking

    John the Ripper is a password cracking tool that uses dictionary, brute-force, and rule-based attacks against hashed passwords.

  3. In a dictionary attack against a login form, what is the attacker using as input?

    Answer: A precompiled list of common passwords/words

    A dictionary attack uses a wordlist of likely passwords (common words, phrases, known breached passwords) rather than pure random guessing.

  4. Which Metasploit payload format is completely self-contained with no external stager needed?

    Answer: Stageless payload (windows/meterpreter_reverse_tcp)

    Stageless payloads (with underscore before the payload name) include the full Meterpreter embedded in the shellcode without needing a separate stager.

  5. What is 'fuzzing' in the context of vulnerability research?

    Answer: Sending large volumes of random/malformed data to discover crashes

    Fuzzing sends unexpected, malformed, or random input to an application to trigger crashes, memory corruption, or other vulnerabilities.

  6. Which technique does Hydra use to test credentials against network services?

    Answer: Online brute-force / dictionary attacks

    Hydra performs online brute-force and dictionary attacks by directly attempting credential combinations against live network services like SSH, FTP, HTTP.

  7. What is the main risk of leaving SMBv1 enabled on a network according to eJPT objectives?

    Answer: It is vulnerable to critical exploits like EternalBlue allowing remote code execution

    SMBv1 contains multiple critical vulnerabilities including MS17-010 (EternalBlue) that allow unauthenticated attackers to execute code remotely.