Attacks and Exploits Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Attacks and Exploits flashcards as text
What is a 'null session' attack against Windows SMB?
Answer: An unauthenticated connection to IPC$ share used to enumerate network info
A null session connects to the IPC$ share without credentials, historically allowing enumeration of users, groups, and shares on older Windows systems.
In web application testing, what does CSRF (Cross-Site Request Forgery) force a victim to do?
Answer: Execute unwanted actions on a site where they are already authenticated
CSRF tricks authenticated users into unknowingly submitting forged requests to a web application, performing actions like changing passwords or transferring funds.
Which Meterpreter command captures screenshots of the victim's desktop?
Answer: screenshot
The `screenshot` command in Meterpreter captures the current state of the victim's desktop and saves it locally for the attacker.
What is 'pass-the-hash' in Windows environments?
Answer: Authenticating using the NTLM hash directly without knowing the plaintext password
Pass-the-hash uses a captured NTLM hash directly for authentication in Windows, bypassing the need to crack it to plaintext first.
Which tool is commonly used in eJPT labs to intercept and modify HTTP/HTTPS traffic from a web browser?
Answer: Burp Suite
Burp Suite acts as an intercepting proxy between the browser and web server, allowing testers to capture, inspect, and modify HTTP/HTTPS requests and responses.
What is the goal of a 'brute-force' attack on an SSH service?
Answer: To systematically try every possible username/password combination until successful
A brute-force attack against SSH exhaustively tries all combinations of credentials until it finds a valid username and password pair.
When exploiting a vulnerable web application with SQL injection, what does the UNION keyword allow an attacker to do?
Answer: Combine results from a malicious SELECT with the original query's results
UNION-based SQL injection appends an attacker-controlled SELECT statement to the original query, allowing retrieval of data from other tables in the database.