← All EJPT Flashcard Decks

Attacks and Exploits Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Attacks and Exploits flashcards as text
  1. What is a 'null session' attack against Windows SMB?

    Answer: An unauthenticated connection to IPC$ share used to enumerate network info

    A null session connects to the IPC$ share without credentials, historically allowing enumeration of users, groups, and shares on older Windows systems.

  2. In web application testing, what does CSRF (Cross-Site Request Forgery) force a victim to do?

    Answer: Execute unwanted actions on a site where they are already authenticated

    CSRF tricks authenticated users into unknowingly submitting forged requests to a web application, performing actions like changing passwords or transferring funds.

  3. Which Meterpreter command captures screenshots of the victim's desktop?

    Answer: screenshot

    The `screenshot` command in Meterpreter captures the current state of the victim's desktop and saves it locally for the attacker.

  4. What is 'pass-the-hash' in Windows environments?

    Answer: Authenticating using the NTLM hash directly without knowing the plaintext password

    Pass-the-hash uses a captured NTLM hash directly for authentication in Windows, bypassing the need to crack it to plaintext first.

  5. Which tool is commonly used in eJPT labs to intercept and modify HTTP/HTTPS traffic from a web browser?

    Answer: Burp Suite

    Burp Suite acts as an intercepting proxy between the browser and web server, allowing testers to capture, inspect, and modify HTTP/HTTPS requests and responses.

  6. What is the goal of a 'brute-force' attack on an SSH service?

    Answer: To systematically try every possible username/password combination until successful

    A brute-force attack against SSH exhaustively tries all combinations of credentials until it finds a valid username and password pair.

  7. When exploiting a vulnerable web application with SQL injection, what does the UNION keyword allow an attacker to do?

    Answer: Combine results from a malicious SELECT with the original query's results

    UNION-based SQL injection appends an attacker-controlled SELECT statement to the original query, allowing retrieval of data from other tables in the database.