System Exploitation & Attack Techniques Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Exploitation & Attack Techniques flashcards as text
Which Metasploit command upgrades a standard shell session to a Meterpreter session?
Answer: sessions -u
The `sessions -u ` command in Metasploit automatically upgrades a command shell to a Meterpreter session.
When exploiting a buffer overflow, what is the purpose of a NOP sled?
Answer: To provide a landing zone so execution slides into the shellcode
A NOP sled is a sequence of NOP instructions that allows imprecise jumps to still reach and execute the shellcode.
Which tool is used within Metasploit to generate custom shellcode payloads?
Answer: msfvenom
msfvenom combines payload generation and encoding, replacing the older msfpayload and msfencode tools.
In a pass-the-hash attack, what credential material is used to authenticate without knowing the plaintext password?
Answer: NTLM hash
Pass-the-hash exploits Windows NTLM authentication by using the captured NTLM hash directly, bypassing the need for the plaintext password.
What does the Metasploit `getsystem` command attempt to do?
Answer: Escalate privileges to SYSTEM level
The `getsystem` command in Meterpreter attempts multiple privilege escalation techniques to obtain SYSTEM-level access.
Which attack technique involves injecting malicious DLLs into a running process to execute code in its context?
Answer: DLL injection
DLL injection forces a running process to load a malicious DLL, allowing code execution within that process's security context.
When using Metasploit's `exploit/multi/handler`, what must match between the handler and the payload delivered to the target?
Answer: The payload type and connection parameters
The handler's payload type and all connection parameters (LHOST, LPORT, payload name) must exactly match what was delivered to the target.