System Exploitation & Attack Techniques Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Exploitation & Attack Techniques flashcards as text
Which Meterpreter command is used to pivot through a compromised host to reach otherwise inaccessible network segments?
Answer: route add
The `route add` command in Metasploit adds routes through a Meterpreter session, enabling traffic to be sent through the compromised host to internal networks.
What is the primary purpose of the EternalBlue exploit (MS17-010)?
Answer: Exploiting a vulnerability in the SMBv1 protocol
EternalBlue exploits a critical buffer overflow vulnerability in the Windows SMBv1 protocol to achieve remote code execution.
In Metasploit, what is a 'staged' payload?
Answer: A small initial stager that downloads and executes the full payload
A staged payload uses a tiny stager (stage 0) that connects back to the attacker and downloads the larger main payload into memory.
Which command in a Meterpreter session dumps credential hashes from the Windows SAM database?
Answer: hashdump
The `hashdump` command in Meterpreter extracts NTLM password hashes from the Windows Security Account Manager (SAM) database.
What technique does process hollowing use?
Answer: Creating a legitimate process in suspended state and replacing its code with malicious code
Process hollowing spawns a legitimate process suspended, unmaps its memory, and replaces it with malicious code before resuming execution.
When exploiting a vulnerable service with Metasploit, what does setting `RHOSTS` specify?
Answer: The target host(s) to attack
RHOSTS (Remote Hosts) specifies the IP address or range of target systems the exploit module will attempt to attack.
Which Metasploit post-exploitation module searches for stored credentials and sensitive files on a Windows target?
Answer: post/windows/gather/credentials/credential_collector
The credential_collector post module searches common locations for stored credentials including browsers, email clients, and credential stores.