โ† All EJPT Flashcard Decks

System Exploitation & Attack Techniques Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 System Exploitation & Attack Techniques flashcards as text
  1. Which Meterpreter command is used to pivot through a compromised host to reach otherwise inaccessible network segments?

    Answer: route add

    The `route add` command in Metasploit adds routes through a Meterpreter session, enabling traffic to be sent through the compromised host to internal networks.

  2. What is the primary purpose of the EternalBlue exploit (MS17-010)?

    Answer: Exploiting a vulnerability in the SMBv1 protocol

    EternalBlue exploits a critical buffer overflow vulnerability in the Windows SMBv1 protocol to achieve remote code execution.

  3. In Metasploit, what is a 'staged' payload?

    Answer: A small initial stager that downloads and executes the full payload

    A staged payload uses a tiny stager (stage 0) that connects back to the attacker and downloads the larger main payload into memory.

  4. Which command in a Meterpreter session dumps credential hashes from the Windows SAM database?

    Answer: hashdump

    The `hashdump` command in Meterpreter extracts NTLM password hashes from the Windows Security Account Manager (SAM) database.

  5. What technique does process hollowing use?

    Answer: Creating a legitimate process in suspended state and replacing its code with malicious code

    Process hollowing spawns a legitimate process suspended, unmaps its memory, and replaces it with malicious code before resuming execution.

  6. When exploiting a vulnerable service with Metasploit, what does setting `RHOSTS` specify?

    Answer: The target host(s) to attack

    RHOSTS (Remote Hosts) specifies the IP address or range of target systems the exploit module will attempt to attack.

  7. Which Metasploit post-exploitation module searches for stored credentials and sensitive files on a Windows target?

    Answer: post/windows/gather/credentials/credential_collector

    The credential_collector post module searches common locations for stored credentials including browsers, email clients, and credential stores.