System Exploitation & Attack Techniques Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Exploitation & Attack Techniques flashcards as text
What is the primary risk of running exploits against production systems during a penetration test?
Answer: It can cause system crashes or data corruption
Exploits, especially those targeting memory corruption vulnerabilities, can crash services or corrupt data, causing unintended denial of service on production systems.
Which type of shell binding method has the target machine connect outward to the attacker (useful for bypassing inbound firewall rules)?
Answer: Reverse shell
A reverse shell has the victim initiate an outbound connection to the attacker's listener, bypassing inbound firewall rules that block incoming connections.
What does the Metasploit option `PAYLOAD` set?
Answer: The code to execute on the target after successful exploitation
The PAYLOAD option specifies what code will be executed on the target system after the exploit successfully gains code execution.
In the context of eJPT, which command-line tool is commonly used for transferring files to/from a Windows target when a Meterpreter session is unavailable?
Answer: certutil
Certutil.exe is a native Windows tool often abused to download files from the internet, making it useful for file transfer when no other agent is present.
What is 'living off the land' in the context of post-exploitation?
Answer: Using built-in OS tools and features to avoid dropping new malware
Living off the land means using legitimate, pre-installed OS utilities (like PowerShell, certutil, wmic) for malicious purposes to blend in and avoid detection.
Which Meterpreter command allows an attacker to record keystrokes on a compromised Windows system?
Answer: keyscan_start
The `keyscan_start` command begins Meterpreter's keylogger, which captures keystrokes that can later be retrieved with `keyscan_dump`.
When using msfvenom, what flag specifies the output format of the generated payload?
Answer: -f
The `-f` flag in msfvenom specifies the output format (e.g., exe, elf, raw, python, powershell) for the generated payload.