System Exploitation & Attack Techniques Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Exploitation & Attack Techniques flashcards as text
Which vulnerability class does SQL injection primarily exploit?
Answer: Insufficient input validation allowing manipulation of database queries
SQL injection occurs when user-supplied input is not properly sanitized and gets interpreted as SQL code, allowing attackers to manipulate database queries.
In Metasploit, what is the `check` command used for before running an exploit?
Answer: To test if the target appears vulnerable without exploiting it
The `check` command probes the target to determine if it appears vulnerable to the exploit without actually attempting exploitation.
What is the purpose of encoding a payload with msfvenom's `-e` option?
Answer: To obfuscate the payload and potentially evade signature-based detection
Encoding transforms the payload bytes to evade simple signature-based antivirus detection, though modern AV can often detect common encoders.
Which post-exploitation Meterpreter command takes a screenshot of the victim's current desktop?
Answer: screenshot
The `screenshot` command in Meterpreter captures the current desktop display of the compromised system and saves it locally.
When exploiting a Linux system with a buffer overflow, which register typically needs to be controlled to redirect execution?
Answer: EIP (or RIP on 64-bit)
Controlling EIP (Instruction Pointer, or RIP on 64-bit systems) allows the attacker to redirect program execution to arbitrary code such as shellcode.
What is 'token impersonation' in Windows post-exploitation?
Answer: Using another user's access token to perform actions with their privileges
Token impersonation uses the Windows access token of another logged-in user to execute commands with that user's privileges, enabling lateral movement or privilege escalation.
Which Metasploit module category contains tools specifically designed for maintaining access after initial exploitation?
Answer: post/
The `post/` module category in Metasploit contains post-exploitation modules for tasks like persistence, credential gathering, lateral movement, and privilege escalation.