Question 861
Security administrator John Smith has noticed abnormal amounts of traffic coming from local computers at night. Upon reviewing, he finds that user data have been exfiltrated by an attacker.
AV tools are unable to find any malicious software, and the IDS/IPS has not reported on any non- whitelisted programs. What type of malware did the attacker use to bypass the company's application whitelisting?
AV tools are unable to find any malicious software, and the IDS/IPS has not reported on any non- whitelisted programs. What type of malware did the attacker use to bypass the company's application whitelisting?
Question 862
During a red team exercise, a Certified Ethical Hacker (CEH) is attempting to exploit a potential vulnerability in a target organization's web server. The CEH has completed the information gathering and footprinting phases and has mirrored the website for offline analysis. It has also been discovered that the server is vulnerable to session hijacking. Which of the following steps is most likely to be part of a successful attack methodology while minimizing the possibility of detection?
Question 863
A penetration tester suspects that a web application's login form is vulnerable to SQL injection due to improper sanitization of user input. What is the most appropriate approach to test for SQL injection in the login form?
Question 864
What would be the fastest way to perform content enumeration on a given web server by using the Gobuster tool?
Question 865
What is GINA?
