312-50V13 · Question #252
John, a professional hacker, targeted an organization that uses LDAP for accessing distributed directory services. He used an automated tool to anonymously query the IDAP service for sensitive…
The correct answer is A. jxplorer. Explanation JXplorer (Option A) is correct because it is an open-source, Java-based LDAP browser and editor that allows users - including attackers - to anonymously connect to and query LDAP directory services, extracting sensitive information such as usernames, addresses…
Question
Options
- Ajxplorer
- BZabasearch
- CEarthExplorer
- DIke-scan
How the community answered
(30 responses)- A87% (26)
- B7% (2)
- C3% (1)
- D3% (1)
Explanation
Explanation
JXplorer (Option A) is correct because it is an open-source, Java-based LDAP browser and editor that allows users - including attackers - to anonymously connect to and query LDAP directory services, extracting sensitive information such as usernames, addresses, departmental details, and server names without requiring authentication credentials.
Option B (Zabasearch) is a public people-search engine used for finding personal information online, not a tool for querying LDAP services. Option C (EarthExplorer) is a USGS geospatial tool used for searching satellite imagery and geographic data, completely unrelated to LDAP enumeration. Option D (Ike-scan) is a network tool specifically used for discovering and fingerprinting IPSec VPN systems, not for LDAP directory enumeration.
Memory Tip: Think of JXplorer as Java eXploring LDAP - the "X" in the name hints at its ability to extract and explore directory information, making it the go-to tool for LDAP-based attacks in CEH exam scenarios.
Topics
Community Discussion
No community discussion yet for this question.