nerdexam
EC-Council

412-79V10 · Question #12

412-79V10 Question #12: Real Exam Question with Answer & Explanation

Sign in or unlock 412-79V10 to reveal the answer and full explanation for question #12. The question stem and answer options stay visible for context.

Question

Richard, a penetration tester was asked to assess a web application. During the assessment, he discovered a file upload field where users can upload their profile pictures. Richard tried to upload a PHP shell, but the web application restricted the upload to image files only. Richard bypassed the restriction and uploaded a malicious PHP shell, but the web page denied the file upload. Trying to get around the security, Richard added the '.jpg' extension to the end of the file. The new file name looked like 'shell.php.jpg'. Richard submitted the file and observed the '.jpg' extension from the request while uploading the file. This enabled him to successfully upload the PHP shell. Identify the exploitation technique that Richard implemented to upload the PHP shell?

Options

  • ASession stealing
  • BCookie tampering
  • CFile extension bug
  • DParameter tampering

Unlock 412-79V10 to see the answer

You've previewed enough free 412-79V10 questions. Unlock 412-79V10 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full 412-79V10 Practice