nerdexam
EC-Council

412-79V10 · Question #30

Peter, a freelance Security Auditor and Penetration Tester, was working on a pen testing assignment for Xsecurity. George is an ESCA certified professional and was following the LPT methodology in…

The correct answer is C. George will perform an exchange to retrieve hash look-up in shadow file. See the full explanation below for the reasoning.

Question

Peter, a freelance Security Auditor and Penetration Tester, was working on a pen testing assignment for Xsecurity. George is an ESCA certified professional and was following the LPT methodology in performing a comprehensive security assessment of the company. After the initial reconnaissance, scanning and enumeration of the target, he targeted a Windows machine that had the following information stored on it: the retc/passwd file and the retc/shadow file. Peter discovered that the retc/passwd file contained multiple usernames but one of the passwords was stored as a single "*" character. What should George perform to retrieve the actual passwords?

Options

  • AGeorge will perform sniffing to capture the actual passwords
  • BGeorge will perform replay attack to collect the actual passwords
  • CGeorge will perform an exchange to retrieve hash look-up in shadow file
  • DGeorge will perform a password attack using the pre-computed hashes also known as a rainbow attack

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    86% (25)
  • D
    3% (1)

Community Discussion

No community discussion yet for this question.

Full 412-79V10 Practice