nerdexam
EC-Council

412-79V10 · Question #313

Joseph, a penetration tester, was asked to test a web application. During the assessment, he discovered a file upload field where users can upload their profile pictures. Joseph successfully…

The correct answer is C. Extension spoofing. See the full explanation below for the reasoning.

Question

Joseph, a penetration tester, was asked to test a web application. During the assessment, he discovered a file upload field where users can upload their profile pictures. Joseph successfully uploaded a malicious PHP shell by exploiting a vulnerability in the application. However, when he tried to execute the malicious PHP shell, but the web page denied the file upload. Trying to get around the security, Richard added the .jpg extension to the end of the file. The new file then successfully uploaded, but it did not execute either. Richard removed the .jpg extension from the request while uploading the file. This enabled him to successfully upload the PHP shell. Which of the following techniques has Richard implemented to upload the PHP shell?

Options

  • ASession stealing
  • BCookie tampering
  • CExtension spoofing
  • DParameter tampering

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    18% (9)
  • C
    71% (36)
  • D
    8% (4)

Community Discussion

No community discussion yet for this question.

Full 412-79V10 Practice