nerdexam
EC-Council

EC0-350 · Question #395

A tester has been using the msadc.pl attack script to execute arbitrary commands on a Windows NT4 web server. While it is effective, the tester finds it tedious to perform extended functions. On…

The correct answer is B. A chained exploit. See the full explanation below for the reasoning.

Question

A tester has been using the msadc.pl attack script to execute arbitrary commands on a Windows NT4 web server. While it is effective, the tester finds it tedious to perform extended functions. On further research, the tester come across a perl script that runs the following msadc functions:system("perl msadc.pl -h $host -C "echo open $your >testfile""); Which exploit is indicated by this script?

Exhibit

EC0-350 question #395 exhibit

Options

  • AA buffer overflow exploit
  • BA chained exploit
  • CA SQL injection exploit
  • DA denial of service exploit

How the community answered

(64 responses)
  • A
    6% (4)
  • B
    81% (52)
  • C
    9% (6)
  • D
    3% (2)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice