EC-Council
EC0-350 · Question #669
Take a look at the following attack on a Web Server using obstructed URL: 4%63%2f%70 %61%73%73%77%64 The request is made up of: ?%2e%2e%2f%2e%2e%2f%2e%2f% = ../../../ ?%65%74%63 = etc ?%2f = /…
The correct answer is B. Create rules in IDS to alert on strange Unicode requests. See the full explanation below for the reasoning.
Question
Take a look at the following attack on a Web Server using obstructed URL:
4%63%2f%70 %61%73%73%77%64 The request is made up of:
?%2e%2e%2f%2e%2e%2f%2e%2f% = ../../../ ?%65%74%63 = etc ?%2f = / ?%70%61%73%73%77%64 = passwd How would you protect information systems from these attacks?
Options
- AConfigure Web Server to deny requests involving Unicode characters.
- BCreate rules in IDS to alert on strange Unicode requests.
- CUse SSL authentication on Web Servers.
- DEnable Active Scripts Detection at the firewall and routers.
How the community answered
(58 responses)- A3% (2)
- B72% (42)
- C9% (5)
- D16% (9)
Community Discussion
No community discussion yet for this question.