nerdexam
EC-Council

EC0-350 · Question #669

Take a look at the following attack on a Web Server using obstructed URL: 4%63%2f%70 %61%73%73%77%64 The request is made up of: ?%2e%2e%2f%2e%2e%2f%2e%2f% = ../../../ ?%65%74%63 = etc ?%2f = /…

The correct answer is B. Create rules in IDS to alert on strange Unicode requests. See the full explanation below for the reasoning.

Question

Take a look at the following attack on a Web Server using obstructed URL:

4%63%2f%70 %61%73%73%77%64 The request is made up of:

?%2e%2e%2f%2e%2e%2f%2e%2f% = ../../../ ?%65%74%63 = etc ?%2f = / ?%70%61%73%73%77%64 = passwd How would you protect information systems from these attacks?

Options

  • AConfigure Web Server to deny requests involving Unicode characters.
  • BCreate rules in IDS to alert on strange Unicode requests.
  • CUse SSL authentication on Web Servers.
  • DEnable Active Scripts Detection at the firewall and routers.

How the community answered

(58 responses)
  • A
    3% (2)
  • B
    72% (42)
  • C
    9% (5)
  • D
    16% (9)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice