nerdexam
ExamsGCIHQuestions#10
GIAC

GCIH · Question #10

GCIH Question #10: Real Exam Question with Answer & Explanation

Sign in or unlock GCIH to reveal the answer and full explanation for question #10. The question stem and answer options stay visible for context.

Web Application Attacks & Post-Exploitation

Question

John works as a professional Ethical Hacker. He has been assigned a project to test the security server. The output of the scanning test is as follows: C:\whisker.pl -h target_IP_address = Host: target_IP_address = Server: Apache/1.3.12 (Win32) ApacheJServ/1.1 mod_ssl/2.6.4 OpenSSL/0.9.5a mod_perl/1.22 + 200 OK: HEAD /cgi-bin/printenv John recognizes /cgi-bin/printenv vulnerability ('Printenv' vulnerability) in the We_are_secure server. Which of the following statements about 'Printenv' vulnerability are true? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AThis vulnerability helps in a cross site scripting attack.
  • B'Printenv' vulnerability maintains a log file of user activities on the Website, which may be
  • CThe countermeasure to 'printenv' vulnerability is to remove the CGI script.
  • DWith the help of 'printenv' vulnerability, an attacker can input specially crafted links and/or

Unlock GCIH to see the answer

You've previewed enough free GCIH questions. Unlock GCIH for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#CGI vulnerabilities#printenv#cross-site scripting#web server enumeration
Full GCIH Practice
John works as a professional Ethical Hacker. He has been assigned... | GCIH Q#10 Answer | NerdExam