nerdexam
GIAC

GCIH · Question #57

Mark works as a Network Administrator for Net Perfect Inc. The company has a Windows-based network. The company uses Check Point SmartDefense to provide security to the network. Mark uses…

The correct answer is A. HTR Overflow worms and mutations. Check Point SmartDefense allows administrators to limit the maximum HTTP response header length, which prevents buffer overflow attacks like HTR Overflow that exploit excessively long HTTP headers.

Vulnerability Exploitation & Privilege Escalation

Question

Mark works as a Network Administrator for Net Perfect Inc. The company has a Windows-based network. The company uses Check Point SmartDefense to provide security to the network. Mark uses SmartDefense on the HTTP servers of the company to fix the limitation for the maximum response header length. Which of the following attacks can be blocked by defining this limitation?

Options

  • AHTR Overflow worms and mutations
  • BRamen worm attack
  • CMelissa virus attack
  • DShoulder surfing attack

How the community answered

(54 responses)
  • A
    70% (38)
  • B
    17% (9)
  • C
    6% (3)
  • D
    7% (4)

Why each option

Check Point SmartDefense allows administrators to limit the maximum HTTP response header length, which prevents buffer overflow attacks like HTR Overflow that exploit excessively long HTTP headers.

AHTR Overflow worms and mutationsCorrect

HTR (HyperText Transfer) Overflow worms exploit buffer overflow vulnerabilities by sending excessively long HTTP headers or responses to web servers. By defining a maximum response header length in SmartDefense, the firewall drops packets exceeding that threshold, blocking HTR Overflow worms and their mutations before they can trigger the overflow condition on the target server.

BRamen worm attack

The Ramen worm targets Linux systems by exploiting vulnerabilities in services like wu-ftpd and LPRng, and is entirely unrelated to HTTP response header length limits.

CMelissa virus attack

The Melissa virus is a macro virus spread via email attachments in Microsoft Word documents, making HTTP header length limitations irrelevant to blocking it.

DShoulder surfing attack

Shoulder surfing is a physical social engineering technique where an attacker visually observes a user entering credentials, which cannot be mitigated by any network-layer header length configuration.

Concept tested: SmartDefense HTTP header length overflow protection

Topics

#HTTP header overflow#SmartDefense#buffer overflow mitigation#worm defense

Community Discussion

No community discussion yet for this question.

Full GCIH Practice