PT0-002 · Question #250
The following output is from reconnaissance on a public-facing banking website: Based on these results, which of the following attacks is MOST likely to succeed?
The correct answer is D. A Heartbleed attack. Based on these results, the most likely attack to succeed is a Heartbleed attack. The Heartbleed attack is a vulnerability in the OpenSSL implementation of the TLS/SSL protocol that allows an attacker to read the memory of the server and potentially steal sensitive information…
Question
The following output is from reconnaissance on a public-facing banking website:
Based on these results, which of the following attacks is MOST likely to succeed?
Exhibit
Options
- AA birthday attack on 64-bit ciphers (Sweet32)
- BAn attack that breaks RC4 encryption
- CAn attack on a session ticket extension (Ticketbleed)
- DA Heartbleed attack
How the community answered
(33 responses)- A15% (5)
- B3% (1)
- C9% (3)
- D73% (24)
Explanation
Based on these results, the most likely attack to succeed is a Heartbleed attack. The Heartbleed attack is a vulnerability in the OpenSSL implementation of the TLS/SSL protocol that allows an attacker to read the memory of the server and potentially steal sensitive information, such as private keys, passwords, or session tokens. The results show that the website is using OpenSSL 1.0.1f, which is vulnerable to the Heartbleed attack.
Topics
Community Discussion
No community discussion yet for this question.
