ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 94 - ECSS discussion

Report
Export

Mark, an attacker, aims to access an organization's internal server, but the local firewall implementation restricted him from achieving this objective. To overcome this issue, he started sending specially crafted requests to the public server, through which he gained access to the local server.

Identify the type of attack initiated by Mark in the above scenario.

A.

Web cache poisoning attack

Answers
A.

Web cache poisoning attack

B.

SSRF attack

Answers
B.

SSRF attack

C.

TTP response-splitting attack

Answers
C.

TTP response-splitting attack

D.

SSH brute-force attack

Answers
D.

SSH brute-force attack

Suggested answer: B

Explanation:

Mark's actions align with aServer-Side Request Forgery (SSRF)attack. In SSRF, an attacker manipulates the target web server into making requests to unintended locations. In this case, Mark sent specially crafted requests to the public server, which allowed him to access the internal server.SSRF vulnerabilities can lead to sensitive information disclosure, unauthorized access to internal systems, and other dangerous attacks12.

EC-Council Certified Security Specialist (E|CSS) documents and study guide.

EC-Council Certified Security Specialist (E|CSS) course materials34.

asked 24/10/2024
Aldrin Plata
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first