ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 244 - CS0-003 discussion

Report
Export

A security analyst reviews the following results of a Nikto scan:

Which of the following should the security administrator investigate next?

A.
tiki
Answers
A.
tiki
B.
phpList
Answers
B.
phpList
C.
shtml.exe
Answers
C.
shtml.exe
D.
sshome
Answers
D.
sshome
Suggested answer: C

Explanation:

The security administrator should investigate shtml.exe next, as it is a potential vulnerability that allows remote code execution on the web server. Nikto scan results indicate that the web server is running Apache on Windows, and that the shtml.exe file is accessible in the /scripts/ directory. This file is part of the Server Side Includes (SSI) feature, which allows dynamic content generation on web pages. However, if the SSI feature is not configured properly, it can allow attackers to execute arbitrary commands on the web server by injecting malicious code into the URL or the web page12. Therefore, the security administrator should check the SSI configuration and permissions, and remove or disable the shtml.exe file if it is not needed.

Reference: Nikto-Penetration testing. Introduction, Web application scanning with Nikto

asked 02/10/2024
Rumen Zazyov
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first