ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 361 - PT0-002 discussion

Report
Export

A penetration tester issues the following command after obtaining a low-privilege reverse shell: wmic service get name,pathname,startmode

Which of the following is the most likely reason the penetration tester ran this command?

A.
To search for passwords in the service directory
Answers
A.
To search for passwords in the service directory
B.
To list scheduled tasks that may be exploitable
Answers
B.
To list scheduled tasks that may be exploitable
C.
To register a service to run as System
Answers
C.
To register a service to run as System
D.
To find services that have unquoted service paths
Answers
D.
To find services that have unquoted service paths
Suggested answer: D

Explanation:

The command wmic service get name,pathname,startmode is used by penetration testers to enumerate services and their configurations, specifically looking for services with unquoted paths. If a service's path contains spaces and is not enclosed in quotes, it can be exploited by placing a malicious executable along the path, leading to privilege escalation. For example, if the service path is C:\Program Files\My Service\service.exe and is unquoted, an attacker could place a malicious Program.exe in C:\, which would then be executed with the same privileges as the service when the service starts. Identifying such services allows penetration testers to highlight potential security risks that could be exploited for privilege escalation.

asked 02/10/2024
Ammar Khan
24 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first