Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

CompTIA PenTest+ Exam PT0-003 Question # 58 Topic 6 Discussion

CompTIA PenTest+ Exam PT0-003 Question # 58 Topic 6 Discussion

PT0-003 Exam Topic 6 Question 58 Discussion:
Question #: 58
Topic #: 6

A penetration tester conducts a scan on an exposed Linux web server and gathers the following data:

Host: 192.168.55.23

Open Ports:

22/tcp Open OpenSSH 7.2p2 Ubuntu 4ubuntu2.10

80/tcp Open Apache httpd 2.4.18 (Ubuntu)

111/tcp Open rpcbind 2-4 (RPC #100000)

Additional notes:

Directory listing enabled on /admin

Apache mod_cgi enabled

No authentication required to access /cgi-bin/debug.sh

X-Powered-By: PHP/5.6.40-0+deb8u12

Which of the following is the most effective action to take?


A.

Launch a payload using msfvenom and upload it to the /admin directory.


B.

Review the contents of /cgi-bin/debug.sh.


C.

Use Nikto to scan the host and port 80.


D.

Attempt a brute-force attack against OpenSSH 7.2p2.


Get Premium PT0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.