Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 20 Topic 3 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 20 Topic 3 Discussion

312-50v13 Exam Topic 3 Question 20 Discussion:
Question #: 20
Topic #: 3

The following is an entry captured by a network IDS. You are assigned the task of analyzing this entry.

You notice the value 0x90, which is the most common NOOP instruction for the Intel processor.

You also notice "/bin/sh" in the ASCII part of the output.

As an analyst, what would you conclude about the attack?

312-50v13 Question 20


A.

The buffer overflow attack has been neutralized by the IDS


B.

The attacker is creating a directory on the compromised machine


C.

The attacker is attempting a buffer overflow attack and has succeeded


D.

The attacker is attempting an exploit that launches a command-line shell


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.