Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 58 Topic 6 Discussion

ECCouncil Certified Ethical Hacker Exam (CEHv13) 312-50v13 Question # 58 Topic 6 Discussion

312-50v13 Exam Topic 6 Question 58 Discussion:
Question #: 58
Topic #: 6

A financial institution in Chicago deploys an internal HTTPS-based customer portal that uses response compression to optimize bandwidth. During an authorized security assessment, a tester gains a vantage point along the communication path between internal clients and the gateway device.

By repeatedly initiating controlled requests and analyzing subtle differences in encrypted response sizes, the tester correlates variations in compressed output with specific input patterns. Over time, this analysis enables extraction of portions of a protected authentication value transmitted within the secure channel.

Which session hijacking technique best describes this activity?


A.

Forbidden Attack


B.

CRIME Attack


C.

Man-in-the-Browser (MITB) Attack


D.

Man-in-the-Middle (MITM) Attack


Get Premium 312-50v13 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.