Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49 All Questions

View all questions & answers for the 312-49 exam

Exam 312-49 topic 1 question 7 discussion

Actual exam question from ECCouncil's 312-49
Question #: 7
Topic #: 1
[All 312-49 Questions]

A honey pot deployed with the IP 172.16.1.108 was compromised by an attacker. Given below is an excerpt from a Snort binary capture of the attack. Decipher the activity carried out by the attacker by studying the log. Please note that you are required to infer only what is explicit in the excerpt.
(Note: The student is being tested on concepts learnt during passive OS fingerprinting, basic TCP/IP connection concepts and the ability to read packet signatures from a sniff dump.)
03/15-20:21:24.107053 211.185.125.124:3500 -> 172.16.1.108:111
TCP TTL:43 TOS:0x0 ID:29726 IpLen:20 DgmLen:52 DF
***A**** Seq: 0x9B6338C5 Ack: 0x5820ADD0 Win: 0x7D78 TcpLen: 32
TCP Options (3) => NOP NOP TS: 23678634 2878772 =+=+=+=+=+=+=+=+=+=+=+=+=+=
+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
03/15-20:21:24.452051 211.185.125.124:789 -> 172.16.1.103:111
UDP TTL:43 TOS:0x0 ID:29733 IpLen:20 DgmLen:84

Len: 64 -
01 0A 8A 0A 00 00 00 00 00 00 00 02 00 01 86 A0 . .............
00 00 00 02 00 00 00 03 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 01 86 B8 00 00 00 01 . ..............
00 00 00 11 00 00 00 00 ........
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
03/15-20:21:24.730436 211.185.125.124:790 -> 172.16.1.103:32773
UDP TTL:43 TOS:0x0 ID:29781 IpLen:20 DgmLen:1104

Len: 1084 -
47 F7 9F 63 00 00 00 00 00 00 00 02 00 01 86 B8

  • A. The attacker has conducted a network sweep on port 111
  • B. The attacker has scanned and exploited the system using Buffer Overflow
  • C. The attacker has used a Trojan on port 32773
  • D. The attacker has installed a backdoor
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bennoli13
5 months, 2 weeks ago
I should disagree with the answer. Based on the log, the most explicit activity is: B. The attacker has scanned and exploited the system using Buffer Overflow The large UDP packet to port 32773 strongly suggests a buffer overflow exploit. Per my understanding, a network sweep would involve scanning multiple IP addresses, but here, the attacker targets specific ports on the same subnet.
upvoted 1 times
...
nirvachi
1 year, 3 months ago
To select something other than A you need more specific information about the attack type, in the output.
upvoted 1 times
...
Ariel235788
2 years, 11 months ago
hard to argue on a sweep over port 111 due to the last line 03/15-20:21:24.730436 211.185.125.124:790 -> 172.16.1.103:32773 but I will agree with this answer as the other choices won't work
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...