312-39 Exam QuestionsBrowse all questions from this exam

312-39 Exam - Question 7


Identify the attack when an attacker by several trial and error can read the contents of a password file present in the restricted etc folder just by manipulating the URL in the browser as shown: http://www.terabytes.com/process.php./../../../../etc/passwd

Show Answer
Correct Answer: AB

The correct answer is Directory Traversal Attack. This type of attack occurs when an attacker manipulates the URL path to access files and directories that are outside the web application's root directory. In this case, the use of '../' sequences in the URL is an attempt to traverse the directory structure to access the '/etc/passwd' file, which contains sensitive information such as user passwords.

Discussion

9 comments
Sign in to comment
udham1111Option: A
Oct 28, 2022

That is directory traversal

iemvrm12Option: A
Nov 20, 2022

A is correct.

ayisuskaOption: A
Jun 21, 2023

A is correct

froi2222Option: A
Oct 13, 2023

A. Directory Traversal Attack In a directory traversal attack, the attacker attempts to access files and directories that are outside the web application's root directory by manipulating the URL. In this case, the attacker is trying to access the password file by using "../" to navigate to the "/etc" directory.

mihaibeucaOption: A
Oct 16, 2022

tHAT'S DIRECTORY Travversal!

rached1996Option: A
Jan 4, 2023

directory traversal

Bender_alorabiOption: A
Jan 11, 2023

directory traversal

MuslihmdzinOption: A
Apr 8, 2023

A. ..//..// directory traversal

basil10Option: A
Jul 10, 2024

a is correct