QuestionQ27

Vulnerability Management

A security analyst identifies an LFI vulnerability that could be exploited to obtain credentials from the underlying host. Which of the following patterns can the analyst use to search the web-server logs for evidence that this specific vulnerability was exploited?

Explanation

Local file inclusion exploits can attempt to read sensitive host files through a web request. On Unix-like systems, /etc/shadow contains password hashes; therefore, its presence in web-server request logs indicates an attempt to use LFI to obtain host credentials.

Community Discussion

No comments yet. Be the first to start the discussion!