QuestionQ9

Threats, Vulnerabilities, and Mitigations

A company web server is initiating outbound traffic to a low-reputation public IP on a non-standard pat. The web server presents an unauthenticated page to clients who upload images the company. An analyst observes a suspicious process running on the server that was not created by the company development team. Which of the following is the most likely explanation for this security incident?

Explanation

An unauthenticated image-upload function can be abused to place a malicious server-side script on the host. Such a web shell can run unauthorized processes and establish outbound connections to attacker-controlled, low-reputation IP addresses over nonstandard ports.

Community Discussion

No comments yet. Be the first to start the discussion!