QuestionQ327

Endpoint Attack and Pivoting

John is a professional Ethical Hacker assigned to test the security of www.we-are-secure.com. He discovers that the We-are- secure server is vulnerable to attacks. As a countermeasure, he recommends that the Network Administrator remove IPP printing capability from the server. He is recommending this as a countermeasure against __________.

  • A IIS buffer overflow
  • B NetBIOS NULL session
  • C SNMP enumeration
  • D DNS zone transfer
Explanation

Internet Printing Protocol (IPP) functionality is implemented as an IIS ISAPI extension, and vulnerabilities in that component can permit remote code execution through an overflow condition. Disabling or removing the IPP service removes that IIS attack surface.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!