CEPT Exam 2 (2024) – All Questions & Answers (100% Correct)
CEPT Exam 2 (2024) – All Questions & Answers (100% Correct)
What protocol does Moon bouncing use? - ANSWER - ICMP
What format string specifier is used to overwrite an address? - ANSWER - %n
Where can buffer overflows occur? -...
CEPT Exam 2 (2024) – All Questions &
Answers (100% Correct)
What protocol does Moon bouncing use? - ANSWER - ICMP
What format string specifier is used to overwrite an address? - ANSWER - %n
Where can buffer overflows occur? - ANSWER - heap, stack, kernel memory
Why are fuzzers popular? - ANSWER - They are adept at finding buffer overrun possibilities.
Why are format string vulnerabilities not as widely exploited? - ANSWER - They are newer, less-known
What does the EBP contain - ANSWER - The Electronic Base Pointer
What does the POP instruction do? - ANSWER - Takes the value pointed to by the ESP
and places it in a specific location.
What does the GetDriveA API do? - ANSWER - Returns the drive currently inserted into
the computer.
What does bind shell shellcode do? - ANSWER - Opens a socket and connects back to the attacker.
How can an IPS be attacked? - ANSWER - By creating a flood of false alerts.
Fuzzers can find what? - ANSWER - Vulnerabilities you were not looking for.
How does passive traffic observation recon work? - ANSWER - Observing network traffic and determining OS versions.
How can you fill the EAX with nulls? - ANSWER - XOR EAX, EAX
What tool can be used to attack IPS systems? - ANSWER - Sneeze
Why is the CALL instruction important? - ANSWER - It saves the EIP onto the stack.
Is attaching a memory resident debugger part of the three stages of software cracking? - ANSWER - No.
What does the %s format string do? - ANSWER - Allows you to write memory to an arbitrary location. What does the EIP register point to? - ANSWER - The next instruction to be executed.
What do Off-by-one overflows overwrite? - ANSWER - The saved EBP.
How do stack overflows work? - ANSWER - Overwriting the saved EIP on the stack with
one that points to an address with shellcode.
What is IDA Pro? - ANSWER - A popular disassembler.
Can DLL's be executable modules? - ANSWER - Yes
How can yo write shellcode that will evade an IDS? - ANSWER - Obsucring the NOP sled.
Are Fault Injection and Fuzzing essentially the same thing? - ANSWER - Yes
What do debuggers do? - ANSWER - Allow you to modify the runtime nature of a program.
What are software breakpoints set with? - ANSWER - 0xCC
What is the best way to to fill a register with nulls when writing shellcode? - ANSWER - Add a non-null value to the regsiter, then subtract the same value from the register.
Can PSExec execute programs remotely? - ANSWER - Yes
What is the hex representation for the ASCII characer A? - ANSWER - 41
What do application breakpointing API calls allow you to do when reverse engineering a
Windows application? - ANSWER - Halt a program when user input is received.
What does IDA Pro use to determine which compiler created a program? - ANSWER - Start Code
What is an encrypted version of netcat - ANSWER - cryptcat
What is Metasploit - ANSWER - An exploitation framework
What are one of the big problems with IDS? - ANSWER - False positivies
Theopcode for NOP is: - ANSWER - x90
Why can you overwrite subsequent blocks in heap memory? - ANSWER - It is contiguous, if one block does not do proper bounds checking.
Les avantages d'acheter des résumés chez Stuvia:
Qualité garantie par les avis des clients
Les clients de Stuvia ont évalués plus de 700 000 résumés. C'est comme ça que vous savez que vous achetez les meilleurs documents.
L’achat facile et rapide
Vous pouvez payer rapidement avec iDeal, carte de crédit ou Stuvia-crédit pour les résumés. Il n'y a pas d'adhésion nécessaire.
Focus sur l’essentiel
Vos camarades écrivent eux-mêmes les notes d’étude, c’est pourquoi les documents sont toujours fiables et à jour. Cela garantit que vous arrivez rapidement au coeur du matériel.
Foire aux questions
Qu'est-ce que j'obtiens en achetant ce document ?
Vous obtenez un PDF, disponible immédiatement après votre achat. Le document acheté est accessible à tout moment, n'importe où et indéfiniment via votre profil.
Garantie de remboursement : comment ça marche ?
Notre garantie de satisfaction garantit que vous trouverez toujours un document d'étude qui vous convient. Vous remplissez un formulaire et notre équipe du service client s'occupe du reste.
Auprès de qui est-ce que j'achète ce résumé ?
Stuvia est une place de marché. Alors, vous n'achetez donc pas ce document chez nous, mais auprès du vendeur conceptialresearchers. Stuvia facilite les paiements au vendeur.
Est-ce que j'aurai un abonnement?
Non, vous n'achetez ce résumé que pour €8,51. Vous n'êtes lié à rien après votre achat.