Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 36 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
CEH - Certified Ethical Hacker
CEH Questions
EH-Net
May 23, 2013, 12:47:10 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
>
CEH - Certified Ethical Hacker
(Moderator:
don
) >
CEH Questions
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: CEH Questions (Read 13640 times)
0 Members and 1 Guest are viewing this topic.
ric2007
Newbie
Offline
Posts: 7
CEH Questions
«
on:
July 18, 2007, 12:32:01 PM »
Hi All! Much thanks to Don and Blackazzaro for your help..
I have some questions that i hope you can help me with and which i hope will be able to help others.. Was supposed to write my CEH exam on 16/07/07 but due to technical difficulties experienced by the testing centre i have been left in limbo.. but i am not complaining as it gives me more time to study..
1.) Is it possible to block/prevent attackers from running any sort of traceroute into your DMZ?
2.) Using a 802.11b wireless nic on your laptop with Netstumbler installed, you would like to scan an 802.11g network? Why is this not possible?
3) You are doing IP spoofing while you scan your target. You find that the target has port 23 open. Anyway you are unable to connect. Why?
4) I notice repeated probes to port 1080. I learn that the protocol being used is designed to allow the host outside of a firewall to connect transparently and securely through the firewall.what would be your inference of what is happening/happened? Could someone be using SOCKS on the network to communicate through the firewall?
Your help is most appreciatted and i hope that i can to oneday give back..
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: CEH Questions
«
Reply #1 on:
July 18, 2007, 01:06:23 PM »
Quote
1.) Is it possible to block/prevent attackers from running any sort of traceroute into your DMZ?
Block ICMP.
Quote
2.) Using a 802.11b wireless nic on your laptop with Netstumbler installed, you would like to scan an 802.11g network? Why is this not possible?
Not sure of the technical reason, but bottom line is that they aren't compatible. G cards can usually pick up B, I'm not aware of any G cards that can't, but B cards can't operate on a G frequency so that's probably why they can't even see the traffic.
Quote
3) You are doing IP spoofing while you scan your target. You find that the target has port 23 open. Anyway you are unable to connect. Why?
Depends on what is running on port 23. It doesn't necessarily have to be telnet (if that's what you're referring to), and there could also be further restrictions imposed. And also, if you're spoofing your IP, perhaps you just happen to be spoofing one that is allowed to connect, but once you try a full connect from your IP, it doesn't work.
Quote
4) I notice repeated probes to port 1080. I learn that the protocol being used is designed to allow the host outside of a firewall to connect transparently and securely through the firewall.what would be your inference of what is happening/happened? Could someone be using SOCKS on the network to communicate through the firewall?
Perhaps run a sniffer to see what sort of traffic is passing through. If this is your firewall, block the port.
Hope that helps somewhat...
«
Last Edit: July 18, 2007, 03:20:05 PM by venom77
»
Logged
Oyle
Sr. Member
Offline
Posts: 264
"Man. Nature. Technology".
Re: CEH Questions
«
Reply #2 on:
July 18, 2007, 03:11:57 PM »
Quote
Using a 802.11b wireless nic on your laptop with Netstumbler installed, you would like to scan an 802.11g network? Why is this not possible?
Could be that 802.11g is faster than 802.11b? B and G work on different frequencies. 802.11N, when it is finally released, is supposed to be faster than B AND G, and is also supposed to be able to facilitate (wow, big word) long-range Wi-Fi.
Hope it helps!
Logged
MCP, MCP+I, MCSA, MCSE(NT4/W2K), CCNA, CCA, NWCCC, VH-PIRTS, CEH
--------------------
"hackers are like jedi, crackers are like the sith: do not fall prey to the dark side".
From 1337 h4x0r h4ndb00k: "the ten laws of geek", law x
-Tapeworm
nebu10uz
Sr. Member
Offline
Posts: 368
Re: CEH Questions
«
Reply #3 on:
July 18, 2007, 08:21:32 PM »
Actually, regarding question number 2:
Quote
2.) Using a 802.11b wireless nic on your laptop with Netstumbler installed, you would like to scan an 802.11g network? Why is this not possible?
The 802.11b and 802.11g standard are generally compatible. It all depends on the setup of the network. For instance, the same encryption must be use on all device in a wifi network. Usually 802.11g devices support more advance encryption options than 802.11b standard. Therefore if your 802.11b wireless nic card does not support the encryption option that the 802.11g network is using then you won't be able to scan this network.
At home I have a 802.11g network setup with my laptop that is using a 802.11b nic . And since my wifi network is properly set, all works fine.
Quote
Could be that 802.11g is faster than 802.11b? B and G work on different frequencies.
Oyle, 802.11b and 802.11g operate on the same frequency (2.4-2.5 GHz) and that's why they are compatible and yes 802.11g ( 54 Mbit/s) is much faster than 802.11b (11 Mbit/s), however, this is not the reason why a 802.11b wifi nic on a laptop can't scan a 802.11g network.
«
Last Edit: July 18, 2007, 08:34:31 PM by blackazarro
»
Logged
Security+, OSCP, CEH
BillV
Hero Member
Offline
Posts: 1892
Re: CEH Questions
«
Reply #4 on:
July 19, 2007, 07:13:46 AM »
D'oh! Haha.. yeah, B and G are same, A is the higher one. Read through the questions too fast.. whoops
Logged
Otter
Newbie
Offline
Posts: 41
Re: CEH Questions
«
Reply #5 on:
July 20, 2007, 05:56:44 AM »
Quote
1.) Is it possible to block/prevent attackers from running any sort of traceroute into your DMZ?
If your router doesn't ever respond with ICMP messages of any type, this effectively breaks traceroute in all its flavors iirc. I believe you may also encounter the distinction in traceroute implementations where Cisco and Linux use UDP packets for the probe while Windows use ICMP echo requests. The "sensing" mechanism on all OS's I believe relies on ICMP replies.
http://www.cisco.com/warp/public/105/traceroute.shtml
Quote
2.) Using a 802.11b wireless nic on your laptop with Netstumbler installed, you would like to scan an 802.11g network? Why is this not possible?
b and g use the same frequency, however b is the older slower standard, g the newer. g is by standard backward compatible with b, but b hardware can't grok g traffic. If you want to get very technical about it, the difference between the two is the modulation scheme. CCK is the scheme used by b, OFDM is used by g, but by standard, g hardware can deal with
CCK.
http://en.wikipedia.org/wiki/802.11#802.11b
But nothing I recall of the CEH exam got anywhere near that technical regarding modulation.
Quote
3) You are doing IP spoofing while you scan your target. You find that the target has port 23 open. Anyway you are unable to connect. Why?
Just think about this for bit. If you spoof your IP address in your scan, where will the target send the reply packets?
Quote
4) I notice repeated probes to port 1080. I learn that the protocol being used is designed to allow the host outside of a firewall to connect transparently and securely through the firewall.what would be your inference of what is happening/happened? Could someone be using SOCKS on the network to communicate through the firewall?
Have a look at /etc/services on a linux box. Or the IANA list of common ports
http://www.iana.org/assignments/port-numbers
I'm not sure I'd come to the conclusion someone is communicating through my fw with SOCKS just because of some probes, but I might conclude that the probes are perhaps hunting for a listening SOCKS server.
Logged
skel
Jr. Member
Offline
Posts: 60
"Beam me up Scotty - Only hackers here"
Re: CEH Questions
«
Reply #6 on:
July 20, 2007, 07:05:37 AM »
Quote
2.) Using a 802.11b wireless nic on your laptop with Netstumbler installed, you would like to scan an 802.11g network? Why is this not possible?
I can remember when I was studying for CEH that one of the CEH documents said that Netstumbler doesnt support 11g. It was probably talking about a earlier version of Netstumbler .
So could this question be a practice test question coming form this era ?
Logged
Skel
ric2007
Newbie
Offline
Posts: 7
Re: CEH Questions
«
Reply #7 on:
July 22, 2007, 02:41:31 PM »
Hi All! I have decided to give you the questions with the multiple choices..
1)Eric notices probes to port 1080. He learns that the protocol being used is designed to allow a host outside of a firewall to connect transparently and securely through a firewall. He wonders if his firewall has been breached. What would be your inference?
A. Eric's network has been penetrated by a firewall breach?
B. The attcker is using ICMP protocol to have a covert channel
C. Eric has a wingate package providing FTP redirection on his network
D.
Somebody is using SOCKS on the network to communicate through the Firewall
2) You are the security administrator for a large network. You want to prevent attackers from running any sort of traceroute into your DMZ and discover the internal structure of publicly accessible areas of the network. How can you achieve this?
A. Block ICMP at the firewall
B. Block UDP at the firewall
C. Both A and B
D.
There is no way to completely block doing a traceroute into this area.
3) What do you conclude from the nmap results below?
starting nmap V. 3. 10ALPHA0 (
www.insecyre.org/nmap
)
(The 1592 ports scanned but not shown below are in stae: closed)
Port state Service
21/tcp open ftp
25/tcp open smtp
90/tcp open http
443/tcp open https
Remote operating system guess: Too many signatures match the reliability to guess the OS. Nmap run completed - 1 IP address (1 host up) scanned in 91.66 seconds.
A. The system is a windows domain controller
B.
The system is not firewalled
C. The system is not running linus or solaris
D. The system is not properly patched
4) You are doing IP spoofing while you scan your target. You find that the target has port 23 open. Abyway you are unable to connect. Why?
A.
A firewall is blocking port 23
B You cannot spoof + TCP
C. You need an automated telnet tool
D. The OS does not reply to telnet if port 23 is open.
The answers given to me as correct.. i have highlighted with a glow or made bold.. Your assistance is most appreciatted and from the replies i have received very educational.. I would like to say Thank you so much to the creators of this website.
Logged
LSOChris
Guest
Re: CEH Questions
«
Reply #8 on:
July 22, 2007, 03:37:24 PM »
Quote from: ric2007 on July 22, 2007, 02:41:31 PM
Hi All! I have decided to give you the questions with the multiple choices..
2) You are the security administrator for a large network. You want to prevent attackers from running any sort of traceroute into your DMZ and discover the internal structure of publicly accessible areas of the network. How can you achieve this?
A. Block ICMP at the firewall
B. Block UDP at the firewall
C. Both A and B
D.
There is no way to completely block doing a traceroute into this area.
>> C, blocking ICMP/UDP should pretty much block any traceroute activities (yes i know there is LFT)
4) You are doing IP spoofing while you scan your target. You find that the target has port 23 open. Abyway you are unable to connect. Why?
A.
A firewall is blocking port 23
B You cannot spoof + TCP
C. You need an automated telnet tool
D. The OS does not reply to telnet if port 23 is open.
>> B, you cannot spoof + TCP
Logged
skel
Jr. Member
Offline
Posts: 60
"Beam me up Scotty - Only hackers here"
Re: CEH Questions
«
Reply #9 on:
July 23, 2007, 11:01:27 PM »
Agree with ChrisG.
Practice tests are a good guide to focus on exam test areas, but U need to read/research further and find answers. That way u will gain lot of knowledge and pass the exam too
Never solely depend on the answers given by them.
Logged
Skel
ric2007
Newbie
Offline
Posts: 7
Re: CEH Questions
«
Reply #10 on:
July 24, 2007, 02:29:01 AM »
Hi All! Thanks for all the help.. Thanks Skel, for your advice.. But i have been doing research and i am not relying on the questions alone. However,i have in some cases been left confused, hence my asking for your help with these questions. You are all good at what you do and i am no expert yet
.. I am a student and you all are my teachers.
Thanks for all your help once again.. I am hoping to write the exam this week and will let you know how it went..
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Editor-In-Chief
: Special Xmas Deal: 10% Off eLearnSecurity Courses
(3) by
hekvvddtest
Greetings
: Hello
(6) by
hekvvddtest
Greetings
: Obtain The Scoop On mulberry bags Before You Are Too Late
(13) by
hekvvddtest
Calendar Of Events
: HITBSecConf2013 – Amsterdam
(9) by
hekvvddtest
Special Events
: [Article]-Webcast: Deep Dive into Red Teaming with the Metasploit Framework
(19) by
hekvvddtest
Network Pen Testing
: HackaServer - Anyone tried it?
(4) by
hekvvddtest
Greetings
: Good day ...
(7) by
hekvvddtest
Gates
: Chris Gates' Blog RSA Finalist
(5) by
hekvvddtest
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(1) by
hekvvddtest
General Certification
: nth topic on Career Advice
(9) by
hekvvddtest
General Certification
: Direction
(5) by
hekvvddtest
Hardware
: Discreet Hacking Devices
(8) by
hekvvddtest
Calendar Of Events
: CanSecWest 2013
(5) by
hekvvddtest
Forensics
: Burn Note
(5) by
hekvvddtest
Calendar Of Events
: Cyber Readiness Challenge - Rome
(1) by
hekvvddtest
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.