Hands-On Ethical Hacking and Network Security, ISBN 9781285454610
Ch. 3 Solutions-1
Chapter 3 Solutions
Review Questions
1. What is the main purpose of malware?
2. A computer _____ relies on a host to propagate throughout a network.
3. An exploit that attacks computer systems by inserting executable code in areas of
memory not protected because of poorly written code is called which of the
following?
4. Which of the following exploits might hide its destructive payload in a legitimate
application or game?
5. Antivirus software should be updated annually. True or False?
6. Which of the following doesn’t attach itself to a host but can replicate itself?
7. Which of the following is an example of a macro programming language?
8. One purpose of adware is to determine users’ purchasing habits. True or False?
9. List three types of malware.
10. A software or hardware component that records each keystroke a user enters is called
which of the following?
11. List three worms or viruses that use e-mail as a form of attack.
12. The Ping of Death is an exploit that sends multiple ICMP packets to a host faster
than the host can handle. True or False?
13. What type of network attack relies on multiple servers participating in an attack on
one host system?
14. What exploit is used to elevate an attackers permissions by inserting executable
code in the computers memory?
Hands-On Ethical Hacking and Network Security, ISBN 9781285454610
Ch. 3 Solutions-2
15. What component can be used to reduce the risk of a Trojan program or rootkit
sending information from an attacked computer to a remote host?
16. To reduce the risk of a virus attack on a network, you should do which of the
following?
17. The base 64 numbering system uses ____ bits to represent a character.
18. An exploit that leaves an attacker with another way to compromise a network later is
called which of the following?
19. Which of the following is a good place to begin your search for vulnerabilities of
Microsoft products?
20. An exploit discovered for one OS might also be effective on a different OS. True or
False?
Activities
Activity 3-1
Activity 3-2
Steps 3: Documents and spreadsheets are designed to trick users into clicking “Enable Macros”
Activity 3-3
The Stuxnet Virus used four different vulnerabilities to propagate itself through a victim network,
Activity 3-4
Step 3: Answers will vary. A multitude of Web sites discuss spyware, and definitions vary on
these sites. For example, at www.spychecker.com/spyware.html, spyware is defined as “tracking
Hands-On Ethical Hacking and Network Security, ISBN 9781285454610
Ch. 3 Solutions-3
Activity 3-5
Case Projects
Case Project 3-1: Determine Vulnerabilities for a Database Server
Case Project 3-2: Investigate Possible Vulnerabilities of Microsoft IIS 6.0
Answers may vary. The memo should include information on the many vulnerabilities of IIS 6.0.