Hands-on Ethical Hacking and Network Defense, 3e, ISBN 9781285454610
Ch. 9 Solutions-1
Chapter 9 Solutions
Review Questions
1. An embedded OS must be developed specifically for use with embedded systems. True or
False?
2. Why are embedded OSs more likely to have unpatched security vulnerabilities than
general-purpose OSs do? (Choose all that apply.)
3. Which of the following describes an RTOS?
4. Which of the following doesnt use an embedded OS?
5. Why are rootkits that infect a device’s firmware considered the biggest threat to any OS
(embedded or general-purpose)?
6. Which of the following is an advantage of Windows CE over other Windows embedded
OSs?
7. VxWorks is which of the following?
8. Which of the following is a major challenge in securing embedded OS?
9. The lack of a familiar interface, such as CD/DVD-ROM drives, contributes to the
difficulty of updating embedded OSs. True or False?
10. Embedded OSs on routers are susceptible to which of the following? (Choose all that
11. Multifunction devices (MFDs) are rarely:
12. SCADA systems are used for which of the following?
Hands-on Ethical Hacking and Network Defense, 3e, ISBN 9781285454610
Ch. 9 Solutions-2
13. Cell phone vulnerabilities enable hackers to do which of the following? (Choose all that
apply.)
14. If the time and money required to compromise an embedded system exceeds the value of
the systems information, a security tester might recommend not fixing the
vulnerability. True or False?
15. Most printers now have only TCP/IP enabled and dont allow default administrator
passwords, so theyre inherently more secure. True or False?
Activities
Activity 9-1: Researching an Attack on the San Francisco Parking Meter
System
Step 5: The attackers used the cellular data connection to the Jeep’s “infotainment” system to
facilitate their attack. The attackers were able to exploit a flaw in the UConnect head unit system.
Once they had access to the UConnect head unit over the data connection, they then were able to
Activity 9-2: Researching Products with Embedded OSs
Step 4: Answers will vary.
Activity 9-3: Researching ATM Vulnerabilities
Step 2: Windows XP is in used on these vulnerable ATMs. The security company recommends
Activity 9-4: Identifying Printer Vulnerabilities
Step 2: Although students might find some exceptions, there have been few improvements to
Hands-on Ethical Hacking and Network Defense, 3e, ISBN 9781285454610
Ch. 9 Solutions-3
Case Projects
Case Project 9-1: Protecting Embedded OSs on the Alexander Rocco
Network
Students should explain how they researched vulnerabilities for these devices and discovered
methods for addressing them. They should search the NVD database as well as other Internet
Case Project 9-2: Identifying Vulnerable Systems That Can’t Be Patched
The purpose of this project is to force students to think about different ways to reduce security
risks when a patch cant be applied. It can take manufacturers months, sometimes even years, to
test and receive approval for patches from regulatory agencies. Even if patches are available, the
Case Project 9-3: Identifying Vulnerabilities in Mobile Phones
Answers will vary, depending on the phone model students research, but the point of this project is
to encourage students to think out of the box in coming up with possible vulnerabilities in their
phones. (Instructors might want to write down the different vulnerability types that students come