Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium

A security analyst is performing a forensic investigation on a server that was recently compromised. They discover a malicious script that attempts to allocate an excessively large amount of memory, exceeding the buffer size intended for a specific program. This action subsequently overwrites adjacent memory locations, including the return address, to execute arbitrary code. What type of vulnerability is being exploited?

  1. ABuffer overflow
  2. BSQL injection
  3. CCross-Site Scripting (XSS)
  4. DDenial of Service (DoS)
Show answer & explanation

Correct answer: A. Buffer overflow

A buffer overflow occurs when a program attempts to write data to a buffer that is larger than the buffer's allocated capacity. This overwrites adjacent memory, potentially including critical control flow data like the return address, allowing an attacker to inject and execute their own code.

Why the other options are wrong

  • B. SQL injection manipulates database queries and does not involve memory allocation or overwriting return addresses.
  • C. XSS is a client-side web vulnerability that injects scripts into web pages, not a server-side memory exploitation technique.
  • D. While a buffer overflow can lead to a DoS, the primary goal described here is arbitrary code execution by overwriting the return address, which is a specific type of buffer overflow exploitation.

Buffer Overflow

A condition where a program attempts to write data beyond the boundaries of a fixed-length buffer, overwriting adjacent memory locations.

  • Can lead to crashes (DoS) or arbitrary code execution.
  • Often exploited by overwriting the return address on the stack.
  • Common in languages like C and C++ due to manual memory management.

Memory trick: Memory corruption is like a brain short-circuit.

More Network Intrusion Analysis questions