EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsMedium
A user reports receiving an email with an attached PDF document. Upon opening the PDF, nothing visible happens, but the user's antivirus software immediately flags a 'Heap Spray' exploit attempt. Which type of malware attack is this indicative of?
- ADrive-by Download
- BZero-day Exploit
- CBuffer Overflow
- DClient-side Exploit
Show answer & explanationAnswer & explanation
Correct answer: D. Client-side Exploit
A 'Heap Spray' exploit attempt originating from opening a PDF document on the user's machine is a classic example of a client-side exploit. These exploits target vulnerabilities in applications running on the user's system (the 'client'), such as PDF readers, web browsers, or office suites, rather than vulnerabilities in a server.
Why the other options are wrong
- A. A drive-by download occurs when malware is downloaded without user interaction, often just by visiting a compromised website, not necessarily by opening a specific document.
- B. A zero-day exploit refers to a vulnerability that is unknown to the vendor, but it describes the nature of the vulnerability, not the attack vector or type of attack itself. This attack *could* be a zero-day, but 'client-side exploit' better describes the mechanism.
- C. Buffer overflow is a type of vulnerability that can be exploited, but it's not the overarching attack category. Heap spray is a technique used in conjunction with buffer overflows or other memory corruption vulnerabilities, often in a client-side context.
Client-side Exploit
An attack that targets vulnerabilities in software applications running on a user's computer (the 'client'), such as web browsers, email clients, or document viewers, to gain control or install malware.
- Relies on user interaction (e.g., opening a malicious file, visiting a compromised website).
- Targets common applications like PDF readers, browsers, office suites.
- Often uses techniques like heap spray or remote code execution.
Memory trick: Client-side attacks hit the user's app, not the server's back.