EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium
A penetration tester is conducting an internal vulnerability assessment. They discover a legacy Windows server running an outdated service that is known to be vulnerable to a remote code execution exploit. The server is critical for a specific line-of-business application and cannot be immediately patched. Which of the following techniques is the MOST appropriate for the penetration tester to recommend to maintain access to the compromised system without immediately disrupting the critical service?
- ANotifying the system administrator to patch the server during the next maintenance window.
- BEstablishing a persistent backdoor through a scheduled task or startup entry.
- CImplementing a host-based intrusion prevention system (HIPS) on the server.
- DDisabling the vulnerable service immediately to prevent further exploitation.
Show answer & explanationAnswer & explanation
Correct answer: B. Establishing a persistent backdoor through a scheduled task or startup entry.
To maintain access to a compromised system, an attacker (or penetration tester in this scenario) will establish persistence. Creating a persistent backdoor via scheduled tasks or startup entries is a common and effective method to ensure access can be regained even after reboots or service restarts, without immediately disrupting the critical service.
Why the other options are wrong
- A. Notifying the administrator is part of reporting, not a technique for maintaining access post-compromise.
- C. Implementing HIPS is a defensive measure, not a technique for maintaining access by an attacker.
- D. Disabling the service would disrupt the critical application, which goes against the scenario's requirement.
Maintaining Access (Persistence)
The phase in system hacking where an attacker establishes mechanisms to retain control over a compromised system, even if the system is rebooted, patched, or if initial exploits are addressed.
- Ensures long-term control over the target.
- Often involves creating backdoors, modifying system configurations, or establishing covert channels.
- Aims to survive system reboots and administrative actions.
Memory trick: To keep the 'keys' to the kingdom, create a 'backdoor' for re-entry.