EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy
A security analyst is investigating a compromised Linux server. They find evidence of an attacker maintaining persistent access. The attacker created a new user account and then modified the '/etc/sudoers' file to grant this new user password-less sudo privileges. Which phase of system hacking does this activity primarily fall under?
- AClearing Tracks
- BMaintaining Access
- CReconnaissance
- DGaining Access
Show answer & explanationAnswer & explanation
Correct answer: B. Maintaining Access
Modifying the sudoers file and creating a new user account with elevated privileges after initial access has been gained are classic methods for an attacker to ensure they can return to the system later, even if other initial access methods are patched. This falls squarely into the 'Maintaining Access' phase.
Why the other options are wrong
- A. Clearing Tracks involves removing evidence of the attack.
- C. Reconnaissance involves gathering information about the target before an attack.
- D. Gaining Access is the initial entry into a system, often through exploitation.
Maintaining Access
The phase of system hacking where an attacker establishes mechanisms to ensure persistent access to a compromised system, even after initial exploits are remediated.
- Involves creating backdoors, rootkits, or new user accounts.
- Aims to ensure future access and control over the target system.
- Often includes modifying system configurations or installing persistent malware.
Memory trick: Recon, Scan, Gain, Maintain, Clear, Cover – the hacker's stair.