EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy
During a penetration test, an ethical hacker successfully exploits a buffer overflow vulnerability on a target system. After gaining initial access, the hacker discovers that the current user context has very limited privileges. To achieve their objective of full system compromise, what is the IMMEDIATE next step the hacker should attempt?
- AInstall a persistent backdoor for future access.
- BAttempt to escalate privileges to a higher-level account.
- CClear system logs to cover their tracks.
- DExfiltrate sensitive data to an external server.
Show answer & explanationAnswer & explanation
Correct answer: B. Attempt to escalate privileges to a higher-level account.
After gaining initial access with limited privileges, the immediate next step in the system hacking methodology is almost always privilege escalation. This allows the attacker to gain control over critical system functions and access restricted resources necessary for further exploitation or compromise.
Why the other options are wrong
- A. Installing a backdoor is part of maintaining access, which usually follows privilege escalation.
- C. Clearing logs is part of covering tracks, which is a later phase in the attack.
- D. Data exfiltration typically happens after achieving sufficient privileges and maintaining access.
Privilege Escalation
The act of exploiting a vulnerability, design flaw or configuration oversight in an operating system or application to gain elevated access to resources that are normally protected from an application or user.
- Can be vertical (user to admin) or horizontal (user to another user).
- Often involves exploiting misconfigurations, kernel bugs, or weak passwords.
- A critical step towards full system control.
Memory trick: After 'gaining access', you need 'more power' to do anything useful.