CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium
A security analyst is investigating a suspected data exfiltration incident from an internal Linux server. The analyst suspects that an attacker may have used a common network utility to establish a reverse shell for data transfer. Which of the following log snippets would be the MOST indicative of this activity?
- ADec 10 09:36:15 webserver kernel: nf_conntrack: table full, dropping packet.
- BDec 10 09:38:20 webserver httpd[9101]: client 10.0.0.5 GET /index.php HTTP/1.1
- CDec 10 09:37:05 webserver bash[5678]: CMD (nc -lp 4444 -e /bin/bash)
- DDec 10 09:35:01 webserver sshd[1234]: Accepted password for user from 192.168.1.10 port 54321 ssh2
Show answer & explanationAnswer & explanation
Correct answer: C. Dec 10 09:37:05 webserver bash[5678]: CMD (nc -lp 4444 -e /bin/bash)
The log snippet showing 'nc -lp 4444 -e /bin/bash' directly indicates the execution of Netcat to listen on port 4444 and execute a bash shell, which is a classic method for establishing a reverse shell for unauthorized access and data exfiltration.
Why the other options are wrong
- A. This indicates a network connection tracking issue, potentially due to high traffic or misconfiguration, but not direct evidence of a reverse shell.
- B. This shows a standard HTTP GET request to a web server, which is normal web traffic and not indicative of a reverse shell.
- D. This indicates a successful SSH login, which is normal behavior for system administration, not necessarily a reverse shell.
Reverse Shell Detection
A reverse shell is a type of shell session where the target machine initiates the connection back to the attacker's machine, often used for bypassing firewalls and gaining remote control.
- Attacker listens for incoming connections.
- Victim machine connects out to the attacker.
- Commonly uses utilities like Netcat (nc) or Python/Perl scripts.
Memory trick: The 'Netcat' fish caught the 'Shell' hook from the 'Server' line.