Soru

Zorluk: KolayHost, Network, and Architecture Vulnerabilities

A network administrator conducts a vulnerability assessment on a critical server and discovers that an unencrypted legacy service, Telnet (TCP port 23), is enabled for remote administrative access across the internal network. Which of the following primary vulnerabilities does this host configuration introduce?

  1. Transmission of administrative authentication credentials in cleartext across the networkCevap
  2. B
    Susceptibility of backend databases to Cross-Site Scripting (XSS) script execution
  3. C
    Inability of edge firewalls to inspect internal perimeter trust boundaries
  4. D
    Failure of network-level firewall filtering rules to prevent host memory buffer overflows

Cevap

Transmission of administrative authentication credentials in cleartext across the network
Telnet communicates in cleartext without cryptographic protection. Anyone performing packet analysis on the local network segment can easily read administrative credentials and session commands, exposing the host and network to unauthorized access.

Adım Adım Çözüm

1
Analyze the service and port identified in the host assessment
Telnet operates over TCP port 23 as an unencrypted remote access protocol.
Identifying protocol security characteristics is required to assess vulnerability impact.
2
Determine the risk associated with unencrypted management traffic
All traffic, including usernames, passwords, and commands, is sent in plain text.
Unencrypted network communications expose session data to packet sniffing and eavesdropping.

Anahtar Kavram

Unencrypted Legacy Protocols and Network Host Vulnerabilities
Tahmini Süre:45s
Bu soruyu puanla