How would you judge if a remote server is running IIS or Apache?
Answers were Sorted based on User's Feedback
Answer / chaitanya
Error messages oftentimes giveaway what the server is running, and many times if the website administrator has not set up custom error pages for every site, it can give it away as simply as just entering a known bad address. Other times, just using telnet can be enough to see how it responds. Never underestimate the amount of information that can be gained by not getting the right answer but by asking the right questions.
| Is This Answer Correct ? | 5 Yes | 0 No |
Answer / gaurav
Penetration testing techniques can easily reveal from a website which of the ports, operating systems and web servers are running. For Instance, Nikto and Owasp-Zed are two methods of doing this.
| Is This Answer Correct ? | 1 Yes | 0 No |
If you were going to break into a database-based website, how would you do it?
Does indexing slow down computer?
What is database in a computer?
How would you compromise an “Office Workstation” at a hotel?
What is a spooler on a computer?
You are an employee for a tech department in a non-management position. A high-level executive demands that you break protocol and allow him to use his home laptop at work. What do you do?
You find out that there is an active problem on your network. You can fix it, but it is out of your jurisdiction. What do you do?
1. Assume that passwords are selected from four-character combination of 26 alphabetic characters. Assume that an adversary is able to attempt passwords at a rate of one per second. a. Assuming no feedback to the adversary until each attempt has been completed, what is the expected time to recover the correct password? b. Assuming feedback to the adversary flagging an error as each incorrect character is entered, what is the expected time to discover the correct password?
How would you login to Active Directory from a Linux or Mac box?
Why would you bring in an outside contractor to perform a penetration test?
What is a table in computer?
Why are internal threats oftentimes more successful than external threats?