PT0-002 Exam Question 26

A penetration tester finds a PHP script used by a web application in an unprotected internal source code repository. After reviewing the code, the tester identifies the following:

Which of the following combinations of tools would the penetration tester use to exploit this script?
  • PT0-002 Exam Question 27

    A penetration tester is conducting a penetration test. The tester obtains a root-level shell on a Linux server and discovers the following data in a file named password.txt in the /home/svsacct directory:
    U3VQZXIkM2NyZXQhCg==
    Which of the following commands should the tester use NEXT to decode the contents of the file?
  • PT0-002 Exam Question 28

    Which of the following assessment methods is MOST likely to cause harm to an ICS environment?
  • PT0-002 Exam Question 29

    During a penetration test, a tester is able to change values in the URL from example.com/login.php?id=5 to example.com/login.php?id=10 and gain access to a web application. Which of the following vulnerabilities has the penetration tester exploited?
  • PT0-002 Exam Question 30

    Which of the following types of information should be included when writing the remediation section of a penetration test report to be viewed by the systems administrator and technical staff?