A forensic analyst suspects that a buffer overflow exists in a kernel module. The analyst executes the following command:
However, the analyst is unable to find any evidence of the running shell.
Which of the following of the MOST likely reason the analyst cannot find a process ID for the shell?
A. The NX bit is enabled
B. The system uses ASLR
C. The shell is obfuscated
D. The code uses dynamic libraries
A forensic analyst suspects that a buffer overflow exists in a kernel module. The analyst executes the following command
-
answerhappygod
- Site Admin
- Posts: 899604
- Joined: Mon Aug 02, 2021 8:13 am
A forensic analyst suspects that a buffer overflow exists in a kernel module. The analyst executes the following command
Join a community of subject matter experts. Register for FREE to view solutions, replies, and use search function. Request answer by replying!