312-50 exam dumps

312-50 practice question 334 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 334

Single answer▪ Attack Shared Environments

During an authorized assessment of a company that runs several web applications on the same Linux-based shared hosting server, you discover that one application allows arbitrary file upload and local code execution under the web server account. The client wants to understand the most realistic next step an attacker would take to compromise other applications hosted on the same server without immediately exploiting a kernel vulnerability. Which action would best demonstrate an attack against the shared environment?

  1. A

    Attempt to read configuration files, session files, and application data belonging to other hosted sites that are accessible due to weak file permissions or shared directories

  2. B

    Launch an ARP spoofing attack against the hosting provider's top-of-rack switch from the compromised web application

  3. C

    Exploit a Bluetooth pairing flaw on administrator laptops connected to the hosting environment

  4. D

    Perform a DNS cache poisoning attack against public recursive resolvers used by the hosting provider

Show answer and explanation

Correct answer: A

Explanation

This question focuses on attacking shared environments, where the primary risk is inadequate isolation between tenants, applications, or workloads using the same underlying resources. In traditional shared hosting, a compromise of one web application often leads attackers to inspect local files, credentials, temporary directories, session storage, backups, and application configuration files belonging to other hosted sites. This is especially effective when permissions are overly broad, directories are shared, or the web server account can access multiple sites' content.

From a CEH perspective, the candidate should recognize that attacks against shared environments commonly exploit misconfigurations in segregation rather than immediately relying on advanced privilege-escalation exploits. Real-world best practices from Linux hardening guidance and common web hosting security recommendations emphasize strict file permissions, per-site account separation, least privilege, isolated PHP-FPM or application pools, containerization or VM isolation where appropriate, and restricting access to session and temporary storage. The key lesson is that once code execution is achieved in one tenant, the next practical step is often to test whether neighboring tenants are exposed through weak local isolation.

  • A. Correct.

    Correct. In a shared hosting environment, multiple applications or tenants often reside on the same operating system and may share web server processes, temporary storage locations, or poorly segregated file paths. If one site is compromised and file permissions are weak, an attacker commonly attempts lateral access by reading other tenants' configuration files, credentials, session data, backups, or database connection strings. This is a classic attack against a shared environment because it abuses insufficient isolation between co-hosted applications rather than requiring a kernel-level escape.

  • B. Incorrect.

    Incorrect. ARP spoofing is a Layer 2 network attack relevant on the same broadcast domain, but it is not the most direct or realistic next step from a compromised web application in a shared hosting scenario. A typical attacker first tests local tenant-to-tenant isolation failures such as world-readable files, shared directories, or insecure permissions. In many hosted environments, the attacker would not have the network position or privileges needed to meaningfully attack the provider's switching infrastructure from a web application account.

  • C. Incorrect.

    Incorrect. A Bluetooth attack on administrator laptops is unrelated to the immediate objective of abusing the shared hosting environment. While endpoint attacks can occur in broader threat campaigns, this option does not demonstrate compromise of co-located tenants on the same server through weaknesses in shared resources or isolation boundaries.

  • D. Incorrect.

    Incorrect. DNS cache poisoning targets name resolution infrastructure, not the local separation between applications sharing the same host. Although DNS attacks can redirect traffic, they do not represent the most realistic follow-on action for compromising neighboring applications after gaining code execution in one shared-hosted web application.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam