Certified Ethical Hacker (CEH) Practice Question

While testing a shared Linux hosting platform, you compromise SiteA and gain shell access as the Apache user (www-data). Each customer owns a separate directory under /home, but Apache is configured with FollowSymLinks and no SymLinksIfOwnerMatch restriction. Which attack would let you retrieve wp-config.php from a neighboring customer's directory without additional network exploits?

  • Launch an ARP poisoning attack on the hosting provider's switch to capture the neighbor's HTTP traffic.

  • Place a symbolic link in SiteA's web root that targets /home/otheruser/public_html/wp-config.php, then fetch it over HTTP.

  • Use SQL injection in SiteA to query the other customer's database for the file content.

  • Send a forged AXFR request to perform a DNS zone transfer from the neighbor's authoritative server.

Certified Ethical Hacker (CEH)
Web Application Hacking
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot