If you find the 111/TCP port open on a Unix system, what is the next logical step to take?
Port 111/TCP is the default port for the RPC (Remote Procedure Call) portmapper service on Unix systems, which registers and manages RPC services.
Why A is correct: Running rpcinfo -p <hostname> queries the portmapper to list all registered RPC services, their programs, versions, and associated ports. This is a logical next step during a security audit or penetration test to identify potential vulnerabilities (e.g., NFS or NIS services). CNSP recommends this command for RPC enumeration.
Why other options are incorrect:
B . Telnet to the port to look for a banner: Telnet might connect, but RPC services don't typically provide a human-readable banner, making this less effective than rpcinfo.
C . Telnet to the port, send 'GET / HTTP/1.0' and gather information from the response: Port 111 is not an HTTP service, so an HTTP request is irrelevant and will likely fail.
D . None of the above: Incorrect, as A is a valid and recommended step.
Sherron
3 months agoDesiree
3 months agoRasheeda
3 months agoBernardo
3 months agoMona
4 months agoYuonne
4 months agoRikki
4 months agoHildegarde
4 months agoKris
4 months agoHubert
5 months agoMarquetta
5 months agoShanda
5 months agoAmalia
5 months agoMertie
7 months agoElli
6 months agoThersa
7 months agoErick
6 months agoElroy
7 months ago