CEH Exam 2 Lab Review Questions And 100%
Correct Answers
8.1.4 Describe an attack by USB keylogger
The CEO of CorpNet.xyz has hired your company to obtain some passwords in a not very
nice way for the company. A senior IT network administrator named Oliver Lennon
suspects that he will be fired from the company. He changed many of the standard
passwords known to only the top executives, and now he is the only one who knows
them. Your company has completed all the legal documents that would help in
protecting you and the company.
You were granted, after hours, into the IT Admin's office using an executive from
CorpNet.xyz. You had unplugged the keyboard from the back of the ITAdmin computer,
placed a USB keylogger into the USB, and then plugged in the USB keyboard to the
keylogger. After one week the company executive lets you back into the IT Admin's
office after hours again.
After viewing Lab - Keylogger, Recovery of Changed Passwords Complete the following
passwords that have been changed using the keylogger: Move - ANSWER Solution
Above the computer, click Back to show the rear of the computer.
On the back of the computer, drag the USB Type A connector for the keyboard to
another USB port on the computer.
Do not forget to attach the keyboard.
On the Shelf, click the > to expand System Cases.
Drag the Laptop to the Workspace.
,Click Back above the laptop to go to the back of the laptop.
From the computer, obtain the keylogger and place it into one of the USB ports of the
laptop
Above the laptop, click Front to go to the front of the laptop
On the laptop, click to show Windows 10.
Click S + B + K to toggle out of the view for the keylogger and into the view for the flash
drive.
Tap to choose what happens with removable drives.
Select Open folder to view files.
Double-click LOG.txt to open the file.
In the upper right, select Answer Questions
Answer the questions.
Select Score Lab.
Question 1: P@ssw0rd
Question 2: 4Lm87Qde
8.1.5 Analyze a USB keylogger attack 2
Recently an administrative assistant found a foreign device attached to the ITAdmin
computer while performing some hardware upgrades. The device was turned over to
you, and you determined it was a keylogger. You will now sift through the information on
the keylogger to determine which accounts could be compromised.
Assignment
, In this lab you will determine what corporate accounts have been compromised by
following these steps:
Connect the USB keylogger to the USB port of ITAdmin.
Use the keyboard shortcut of SBK to change the mode of the USB keylogger from
keylogger to USB flash drive mode
Open the LOG.txt file and study its contents.
Look for corporate passwords or financial information in the document.
Questions - Solutions
1. On the Shelf, open Storage Devices.
2. From the shelf, drag the USB Keylogger onto a USB port on ITAdmin.
3. In the monitor, select Click to view Windows 10.
4. Type in S + B + K and switch the keylogger mode with the flash drive mode.
5. Select Tap to choose what happens with removable drives.
6. Click Open folder to view files.
7. Double click LOG.txt to open it.
8. Max the window for a clearer viewing.
9. At the top right, click Answer Questions.
10. File open and look for captured account passwords
11. File open and look for financial information.
12. Select Score Lab.
Question 1: email.com, amazon.com
Question 2: 4556358591800117
8.1.7 Password cracking using rainbow tables
While doing some penetration testing for your company, you captured a number of
Correct Answers
8.1.4 Describe an attack by USB keylogger
The CEO of CorpNet.xyz has hired your company to obtain some passwords in a not very
nice way for the company. A senior IT network administrator named Oliver Lennon
suspects that he will be fired from the company. He changed many of the standard
passwords known to only the top executives, and now he is the only one who knows
them. Your company has completed all the legal documents that would help in
protecting you and the company.
You were granted, after hours, into the IT Admin's office using an executive from
CorpNet.xyz. You had unplugged the keyboard from the back of the ITAdmin computer,
placed a USB keylogger into the USB, and then plugged in the USB keyboard to the
keylogger. After one week the company executive lets you back into the IT Admin's
office after hours again.
After viewing Lab - Keylogger, Recovery of Changed Passwords Complete the following
passwords that have been changed using the keylogger: Move - ANSWER Solution
Above the computer, click Back to show the rear of the computer.
On the back of the computer, drag the USB Type A connector for the keyboard to
another USB port on the computer.
Do not forget to attach the keyboard.
On the Shelf, click the > to expand System Cases.
Drag the Laptop to the Workspace.
,Click Back above the laptop to go to the back of the laptop.
From the computer, obtain the keylogger and place it into one of the USB ports of the
laptop
Above the laptop, click Front to go to the front of the laptop
On the laptop, click to show Windows 10.
Click S + B + K to toggle out of the view for the keylogger and into the view for the flash
drive.
Tap to choose what happens with removable drives.
Select Open folder to view files.
Double-click LOG.txt to open the file.
In the upper right, select Answer Questions
Answer the questions.
Select Score Lab.
Question 1: P@ssw0rd
Question 2: 4Lm87Qde
8.1.5 Analyze a USB keylogger attack 2
Recently an administrative assistant found a foreign device attached to the ITAdmin
computer while performing some hardware upgrades. The device was turned over to
you, and you determined it was a keylogger. You will now sift through the information on
the keylogger to determine which accounts could be compromised.
Assignment
, In this lab you will determine what corporate accounts have been compromised by
following these steps:
Connect the USB keylogger to the USB port of ITAdmin.
Use the keyboard shortcut of SBK to change the mode of the USB keylogger from
keylogger to USB flash drive mode
Open the LOG.txt file and study its contents.
Look for corporate passwords or financial information in the document.
Questions - Solutions
1. On the Shelf, open Storage Devices.
2. From the shelf, drag the USB Keylogger onto a USB port on ITAdmin.
3. In the monitor, select Click to view Windows 10.
4. Type in S + B + K and switch the keylogger mode with the flash drive mode.
5. Select Tap to choose what happens with removable drives.
6. Click Open folder to view files.
7. Double click LOG.txt to open it.
8. Max the window for a clearer viewing.
9. At the top right, click Answer Questions.
10. File open and look for captured account passwords
11. File open and look for financial information.
12. Select Score Lab.
Question 1: email.com, amazon.com
Question 2: 4556358591800117
8.1.7 Password cracking using rainbow tables
While doing some penetration testing for your company, you captured a number of