CHFI Application, Email and Cloud Forensics Practice Question
An incident responder is analyzing a compromised web server and finds a file named 'cmd.aspx' in the uploads directory. The file contains ASP.NET code that accepts commands via the 'cmd' parameter and executes them on the server. Which of the following best describes this artifact?
⚠ Common exam trap
The CHFI exam often tests the distinction between the artifact itself (webshell) and the method of compromise (e.g., SQL injection), so candidates may incorrectly choose option C because they focus on how the file got there rather than what the file is.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A webshell allowing remote command execution
The file 'cmd.aspx' is an ASP.NET webshell that accepts commands via the 'cmd' parameter and executes them server-side. This is a classic indicator of a webshell, which provides remote command execution (RCE) capabilities to an attacker, not a legitimate administrative tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A legitimate administrative tool for server management
Why it's wrong here
A legitimate administrative tool (e.g., Webmin, cPanel, or a custom management script) is typically installed outside the webroot, protected by authentication, and constrained to the host's administrative interfaces. It would not expose an unauthenticated HTTP endpoint that accepts raw operating-system commands via parameters. Moreover, legitimate tools are digitally signed, well-documented, and appear in system package logs, whereas the identified artifact shows classic webshell behavior: interactive command input with process execution.
- ✓
A webshell allowing remote command execution
Why this is correct
The file is a webshell because it accepts attacker-supplied input through HTTP parameters and passes it directly to a function such as system(), exec(), shell_exec(), or eval(). This provides unauthenticated remote command execution on the web server, allowing an attacker to run arbitrary commands, read sensitive files, or pivot to the internal network. The presence of obfuscated code, a small file size, and a recently modified timestamp in a writable web directory strongly corroborates this conclusion.
- ✗
A backdoor installed via a SQL injection vulnerability
Why it's wrong here
Although a SQL injection vulnerability can sometimes lead to a web shell if the database user has FILE privilege and can use SELECT ... INTO OUTFILE, the artifact in question is itself a command-execution script, not the injection technique. SQL injection primarily targets the database layer to exfiltrate data or manipulate queries; it does not directly produce an interactive command-execution file unless it is a multi-stage attack. The correct classification focuses on the file's function—arbitrary remote command execution—rather than the initial vector that may have placed it.
- ✗
A malware dropper for deploying ransomware
Why it's wrong here
A malware dropper is designed to silently install a secondary payload, such as ransomware, typically without an interactive command interface. The analyzed file, by contrast, executes commands dynamically based on input and produces output to the attacker, which is the signature behavior of a webshell, not a dropper. While a webshell could later be used to deploy ransomware, the file itself shows no evidence of encryption, file system traversal for target selection, or payload extraction—so classifying it as a dropper would misstate its role in the incident.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.