Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

An investigator examining a compromised web server finds a file named shell.aspx in the uploads directory. The file contains code that accepts commands via HTTP POST and executes them on the server. What is the MOST likely type of attack?

⚠ Common exam trap

EC-Council often tests the distinction between attacks that involve direct server-side code execution (webshell) versus attacks that manipulate other systems or users (SSRF, CSRF) or exploit database layers (SQL injection), so candidates must focus on the presence of an uploaded executable script file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Webshell

The file shell.aspx contains code that accepts commands via HTTP POST and executes them on the server, which is the classic definition of a webshell. A webshell is a malicious script uploaded to a web server that provides an attacker with remote command execution capabilities, often used for persistence and post-exploitation activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Server-side request forgery (SSRF)

    Why it's wrong here

    SSRF tricks the server into making requests to internal or external resources; it does not write an executable web shell. It is correctly identified when logs show the server being induced to fetch attacker-chosen URLs.

  • ✗

    SQL injection

    Why it's wrong here

    SQL injection targets database queries through unsanitised input; it does not place an executable file on the web server. The shell.aspx file accepting POST commands and executing them is a web shell, typically planted after remote code execution or file-upload exploitation. SQL injection would be correct for database manipulation.

  • ✓

    Webshell

    Why this is correct

    A webshell is a script uploaded to a web server that accepts commands over HTTP and executes them on the host, giving the attacker remote control. The .aspx extension and POST-based command execution match this pattern exactly.

  • ✗

    Cross-site request forgery (CSRF)

    Why it's wrong here

    CSRF forges authenticated requests from a victim's browser; it never executes OS commands on the server. The shell.aspx web shell accepts POST commands and runs them, which is remote code execution. CSRF is tempting because it also abuses HTTP requests, and would fit a scenario where state-changing actions are triggered without the user's intent.

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.