CHFI Application, Email and Cloud Forensics Practice Question
An investigator examining a compromised web server finds a file named shell.aspx in the uploads directory. The file contains code that accepts commands via HTTP POST and executes them on the server. What is the MOST likely type of attack?
⚠ Common exam trap
EC-Council often tests the distinction between attacks that involve direct server-side code execution (webshell) versus attacks that manipulate other systems or users (SSRF, CSRF) or exploit database layers (SQL injection), so candidates must focus on the presence of an uploaded executable script file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Webshell
The file shell.aspx contains code that accepts commands via HTTP POST and executes them on the server, which is the classic definition of a webshell. A webshell is a malicious script uploaded to a web server that provides an attacker with remote command execution capabilities, often used for persistence and post-exploitation activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server-side request forgery (SSRF)
Why it's wrong here
SSRF tricks the server into making requests to internal or external resources; it does not write an executable web shell. It is correctly identified when logs show the server being induced to fetch attacker-chosen URLs.
- ✗
SQL injection
Why it's wrong here
SQL injection targets database queries through unsanitised input; it does not place an executable file on the web server. The shell.aspx file accepting POST commands and executing them is a web shell, typically planted after remote code execution or file-upload exploitation. SQL injection would be correct for database manipulation.
- ✓
Webshell
Why this is correct
A webshell is a script uploaded to a web server that accepts commands over HTTP and executes them on the host, giving the attacker remote control. The .aspx extension and POST-based command execution match this pattern exactly.
- ✗
Cross-site request forgery (CSRF)
Why it's wrong here
CSRF forges authenticated requests from a victim's browser; it never executes OS commands on the server. The shell.aspx web shell accepts POST commands and runs them, which is remote code execution. CSRF is tempting because it also abuses HTTP requests, and would fit a scenario where state-changing actions are triggered without the user's intent.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.