2.4 Flashcards
(23 cards)
How is phising usually delivered ?
Phone, sms or email
What is phishing ?
Social engineering with a touch of spoofing.
What is a good indication of phishing ?
Provided URL, dodgy font, graphics or spelling.
What is Vishing ?
Vishing is done over phone (basically Caller ID is spoofed).
Give an example of Vishing
Fake security checks or bank updates
What is Wireless evil twins ?
Fraudulent Wi-Fi access point that appears to be legitimate but is set up to eavesdrop on wireless communications
What is spear phishing ?
Going for a specific groups of users.
What is a good resource for monitoring zero-day attacks ?
Checking hacker forums/websites
What is spoofing ?
Masquerading as another user or device
Give some examples of spoofing
Faking a Legitimate:
IP address.
MAC address.
Username/password.
What is the result of a Structured Query Language (SQL) injection ?
Attacker gains acces to a database.
What is good practice in preventing a wireless evil twin ?
Encrypt i.e. https and a VPN
What does a anti-DDoS system do ?
Filter out traffic by looking for patterns associated with DDoS attacks.
What are the two kinds of on path attacks ?
Network and browser
https://www.youtube.com/watch?v=pY20_7l8AKc
ARP
Address Resolution Protocol
What is a SQL injection ?
A web application security vulnerability that allows an attacker to inject malicious code into a SQL statement through user input.
What is the difference between adware and spyware ?
Adware to generates revenue through the display of advertisements
Spyware is designed to collect sensitive information without the user’s knowledge or consent.
What is ARP spoofing ?
MAC address is faked.
What is an insider threat ?
Any current or former employee, contractor, or business partner who has or had authorized access and misused said access.
What is phishing over sms sometimes referred to as ?
Smishing
What is arp spoofing ?
Attacker spoofs the IP to MAC mapping usually to perform a man-in-the-middle attack
What kind of attack is IP spoofing ?
On path attach
What is arp poisoning ?
Sending fake ARP packets that link an attacker’s MAC address with an IP of a computer already on the LAN.