SECFND 7: Network App Attacks Flashcards

1
Q

Fast Flux

A

have numerous IP addresses that are associated with a single fully qualified domain name, where the IP addresses are changed with extremely high frequency by changing DNS A records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Double IP flux

A

rapidly change both the hostname to IP address mappings, and also the authoritative name server using the DNS name server resource records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Domain Generation Algorithm (DGA)

A

Randomly generated domain names often used in CnC or malware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

XSS

A

injection of malicious scripts into web pages that are executed on the client-side. Lack of input validation. Often delivered via phishing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Stored XSS

A

Most dangerous. Stored on infected server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Reflected XSS

A

Most common. User clicks malicious link.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

XSS exploits trust in

A

Users trust in a particular website

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CSRF exploits trust in…

A

Website trust in a users browser

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Homoglyph

A

text characters that have shapes which are identical or similar to each other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly