Zero Day Attack Flashcards

1
Q

What is a Zero Day Attack ?

A

a Zero Day Attack is when a vulnerability is found and exploited that a vendor/defender of a given software is unaware of and is incredibly detrimental to the said software.

Think of something like attacking PayPal on Black Friday and just how incredibly detrimental that could be to their profits and to their customers.
Another very good example of this would be the exploits “Meltdown” and “Specter” used to attack Intel devices and cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

1st step:

A

The hacker discovers a vulnerability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

2nd step:

A

The hacker exploits the vulnerability before the vendor/defender discovers the vulnerability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

3rd step:

A

3rd step: Day Zero. The attack takes place (there’s probably a pretty decent amount of chaos at this point).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

4th step:

A

With all the chaos, the vendor has been made aware that there is an issue and begins to patch the vulnerability. (Keep in mind, the vendor will not ALWAYS patch the vulnerability. Older technology could still be massively in use, but the vendor does not find it within value to patch a vulnerability within an older product that they cannot easily turn a profit out of).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

5th and 6th step:

A

The vendor’s patch is created and the vendor’s patch is applied
- - - - - -
Keep in mind that there is significant frame of time between the time a patch is created and when it is applied where the vulnerability is still relevant and can be exploited.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly