{ "@context": "https://schema.org", "@type": "Organization", "name": "Brainscape", "url": "https://www.brainscape.com/", "logo": "https://www.brainscape.com/pks/images/cms/public-views/shared/Brainscape-logo-c4e172b280b4616f7fda.svg", "sameAs": [ "https://www.facebook.com/Brainscape", "https://x.com/brainscape", "https://www.linkedin.com/company/brainscape", "https://www.instagram.com/brainscape/", "https://www.tiktok.com/@brainscapeu", "https://www.pinterest.com/brainscape/", "https://www.youtube.com/@BrainscapeNY" ], "contactPoint": { "@type": "ContactPoint", "telephone": "(929) 334-4005", "contactType": "customer service", "availableLanguage": ["English"] }, "founder": { "@type": "Person", "name": "Andrew Cohen" }, "description": "Brainscape’s spaced repetition system is proven to DOUBLE learning results! Find, make, and study flashcards online or in our mobile app. Serious learners only.", "address": { "@type": "PostalAddress", "streetAddress": "159 W 25th St, Ste 517", "addressLocality": "New York", "addressRegion": "NY", "postalCode": "10001", "addressCountry": "USA" } }

A3 - Sensitive Data Exp Flashcards

(4 cards)

1
Q

Data Exposure

A

Preisgabe sensibler Daten durch fehlende/unzureichende verschlüsselung, Verwendung von PW-Hashes ohne Salt, Ausgabe von sensiblen Infos

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Heartbleed

A

Erlaubt einem Angreifer einen zufälligen Speicherbreich des Server-Prozesses auszulesen (information disclosure). Ermöglichst durch Schwachstelle in bestimmten OpenSSL-Versionen Zugriff auf Session Tokens, PW oder Schlüsselmaterial

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Wofür SSL

A

Authentizität (durch Zertifikate)
Integrität (Prüfsumme, durch MAC)
Vertraulichkeit (Verschlüsselung)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Mögl Schwachstellen in SSL Konfig

A
  • nicht vertrauenswürdiges Zert.
  • veraltetes Zert
  • falsches Zert
  • Unterstützung von SSLv2
  • Unterstützung kurzer Schlüssellämgen, unsicherer Chiffren
  • Kompression vor Verschlüsselung
  • Veraltete Komponenten
How well did you know this?
1
Not at all
2
3
4
5
Perfectly