13.2 Flashcards
Baseline Configuration Purpose
Maintain consistent level of security; Help mitigate flaws and security risks.
Causes of Privilege Escalation
Error by administrator; weak passwords; bad coding in software.
Baseline Accounts
Minimum 2 accounts; administrator and user.
4 Security Baseline Settings
- Minimum Password Length
- Account lockout duration
- Disabling unnecessary services
- “Allow administration by” option
Remote Access Trojan
A remote access Trojan provides full or partial access to the victim’s system
Data Sending Trojan
This type sends data such as key strokes, passwords, or cookies to the attacker via email or a back door
Destructive Trojan
These types cause havoc like deleting files, corrupting the OS, or crashing the entire system. Usually the purpose is to disable an antivirus or firewall
Proxy Trojans
This sort of Trojan is used as a jumping point for an attack on another system in order to mask the attacker’s identity.
Goal of Denial of Service
Deny legitimate users from accessing information or services.
Signs of DoS
unusually slow network
unavailability of particular website
dramatic increase of spam mail
Session Hijacking
Exploits the session between devices; must be on the same network.
Session Hijacking Prevention
Encryption, Secure Protocols, Limit Incoming Connections, Minimize Remote Access, Strong Authentication, Using Switches instead of Hubs, User Training