4.4 Flashcards
Whats DoS?
(Denial of service) It forces a service to fail and cause a system to be unavailable.
Whats DDoS?
(Distributed Denial of Service) It’s a launch of an army of computers to bring down a service(use all bandwidth or resources and it’s the reason bad guys use botnets.)
Whats DDoS amplification?
Turning a small attack into a big attack and uses protocols with little authentication or checks(like NTP, DNS, ICMP)
What are social engineering principles?
- Authority(social engineer is in charge)
- Intimidation(there will be bad things if you dont help)
- Consensus/Social proof(Convince based on whats normally expected.
- Scarcity(the situation will not be this way for long)
- Urgency(act quick, don’t think)
- Familiarity/liking(we have common friends)
- Trust(someone who is safe like from IT)
Whats Insider threats?
IT happens when we give people tons of access they shouldn’t have. But sometimes it could be phishing scams or hacking scams.
What are logic bombs?
A logic bomb is a very specific kind of malware that’s waiting for an event to occur(usually time, user event) and difficult to identify.
Whats rouge access point
It’s a significant potential backdoor(huge security concerns) and they are very easy to plug in a wireless AP, or enable wireless sharing in your OS.
What are wireless evil twins?
By using a wireless access point, the bad guys can configure it exactly the same way as an existing network(same SSID and security settings) WiFi hotspots are easy to feel(wifi in a hotel) and can be countered if you encrypt your communication by using HTTPS and a VPN.
Whats Wadriving?
Gathering information about your network(huge amount of intel in a short period of time)
Whats Phishing?
Phishing is a technique used by the bad guys to try to convince you to give up some personal information.(like username and password)
Whats Vishing?
It’s phishing thats done over the phone(fake security check)
Whats spear phishing?
it’s a way to really focus in on a narrow group of people and try to construct a front-end and a message that seems very legitimate to the end user.
Whats ransomware?
It’s one where the bad guys want your money, and the best way to get the money from you is to take the data away from you.
Whats crypto-malware?
This is ransomware that encrypts all of the data on your computer and holds that data for ransom.
how can we protect against ransomware?
- Always having a backup
- Keep your system up-to-date
- Keep your applications up-to-date
- Keep your anti-virus/anti-malware signatures up-to-date.
- Keep everything up-to-date