ACRONYMS Flashcards
CIFS
Common Internet File System = Samba
111/tcp
RPC port
LLMNR
Link Local Multicast Name Resolution = host name to IP resolution Windows
BPDU
Bridge Protocol Data Unit = update frames multicast between switches
TTY
terminal shell
WAF
Web Application Firewall
SET
Social Engineering Toolkit
BeEF
Browser Exploitation Framework = social engineering
XOR
Exclusive OR = encryption
TKIP
Temporal Key Integrity Protocol
OSINT
open source intelligence gathering –> method of searching public records, social media, google etc.
WAF
web application firewall
ICS
industrial control systems
DAR
data at rest
SAST
static application security testing
ICS
Industrial Control System
CAPEC
MITRE’s Common Attack Pattern Enumeration & Classification
provides a dictionary of known patterns of attack
capec.mitre.org
NVD
National Vulnerability Database
Maintained by NIST
Full Disclosure is a public forum.
SoW
Statement of Work
plans the project-specific work to be done.
identifies the cope of work and testing to be completed.
OSINT
collection and analysis of data gathered from open sources
SCADA
Supervisory Control And Data Acquisition (SCADA) systems
DAR
data at rest
SAST
static application security testing
Static application security testing can be embedded directly within the development environment. This allows developers to track their code continuously. Scrum masters and product owners will also regulate secure coding best practices. This leads to rapid vulnerability reduction and improved code integrity and security.
DAST
Dynamic Application Security Testing
focuses on testing the application in run-time, and this is usually done using vulnerability scanners. While SAST focuses on creating and writing secure code, DAST focuses more on finding security flaws in the deployed application.
SOAP
Simple Object Access Protocol
a Connection or an interface between the web services or a client and web service. SOAP is operated with application layer protocols like HTTP, SMTP or even with the TCP for message transmission.
created from WSDL
WSDL
Web Service Description Language
XML based.
SOAP.
REST
representational state transfer
replacing SOAP in web applications
WADL
web application description language
XML based.
REST
XSD
XLM schema definition
LSASS
Local Security Authority Subsystem Service
windows security policy enforcement
verifies users at login
SPN
service principle names
are used to uniquely identify each instance of a Windows service
MSA
master service agreement - addresses high-level requirements for contract