Application Flashcards
Service Attacks
Flooding a target machine or resource with many requests to overload the system and prevent use of its resources
DoS - Denial of Service
Multiple different sources attack one victim.
DDoS - Distributed Denial of Service
The attacker alters the communication between two parties who believe that are directly communicating.
Man-in-the-middle
A program attempts to write more data than can be held in fixed block of memory.
Buffer overflow
Occurs from processing invalid data, inserts code into the vulnerable computer program and changes the course of execution.
Injection
Found in web applications, allows for an attacker to inject client side scripts in web pages
Cross-site scripting
XXS
Unauthorized commands are sent from a user that is trusted by the website and allows attackers to steal cookies and harvest passwords.
Cross-site request forgery
(XSRF)
An attack that exploits a vulnerability that allows them to gain access to resources that they normally would be restricted from accessing
Privilege escalation
The act of falsifying the IP-to-MAC address resolution system employed by TCP/IP
ARP poisoning
The amount of traffic sent by the attacker is originally small but then is repeatedly multiplied to place a massive strain on the victim’s resources, in an attempt to cause failure or malfunction.
Amplification
Type of attack that exploits vulnerabilities in the domain name system (DNS) to divert internet traffic away from legitimate servers and towards fake ones.
DNS poisoning
The act of changing the registration of a domain name with the permission of the victim.
Domain hijacking
A proxy trojan horse that infects web browsers and captures browser session data.
Man-in-the-browser
The aim is to exploit flaws or vulnerabilities in targeted systems that are unknown or undisclosed to the world in general. Meaning that there is no direct or specific defense to the attack; that puts most systems to become vulnerable assets at risk
Zero day
Network-based attack where a valid data transmission is rebroadcasted, repeated or delayed.
Replay