Attacks Flashcards
Denial of Service Attack
In a DoS attack, a hacker overloads a specific server with so much data that the server is too busy to service valid requests coming from real clients on the network.
(SYN) flood (DoS)
“SYN is an aspect of TCP/IP that allows systems to synchronize with each other while communicating. One system sends a SYN packet that is acknowledged by another system. The target system then waits for another acknowledgement from the sender. This process can be abused by a malicious hacker by sending forged SYN packets to a host that is unable to reply to the request because the return address is incorrect. This causes the host to halt communications while waiting for the other system to reply. overloaded and unable to respond to legitimate requests. If the host is flooded with a high number of forged SYN packets, it will be This process can be abused by a malicious hacker by sending forged SYN packets to a host that is unable to reply to the request because the return address is incorrect. This causes the host to halt communications while waiting for the other system to reply. overloaded and unable to respond to legitimate requests.
If the host is flooded with a high number of forged SYN packets, it will be
Back Door
“A back door is traditionally defined as a way for a software programmer to access a program while bypassing its authentication schemes.
In hacking terms, a back door is a program secretly installed on an unsuspecting user?s computer so the hacker can later access the user?s computer, bypassing any security authentication systems.”
Back Door Mitigation
Anti-virus programs can detect the presence of back-door programs. Personal firewalls can also detect suspicious incoming and outgoing network traffic from a computer. Port-scanning software can also be used to identify any open ports on the system, including those you do not recognize. These open ports can be cross-referenced with lists of ports used by known back-door programs.
Blue jacking
Blue jacking is the sending of unsolicited messages (think spam) over the Bluetooth connection
Bluesnarfing
Bluesnarfing is the gaining of unauthorized access through a Bluetooth connection. This access can be gained through a phone, PDA, or any device using Bluetooth. Once access has been gained, the attacker can copy any data in the same way they would wi
Cross-site scripting (XSS)
is a type of computer security vulnerability typically found in web applications which enable malicious attackers to inject client-side script into web pages viewed by other users. An exploited cross-site scripting vulnerability can be used by attackers to bypass access controls such as the same origin policy. Cross-site scripting carried out on websites were roughly 80% of all security vulnerabilities documented by Symantec as of 2007
Data emanation
as unprotected and unsecured wireless communications can be easily intercepted and an unauthorized user can steal user names and passwords and sensitive private data. All information on an unsecured WLAN is transmitted in clear text, and any wireless user can use a protocol analyzer or sniffer application to view the data traversing the WLAN. All WLANs should communicate using secure encrypted channels to prevent eavesdropping from unauthorized users.
DNS Poisoning
“The DNS poisoning technique takes advantage of a DNS server?s tables of IP addresses and host names by replacing the IP address of a host with another IP address that resolves to an attacker?s system.
For example, a malicious user can masquerade her own web server by poisoning the DNS server into thinking that the host name of the legitimateweb server resolves to the IP address of the rogue web server. The attacker can then spread spyware, worms, and other types of malware to clients connecting to her web server. This type of attack has a great potential for damage, as several thousand clients can be using the DNS server or its cache of IP addresses and host names, and all of themwill be redirected to the poisoned address in the DNS cache tables.
The malicious attacker can perform this attack by exploiting vulnerabilities in a DNS server that does not perform authentication or any type of checks to ensure the DNS information is coming froman authentic source. This information can be passed fromone DNS server to another, almost like a worm, and the rogue address can be quickly spread.
DNS poisoning attacks can be mitigated by ensuring that your DNS sever updates its information only from authoritative sources by proper authentication or the use of secure communications.MostDNSsoftware has been updated to prevent these types of attacks, and typically only out-of-date DNS software is vulnerable to DNS poisoning.
”
DNS Poisoning Mitigation
DNS poisoning attacks can be mitigated by ensuring that your DNS server updates its information only from authoritative sources by proper authentication or the use of secure communications. Most DNS software has been updated to prevent these types of attacks, and typically only out-of-date DNS software is vulnerable to DNS poisoning.
Domain Kiting
refers to the practice of registering a domain name, then deleting the registration after the five-day grace period, and then re-registering it to start another five-day grace period. This results in the domain being registered to the user without his having to pay for the registered domain.
Dynamic NAT
Provides a pool of various external IP addresses that can be used when an internal client wants to access something externally. Dynamic NAT helps in environments that have only a limited amount of external addresses to use and not all of the clients are going to be active at the same time
Extranet
“An extranet is an extension of your private network or intranet.
An extranet extends outside the body of your local network to enable other companies or networks to share information. For example, an automobile manufacturing company could have an extranet that connects selected business partners, so they can access and share specific information on availability and inventories between the networks. These are often referred to as business-to-business (B2B) communications or networks because one company uses the internal resources and services of another.”
MAC address-based VLAN
“Tracks clients and their respective VLAN memberships through the MAC address of their network card. The switches maintain a list of MAC addresses and VLAN membership, and they route the network packets to their destinations, as appropriate.
The advantage of MAC address-based VLANs is if their VLAN membership changes, they needn?t be physically moved to another port. One drawback of this method is that being part of multiple VLANs can cause confusion with the switch?s MAC address tables. This model is recommended for single VLAN memberships. “
Man-in-the-middle (MITM) bucket-brigade attack, or sometimes Janus attack
Man-in-the-middle Mitigation
“To prevent man-in-the-middle attacks, a unique server host key can be used to prove its identity to a client as a known host. This has been implemented in newer versions of the SSH protocol, which was vulnerable to man-in-the-middle attacks in the past.
“