Chapter 13 - Social Engineering & Pen Test Flashcards
Spear Phishing
Targeting a person or a group with a phishing attack
Whaling
going after CEOs or other C-level Executives
Pharming
use of malicious code that redirects a user’s traffic
Spimming
sending spam over instant message
Netcraft Toolbar
Phishing tool
PhishTank Toolbar
Phishing tool
Fave Antivirus
very prevalent attack; pretends to be anti-virus but is malicious
Mobile-based attack - ZitMo
Zeus in the Mobile - banking malware that was ported to Android
Security Assessment
Test perfromed in order to assess the level of security on a network or system
Security Audit
Policy and procedure focused; tests whether organization is following specific standards and policies
Vulnerability Assessment
Scans and tests for vulnerabilities but does not intentionally exploit them.
Pen Test - External Assessment
Analyzes publicly available information; conducts network scanning, enumeration and testing from the network perimeter.
Pen Test - Internal Assessment
Performed from within the organization, from various network access points.
Red Team vs Blue Team
Red Team - Pen Test team that is doing the attacking. Blue Team - Pen test team that is doing the defending
Purple Team
Pen test team that is doing both attacking and defending