Test Prep Flashcards
Directory Traversal
Aims to access files and directories stored outside the webroot folder.
ARP Poisoning
This involves
Smurf
Uses a single ping with a spoofed address sent to the broadcast address of a network. This causes every device in the network to receive a single ping, each device responds to the spoofed address causing the victim to be overwhelmed with the responses to the ping.
Passive information gathering
penetration tester gathers publicly available info without the organization being aware that the info was accessed
Active information gathering
Starts top probe the organization using port scanning, vulnerability scanning etc that the organization can recognize.
Ping of Death
Involves sending a malicious ping to a computer
MITRE ATT&CK framework
provides explicit examples for detecting or mitigating a given threat within a network and ties specific behaviors back to individual actors
OpenIOC
Contains a depth of research on APTs but doesnt integrate the detection and mitigation strategy
Diamond Model of Intrusion Analysis
Provides a graphical depiction of the attackers approach relative to kill chain
Cain and Abel
Password cracking tool, also includes password decoding