IAS Prelims Part 2

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/103

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:27 PM on 9/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

104 Terms

1
New cards

bluetooth

a wireless technology that allows devices to share data over short distances, and is vulnerable to various types of atacks

2
New cards
  • discoverable

  • limited discoverable

  • non-discoverable


bluetooth operates in the following 3 discoverable modes:

3
New cards

discoverable

a bluetooth discoverable mode, devices are visible to other bluetooth-enabled devices. is necessary only while connecting to a device for the first time, since upon saving the connecting, the devices remember each other

4
New cards

limited discoverable

a bluetooth discoverable mode, devices are discoverable only for a limited period, for a specific event, or during temporary conditions. filters out non-matched IACs and reveals itself only to those that matched

had no host controller interface (HCI) to set a device directly in the limted discoverable mode, and a user has to do this indirectly

5
New cards

non-discoverable

a bluetooth discoverable mode, prevents the device from appearing on the list during a bluetooth-enabled device search process. remains visible to users and devices that were previously paired with it or know its MAC address

6
New cards

bluetooth hacking

the exploitation of bluetooth stack implementation vulnerablities to compromise sensitive data in bluetooth-enabled devices and networks

7
New cards

piconets

bluetooth-enabled devices connect and communicate wirelessly through ad-hoc networks known as what?

8
New cards

bluesmacking

a bluetooth device attack, occurs when an attacker sends an oversized ping packet to a victim’s device, causing a buffer overflow. similar to ICMP ping of death attack

9
New cards

bluejacking

a bluetooth device attack, the use of bluetooth to send messages to users without the recipient’s consent, similar to email spamming. does not cause any damage but is disruptive to the victims

10
New cards

bluesnarfing

a bluetooth device attack, method of gaining access to sensitive data in a bluetooth enabled device.

11
New cards

bluesniff

a bluetooth device attack, a proof-of-concept code for a bluetooth wardriving utility, useful for finding hidden and discoverable bluetooth devices and operates on linux

12
New cards

bluebugging

a bluetooth device attack, attacker gains remote access to a target bluetooth-enabled device without the victim’s awareness. attacker sniffs information and might perform malicious activities such as interpreting and forwarding phone calls and messages

13
New cards

blueprinting

a bluetooth device attack, performed to determine the make and model of a target bluetooth-enabled device. attacker collects info to creat infographics of the model, manufacturer, etc. to analyze for vulnerabilities

14
New cards

btlejacking

a bluetooth device attack, detrimental to bluetooth low energy (BLE) devices. attacker can sniff and take control of data transmission between BLE devices by performing MITM attack

15
New cards

key negotiation of bluetooth (KNOB) attack

a bluetooth device attack, enables attacker to breach bluetooth security mechanisms and perform and MITM attack on paired devices without being traced. detrimental to 2 bluetooth enabled devices sharing encrypted keys

16
New cards

MAC spoofing attack

a bluetooth device attack, passive attack in which attackers spoof the MAC address of a target bluetooth enabled device to intercept or manipulate the data sent to the target device

17
New cards

man in the middle/impersonation attacks

a bluetooth device attack, attackers manipulate the data transmitted between devices communicating via a bluetooth connection (piconet). devices intended to pair with one another unknowingly pair with the attacker’s device

18
New cards

cisco adaptive wireless intrusion detection system

offers advanced network security for dedicated monitoring and detection of wireless network anomalies, unauthorized access, and RF attacks

19
New cards
  • AirMagnet WiFi analyzer PRO

  • RFProtect

  • WatchGuard WIPS

  • AirMagnet Planner

  • Extreme AirDefense


these are 5 additional wireless security tools

20
New cards

AirMagnet WiFi Analyzer PRO

an additional wireless security tools, professional tool that audits network performance, detects connectivity issues, and identifies security vulnerabilties in real time

21
New cards

RFProtect

an additional wireless security tools, Aruba Networks’ built-in WIPS that protects against rogue APs, MITM attacks, and unauthorized WiFi devices

22
New cards

WatchGuard WIPS

an additional wireless security tools, provides continuous monitoring, rogue AP detection, and automated wireless threat mitigation

23
New cards

AirMagnet Planner

an additional wireless security tools, allows network engineers to design optimal wireless coverage, predict signal strength, and plan AP placement before deployment

24
New cards

Extreme AirDefense

an additional wireless security tools, enterprise-grade WIPS and wireless monitoring platform that provides centralized detection, alerting, and response to wireless threats

25
New cards

phishing

a browser-based attack, redirects users to fake web pages that mimic trustworthy sites, asking them to submit their personal information

26
New cards

framing

a browser-based attack, involves a webpage integrated into another webpage using the iFrame elements of HTML

27
New cards

clickjacking

a browser-based attack, used to trick web users into clicking something different from what they think they are clicking

28
New cards

man-in-the-mobile

a browser-based attack, attacker implants malicious code into the victim’s mobile device to bypass password verification systems that send OTPs via SMS or voice calls

29
New cards

buffer overflow

a browser-based attack, abnormality whereby a program, while writing data to a buffer, surfeits the intended limit and overwrites the adjacent memory, resulting in erratic program behavior

30
New cards

data caching

a browser-based attack, pertains to parts of mobile devices that store information that is often required to interact with web applications, thereby preserving scarce resources and resulting in better response time for client applications

attackers attempt to exploit these to access the sensitive information stored in them

31
New cards

baseband attacks

a phone/SMS-based attack, attackers exploit vulnerabilities in a phone’s GSM/3GPP baseband processor, which sends and receives radio signals to cell towers

32
New cards

SMIShing

a phone/SMS-based attack, attacker uses SMS to send text messages containing deceptive links to malicious websites or telephone numbers to a victim

33
New cards

sensitive data storage

an application-based attack, some apps installed and used by mobile users employ weak security in their database architecture, which makes them targets for attackers who seek to hack and steal the sensitive user information stored in them

34
New cards

no encryption/weak encryption

an application-based attack, apps that transmit unencrypted or weakly encrypted data are susceptible to attacks such as session hijacking

35
New cards

improper SSL validation

an application-based attack, security loopholes in an application’s SSL validation process may allow attackers to circumvent the data security

36
New cards

configuration manipulation

an application-based attack, apps may use external configuration files and libraries that can be exploited in this attack. includes gaining unauthorized access to administration interfaces and configuration stores

37
New cards

dynamic runtime injection

an application-based attack, attackers manipulate and abuse the run time of an application to circumvent security locks and logic checks, access privileged parts of an app

38
New cards

unintended permissions

an application-based attack, misconfigured apps can sometimes open doors to attackers by providing this

39
New cards

escalated privileges

an application-based attack, take advantage of design flaws to gain access to resources that are usually protected from an application or user

40
New cards

no passcode/weak passcode

many users choose not to set a passcode or use a weak one, which an attacker can easily guess or crack to compromise sensitive data stored in the mobile device

41
New cards

iOS jailbreaking

process of removing security mechanisms set by Apple to prevent malicious code from running on the device

42
New cards

android rooting

allows android users to attain privileged control within android’s subsystem

43
New cards

OS data caching

since this specific part stores used data/information in memory temporarily on the hard disk, an attacker can dump this memory by rebooting the victim’s device with a malicious OS and extract sensitive data from the dumped memory

44
New cards

passwords and data accessible

iOS devices store encrypted passwords and data using cryptographic algorithms that have certain known vulnerabilities, in which attackers exploit to decrypt the device’s keychain and other private data

45
New cards
46
New cards
47
New cards
48
New cards
49
New cards
50
New cards
51
New cards
52
New cards
53
New cards
54
New cards
55
New cards
56
New cards
57
New cards
58
New cards
59
New cards
60
New cards
61
New cards
62
New cards
63
New cards
64
New cards
65
New cards
66
New cards
67
New cards
68
New cards
69
New cards
70
New cards
71
New cards
72
New cards
73
New cards
74
New cards
75
New cards
76
New cards
77
New cards
78
New cards
79
New cards
80
New cards
81
New cards
82
New cards
83
New cards
84
New cards
85
New cards
86
New cards
87
New cards
88
New cards
89
New cards
90
New cards
91
New cards
92
New cards
93
New cards
94
New cards
95
New cards
96
New cards
97
New cards
98
New cards
99
New cards
100
New cards