13.2: Physical and Network Attack Indicators

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/30

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:36 PM on 9/16/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

31 Terms

1
New cards

What is a birthday attack?

Exploits the probability of hash collisions — two different inputs producing the same hash — using the birthday paradox to find a match far faster than brute force.

2
New cards

What is a collision attack?

Finding two different inputs that produce the same hash value, letting an attacker substitute a malicious file for a legitimate one with a matching hash. Why MD5 and SHA-1 are deprecated.

3
New cards

What is a downgrade attack?

Forcing a connection to fall back to an older, weaker protocol or cipher the attacker can break — such as pushing TLS down to SSL. Mitigated by disabling legacy versions entirely.

4
New cards

What is SSL stripping?

An on-path attack that downgrades a victim's HTTPS connection to HTTP, exposing traffic in cleartext. Mitigated by HSTS (HTTP Strict Transport Security)

5
New cards

What is key stretching?

Applying a hashing function repeatedly (PBKDF2, bcrypt, scrypt, Argon2) to make each password guess computationally expensive, slowing brute-force attacks.

6
New cards

What is salting, and what does it prevent?

Adding unique random data to each password before hashing, so identical passwords produce different hashes. Defeats rainbow tables and precomputed hash lookups.

7
New cards

What is a brute-force attack?

Systematically trying every possible character combination until the correct password is found. Guaranteed to work eventually, but slow — countered by length, lockouts, and rate limiting.

8
New cards

What is a dictionary attack?

Trying passwords from a list of common words, leaked passwords, and predictable variations. Much faster than brute force because it targets likely candidates.

9
New cards

What is password spraying?

Trying one or a few common passwords against many accounts, avoiding lockout thresholds that would trigger from repeated attempts on a single account.

10
New cards

What is credential stuffing?

Using username/password pairs leaked from one breach against other services, exploiting password reuse. Defeated by unique passwords and MFA.

11
New cards

What is a rainbow table attack?

Using precomputed tables of hash-to-plaintext mappings to reverse password hashes quickly. Salting makes it ineffective.

12
New cards

What is the difference between an online and offline password attack?

Online attacks guess against a live system and are limited by lockouts and rate limiting. Offline attacks crack a stolen hash file locally with no such limits, so speed depends only on hardware.

13
New cards

What is a pass-the-hash attack?

Authenticating with a captured password hash directly, without ever cracking it to plaintext. Enables lateral movement in Windows environments.

14
New cards

What is a denial-of-service (DoS) attack?

Overwhelming a system's resources or exploiting a flaw to make a service unavailable to legitimate users.

15
New cards

What is a distributed denial-of-service (DDoS) attack?

A DoS launched from many compromised hosts at once, usually a botnet, making it far harder to block by source.

16
New cards

What is an amplification/reflection attack?

Sending small spoofed requests to third-party servers (DNS, NTP, memcached) that send much larger responses to the victim, multiplying attack volume and hiding the source.

17
New cards

What is DNS poisoning / cache poisoning?

Injecting false records into a DNS resolver's cache so users are silently redirected to attacker-controlled sites. Mitigated by DNSSEC.

18
New cards

What is domain hijacking?

An attacker gains control of a domain registration itself — through registrar account compromise or social engineering — and redirects all traffic for that domain.

19
New cards

What is a DNS tunneling attack?

Encoding data inside DNS queries and responses to exfiltrate data or maintain C2 through a port that's almost never blocked.

20
New cards

What is typosquatting / URL hijacking?

Registering domains that are near-misses of legitimate ones to catch mistyped traffic for phishing or malware delivery.

21
New cards

What is an on-path (man-in-the-middle) attack?

The attacker positions between two parties to intercept, read, or alter traffic while both sides believe they're communicating directly.

22
New cards

What is ARP (Address Resolution Protocol) poisoning?

Sending forged ARP replies on a LAN so traffic for another device is sent to the attacker's MAC address instead. A common way to establish an on-path position.

23
New cards

What is MAC flooding?

Overwhelming a switch's MAC address table so it fails open and floods traffic to all ports, letting the attacker sniff it. Mitigated by port security.

24
New cards

What is MAC cloning / spoofing?

Changing a device's MAC address to impersonate an authorized device, bypassing MAC filtering and port-based restrictions.

25
New cards

What is a replay attack?

Capturing valid traffic — like an authentication token or session cookie — and retransmitting it to gain access. Countered by timestamps, nonces, and sequence numbers.

26
New cards

What is session hijacking?

Taking over an authenticated session by stealing or predicting the session token, letting the attacker act as the logged-in user without credentials.

27
New cards

What is a rogue access point, and what is an evil twin?

A rogue AP is any unauthorized wireless AP on the network. An evil twin specifically impersonates a legitimate SSID to trick users into connecting through the attacker.

28
New cards

What is a wireless disassociation/deauthentication attack?

Sending forged management frames to forcibly disconnect clients from an AP, often to force reconnection to an evil twin or capture a handshake. Mitigated by protected management frames.

29
New cards

What is RF jamming?

Flooding a wireless frequency with interference to disrupt legitimate communication — a wireless denial-of-service attack.

30
New cards

What is a malicious Bluetooth attack — bluejacking vs. bluesnarfing?

  • Bluejacking sends unsolicited messages to a nearby Bluetooth device — mostly a nuisance.

  • Bluesnarfing steals data from the device.

  • Bluebugging goes further and takes control of the device.


31
New cards

What is a credentialed indicator of a password attack?

A spike in failed logins, lockouts across many accounts, logins at unusual hours, or impossible-travel logins — all signs of spraying, stuffing, or brute force.