1/24
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
what are threat vectors
method used by the actor to gain acess or infect to the target
what is another name for threat vector
attack vector
what is the biggest and most successful threat vector
message based vectors
what are different message based vectors
email, sms
how can messages be used as an attack vector
phishing attacks with links in emails or text devlier the malware to the user
there are also invoice and cryptocurrency scames
what are image based vectors
threats are inputted in images
what image formats can be linked to threats and what kids of concerns can they contain
scalable vector graphic (svg) or xml (extensible makrup language) can contain html injection or javascript attack code
what are file based vectors
can hold malware in files like adobe pdf, zip/rar files that contain many other files, microsoft office that allows docs with macros
how can voice call vectors be a threat
vishing
spam over ip - large scale phone calls
war dialing - auto calls large blocks of numbers
call tampering - disrupting voice calls
what are removable device vectors
usb interface gets around the firewall containing malicious software
vulnerable software vectors can be two types
client based or agentless
client based vuleranble software
infected executable
may require constant updates
known or unknown vulerabilities
agentless vulnerable software
no installed executable
compromised software on the server would affect all users
client runs a new instance each time
unsupported systems vectors
patching is an important prevention tool
unsupported systems are patched
outdated operation systems become vulnerable
a single system could be an entry
unsecure network vectors
network connects everything so it is very easy for attackers to acess anad view all non encrypted data
how to take care of wireless systems
update security protocols and perform scans to check for open or rogue wireless entworks
how to take care of wired systems
enable no 802.1x an authentical protocol that prevents access unless proper credentials are provided
how can bluetooth be used by attackers
reconnaissance to see where a system might be
bluetooth might not have enough security palced and can be an entry point for an attacker
what are open service ports
most network based serivces connect over tcp or udp port that is an open port and these are oportunities for an attacker to gain access
what happens as you have more services
the more open ports you need to provide the service outside and so the less secure the system may be
why do we use port based firewalls and application based firewalls
creates additional security for systems with open ports
default credentials
most devices have default usernames and passwords and the right credentials provide full control
its very easy to find the defaults for your access point or router
supply chain vectors
third party tampers with the underlying infrastructure or the manufacturing process
supply chain vectors might be placedd ecaues you are working
with a third party
managed service providers (msps)
access many different customer networks from one location