1/28
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
threat vectors
the method an attacker uses to gain access to your system; also known as attack vectors; trying to find weak spots in system
message based vectors
most successful; emails with malicious links; SMS attacks; phising attacks (pretending to be someone else)
image based vectors
scaleable vector graphic also known as SVG is an XML file that describes an image; attacker could embed attack code within XML files & have it run when you open the image
file based vectors
adobe PDF is a good spot for containing attack files; hid within compressed files ZIP/RAR
voice call vectors
vishing, calling pretending to be someone else to get personal information; war dialing, finding unpublished phone numbers to gain access to system
removeable device vectors
malicious information on a USB drive; data exfiltration
vulnerable software vectors
ensuring our system is always updated; attackers finding vulnerablities in a old system
unsupported system vectors
manfacturer doesnt provide updates for that system; no security patches leaves risk for attackers; older systems
unsecure network vectors
wireless connection requires an update to WP3; No. 802.1x a authorization protocol that stops unsupported connections
open service ports
opening TCP or UDP allows an entry point for hackers; firewall rules
default credentials
using credentials given to you by a company without changing or updating
supply chain vectors
allows third party to see infrastructure; normally carried in system without knowing
What does MSP stand for
message service providers
phising
social engineering to make your think somethings real when its not; normally through mail or text message
business email compromise
People have the tendency to be more trusting towards this form for phising; normally have spoofed addresses; financial fraud (Ex. Paypal reset password gain access)
typo squatting
A type of trick of misspelling URL
pretexting
Giving a drawn out story in hopes you will click a link
vishing
voice phishing; normally done over the phone; pretending to be banks
smishing
SMS phishing; normally done by text; consist of forwarding links
impersonation
attacker pretending to be someone they are not in hopes to gain trust
eliciting information
Looking for information or details they wont normally have access to; seen in vishing
identity fraud
pretending to be you; using your information to open a credit
How can you protect against information?
Not giving private information over the phone; Verify who they are before providing information
waterhole attack
Gain access to system we will use later & wait for us to use it instead of attacking us directly
How do waterhole attacks happen?
attacker watches what sites a company uses (Ex. ordering from starbucks, hacker would then get into starbucks system & wait for us to order or login)
defense in depth
multiple layers of security; firewall, anti virus.. etc
Misinformation & disinformation
contains factually incorrect information used to confuse or upset people; found in political campaigns
misformation process
attacker creates fake users
creates content
get increase in likes so it gets pushed to other people that arent bots
Information gets popular others will then speak on this false topic
brand impersonation
Using brand names or logos so users could be redirected to these sites