Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

INF4831 INFORMATION SECURITY QUESTIONS AND ANSWERS A+ GRADED. Buy Quality Materials!

Beoordeling
-
Verkocht
-
Pagina's
9
Cijfer
A+
Geüpload op
16-11-2024
Geschreven in
2024/2025

INF4831 INFORMATION SECURITY QUESTIONS AND ANSWERS A+ GRADED. Buy Quality Materials! Intrusions An attempt to gain unauthorised access to your system Malware Automated attacks designed to exploit common vulnerabilities Denial of Service attacks (DoS) Deny's authorised users access to the system. UDP Flood, TCP SYN Flood, ICMP Flood, Smurf IP attack. Nuke Attack: Tie computer up. Vulnerabilities Mistakes in programs that allow bad things to happen Biggest vulnerability: USERS Cross site scripting, Cross site request forgery, cookie injection Network vulnerabilities Man in the middle attacks, Router attacks, Ethernet traffic sniffing, DNS attacks Secure Socket Layer (SSL) Secure communication method which protects web traffic Perimeter Security Nothing leaves unless explicitly authorized. All information is checked at perimeter. Used in contexts where any leaked information is bad. Government, Military. Expensive and complex. Layered Security Most sensitive information is accessed by the least number of people. Internal access controls are placed on data. Cheaper and simpler than perimeter security. Widely used in business Attacking the Network Methodology 1. Footprint 2. Scan 3. Enumerate 4. Penetrate 5. Attack 6. Cover Tracks 7. Install back doors Reconnaissance Footprint, Scan and Enumerate. Aim is to find attack vectors Attack Vectors parts of the application that can be reached by users. All attack vectors form the attack surface Footprinting

Meer zien Lees minder
Instelling
Vak

Voorbeeld van de inhoud

INF4831 INFORMATION SECURITY QUESTIONS AND ANSWERS
A+ GRADED. Buy Quality Materials!

Intrusions
An attempt to gain unauthorised access to your system
Malware
Automated attacks designed to exploit common vulnerabilities
Denial of Service attacks (DoS)
Deny's authorised users access to the system.

UDP Flood, TCP SYN Flood, ICMP Flood, Smurf IP attack.
Nuke Attack: Tie computer up.
Vulnerabilities
Mistakes in programs that allow bad things to happen

Biggest vulnerability: USERS

Cross site scripting, Cross site request forgery, cookie injection
Network vulnerabilities
Man in the middle attacks, Router attacks, Ethernet traffic sniffing, DNS attacks
Secure Socket Layer (SSL)
Secure communication method which protects web traffic
Perimeter Security
Nothing leaves unless explicitly authorized. All information is checked at perimeter.
Used in contexts where any leaked information is bad. Government, Military. Expensive
and complex.
Layered Security
Most sensitive information is accessed by the least number of people. Internal access
controls are placed on data. Cheaper and simpler than perimeter security. Widely used
in business
Attacking the Network Methodology
1. Footprint
2. Scan
3. Enumerate
4. Penetrate
5. Attack
6. Cover Tracks
7. Install back doors
Reconnaissance
Footprint, Scan and Enumerate. Aim is to find attack vectors
Attack Vectors
parts of the application that can be reached by users. All attack vectors form the attack
surface
Footprinting

, Gathering information about the target. IP addresses, web presence, phone numbers,
emails
Footprinting questions
What software is the target based on? What language does the target use? How can
you communicate with the target?
Footprinting Tools
who.is, nslookup, social engineering
Scanning
determines which of the systems are net accessible . which IP addresses are
accessible, any obvious open doors. At its most basic, ping and address to see if its
alive, scan the ports to see if they are open. Google the port numbers to get application,
google the applications to get vulnerabilities
FIN Scanning
If port is in LISTEN, no reply.
If port is closed, responds with reset.
SYN Scanning
if port is open, responds with SYN/ACK.
you return RESET, no connection established.
Sneaky manipulation of TCP
Send TCP FIN packet, if the port is in LISTEN, no reply. if the port is in CLOSED,
responds with reset. no connection attempt made. Send a SYN packet, if port is open,
responds with SYN/ACK. You return RESET, no connection.
Dorking
using advanced google searches to reveal vulnerable websites
Shodan
Device search engines. Permits searching by IP address, open port, Active protocol,
Vulnerability number
Enumeration
The process of identifying low hanging fruit and user accounts. Scanning shows you the
doors, enumeration identifies how to get through them safely.
Spidering
Automated mapping of websites or file system. Program that recursively follows all links
in a HTML document. can reveal old insecure pages, backups, databases connected
etc.
Penetration
Entering the system using information discovered up till now
Attacking
the attacker accomplishes their goal
Covering Tracks
inexperienced attacker leaves evidence. Turn off event logging, clearing event logs,
hide malicious files left behind.
Installing back doors
intruder installs back door to make intrusions easier
Attacking a web server
1. identify all entry points
2. examine the structure of entry points

Geschreven voor

Vak

Documentinformatie

Geüpload op
16 november 2024
Aantal pagina's
9
Geschreven in
2024/2025
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$9.49
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF


Ook beschikbaar in voordeelbundel

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
TopGradeSolutions Chamberlain College Of Nursing
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
95
Lid sinds
2 jaar
Aantal volgers
9
Documenten
13297
Laatst verkocht
5 dagen geleden
TOPGRADESOLUTIONS

Here we offer revised study materials to elevate your educational outcomes. We have verified learning materials (Research, Exams Questions and answers, Assignments, notes etc) for different courses guaranteed to boost your academic results. We are dedicated to offering you the best services and you are encouraged to inquire further assistance from our end if need be. Having a wide knowledge in Nursing, trust us to take care of your Academic materials and your remaining duty will just be to Excel. Remember to give us a review, it is key for us to understand our clients satisfaction. We highly appreciate clients who always come back for more of the study content we offer, you are extremely valued. All the best.

Lees meer Lees minder
4.9

171 beoordelingen

5
159
4
7
3
4
2
0
1
1

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen