EC-Council Certified Ethical Hacker (CEH) v12 flashcards
189 free flashcards. Tap a card to flip it.
Footprinting
Flip cardFootprinting is the first phase of ethical hacking, involving the collection of as much information as possible about a target system or network without directly interacting with it, often using publicly available sources.
- It is a passive reconnaissance technique.
- Aims to gather information about domains, IP ranges, network topology, and employee details.
- Utilizes publicly available resources like search engines, WHOIS, DNS records, and social media.
Memory trick: Footprints in the sand, leave no trace, gather all you can.
DNS Cache Snooping
Flip cardAn enumeration technique where an attacker queries a recursive DNS server to determine if it has cached specific DNS records, potentially revealing internal network information or user activity.
- Exploits open recursive DNS servers.
- Reveals cached DNS entries for non-authoritative domains.
- Can expose internal hostnames or external sites visited by the organization.
Memory trick: DNS is the phone book, but sometimes it 'snoops' on your calls.
Server-Side Validation
Flip cardThe process of validating user input on the server, after it has been submitted by the client. This is a critical security measure as client-side validation can be bypassed.
- Occurs on the server after submission.
- Essential for security, unlike client-side validation.
- Prevents various input-based attacks.
Memory trick: Validate on the server, or attackers will conquer.
Google Dorking (Advanced Search Operators)
Flip cardGoogle Dorking, or Google Hacking, uses advanced search engine operators to find specific information or vulnerabilities that are publicly exposed but not easily discoverable through normal browsing.
- Operators like `site:`, `filetype:`, `inurl:`, `intitle:` narrow down search results.
- Can reveal sensitive information like configuration files, login pages, or exposed documents.
- A crucial part of passive reconnaissance and footprinting.
Memory trick: Search smarter, not harder; operators are your dorking key.
HTTP Header Analysis
Flip cardThe process of examining the metadata exchanged between a web browser and a web server, often revealing server software, versions, and configurations.
- Passive reconnaissance technique.
- Information found in 'Server' header.
- Does not directly interact with the server intrusively.
Memory trick: Headers are like nametags for web servers.
TCP SYN Scan (-sS)
Flip cardA stealthy Nmap scan technique that sends a SYN packet and, upon receiving a SYN/ACK, immediately sends an RST packet, never completing the TCP three-way handshake. This 'half-open' nature makes it less detectable by application-layer logs.
- Also known as 'half-open' scan.
- Does not complete TCP handshake.
- Less likely to be logged by target applications.
- Effective for identifying open TCP ports stealthily.
Memory trick: SYN is subtle; Connect is complete; FIN is finicky.
WHOIS Lookup
Flip cardA query and response protocol widely used for querying databases that store the registered users or assignees of an Internet resource, such as a domain name, an IP address block, or an autonomous system.
- Provides registration details (registrant, ISP, contact info).
- Useful for IP addresses and domain names.
- Helps in initial intelligence gathering (OSINT).
- Publicly accessible information.
Memory trick: WHOIS: 'Who Owns It, Stupid?'
Arbitrary File Upload
Flip cardArbitrary File Upload vulnerabilities allow an attacker to upload executable files (e.g., scripts, web shells) to a web server, which can lead to remote code execution.
- Often exploited by bypassing client-side and weak server-side validation (e.g., extension, MIME type).
- Can result in complete compromise of the web server.
- Mitigated by strict server-side validation, renaming files, and storing uploads outside the web root.
Memory trick: Uploads Need Rigorous Verification.
Schema Validation
Flip cardSchema Validation is the process of verifying that a given data structure (like XML or JSON) conforms to a predefined schema, ensuring correctness and integrity.
- Enforces data types, field names, required fields, and structural constraints.
- Prevents malformed data from being processed, reducing attack surface.
- Commonly used for API inputs and configuration files.
Memory trick: APIs Guard Data with Strict Schemas.
Parameter Tampering
Flip cardParameter Tampering is a web-based attack where an attacker manipulates parameters exchanged between the client and server to modify application data or logic.
- Involves altering URL query strings, form fields, or HTTP headers.
- Can lead to unauthorized access, privilege escalation, or data manipulation.
- Often targets hidden fields, prices, or user IDs.
Memory trick: Parameters Play Perilously, Prompting Protection.
Nmap NULL Scan (-sN)
Flip cardA stealthy Nmap scan that sends TCP packets with no flags (SYN, ACK, RST, FIN, PSH, URG) set. It relies on RFC 793 behavior where closed ports respond with RST and open ports send no response, aiming to avoid application-layer logging.
- Sends TCP packets with no flags.
- Relies on RFC 793 behavior (open = no response, closed = RST).
- Highly stealthy, aims to bypass firewalls and NIDS.
- Effectiveness is OS-dependent (Windows often ignores).
Memory trick: NULL is 'No Usual Logging Lure'.
DNS Zone Transfer (AXFR)
Flip cardA mechanism used to replicate DNS database files from a primary DNS server to secondary DNS servers. If misconfigured, it can allow unauthorized users to obtain a complete list of all DNS records for a domain.
- Uses AXFR query type.
- Reveals internal network structure.
- Significant information leakage risk.
- Countermeasures involve restricting AXFR to trusted IPs.
Memory trick: AXFR: 'All eXtra Files Revealed'.
Passive Subdomain Enumeration
Flip cardPassive subdomain enumeration involves discovering subdomains of a target domain by querying publicly available datasets and services without directly interacting with the target's DNS servers or web servers.
- Leverages sources like Certificate Transparency logs, DNS databases, search engines, and third-party APIs.
- Examples of tools include Amass, Sublist3r, and online services.
- It is a stealthier approach compared to active DNS brute-forcing.
Memory trick: Subdomains are branches; find them all without shaking the tree.
SQL Injection
Flip cardA web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. It typically allows an attacker to view data that they are not normally able to retrieve, alter database data, execute administration operations on the database (such as shutting it down), or recover the contents of a given file present on the database server's file system.
- Injects malicious SQL code.
- Targets database operations.
- Can lead to data disclosure, modification, or destruction.
Memory trick: If the query gets dropped, SQL Injection has popped.
Nmap OS Detection
Flip cardNmap's OS detection feature uses a series of TCP and UDP probes to analyze responses and infer the operating system running on a target host.
- Activated with the -O option.
- Analyzes TCP/IP stack implementation details (e.g., initial sequence numbers, TCP window sizes, IP ID fields).
- Can be less accurate if firewalls or network devices modify responses.
Memory trick: Nmap's many maps, each for a different task, know your purpose.
Transport Layer Security (TLS)
Flip cardA cryptographic protocol designed to provide communication security over a computer network. It is widely used in applications such as web browsing (HTTPS), email, instant messaging, and voice over IP (VoIP).
- Successor to SSL (Secure Sockets Layer).
- Provides encryption, authentication, and data integrity.
- Forms the 'S' in HTTPS.
Memory trick: HTTPS is secure because TLS is its core.
Passive Footprinting
Flip cardThe process of gathering information about a target without directly interacting with their systems, primarily through publicly available sources.
- No direct interaction with target.
- Relies on public data (OSINT).
- Includes searching WHOIS, DNS records, public websites, social media.
Memory trick: Passive means 'no touchy,' Active means 'poke around.'
Aircrack-ng Suite (airodump-ng)
Flip cardA collection of tools for assessing WiFi network security. Specifically, `airodump-ng` is used for capturing raw 802.11 frames, identifying access points, clients, and data packets, which is essential for wireless reconnaissance.
- Requires wireless adapter in monitor mode.
- Identifies SSIDs, BSSIDs, channels.
- Captures raw 802.11 traffic.
- Critical for wireless penetration testing.
Memory trick: Aircrack-ng is the 'Air Traffic Controller' for WiFi intel.
Unrestricted File Upload
Flip cardA vulnerability that occurs when a web application allows users to upload files without properly validating their type or content, enabling attackers to upload malicious files (e.g., web shells) that can then be executed on the server.
- Lack of server-side file validation.
- Allows upload of malicious files (e.g., web shells).
- Can lead to remote code execution (RCE).
Memory trick: If the file check is flimsy, the shell will be frisky.
Stored XSS
Flip cardStored (or Persistent) XSS is a type of Cross-Site Scripting attack where a malicious script is permanently stored on the target server (e.g., in a database) and delivered to other users.
- The most damaging type of XSS due to its persistence.
- Attacker injects script into databases, forums, comment fields, etc.
- Users execute the script unknowingly when they retrieve the compromised data.
Memory trick: Scripts Steal Secrets, Severely.
SNMP Enumeration
Flip cardThe process of querying network devices using the Simple Network Management Protocol (SNMP) to gather information, often by guessing or exploiting weak community strings.
- Uses UDP port 161 (agent) and 162 (manager)
- Relies on community strings for authentication (e.g., 'public', 'private')
- Can reveal sensitive network topology and device configuration
Memory trick: SNMP at 161 helps you walk the network's secrets.
Iframe Sandboxing
Flip cardIframe sandboxing, using the HTML5 `sandbox` attribute, creates a highly restricted environment for content embedded within an `<iframe>` element.
- Prevents embedded content from executing scripts, accessing parent DOM, or submitting forms.
- Mitigates Cross-Site Scripting (XSS) and other content injection attacks.
- Specific 'allow' flags can selectively re-enable certain functionalities.
Memory trick: Frames Secure, Content Contained.
TLS Downgrade Attack
Flip cardA TLS downgrade attack forces a client and server to negotiate an older, less secure version of the TLS (or SSL) protocol, making the connection vulnerable to eavesdropping and tampering.
- Often relies on the server supporting outdated protocols (e.g., TLS 1.0, SSLv3).
- Can be combined with weak cipher suites for easier exploitation.
- Prevented by disabling all outdated protocols and weak ciphers on the server.
Memory trick: Network Weaknesses Invite Eavesdroppers.
HTTPS
Flip cardHTTPS (Hypertext Transfer Protocol Secure) is an extension of the Hypertext Transfer Protocol (HTTP) for secure communication over a computer network.
- Uses SSL/TLS protocol for encryption and authentication.
- Default port is 443.
- Protects against eavesdropping, tampering, and message forgery.
Memory trick: Web's Secure Path: Always Encrypted.
TCP ACK Ping Scan (-PA)
Flip cardAn Nmap host discovery method that sends TCP ACK packets to target hosts. It's effective for bypassing firewalls that block ICMP or SYN packets, as it doesn't attempt to establish a connection.
- Sends ACK packets to a specified port (default 80)
- Target responds with RST if port is closed, or nothing if filtered
- Good for firewall bypass, especially for ICMP/SYN blocking
Memory trick: ACKing bypasses the firewall's ICMP and SYN guards.
Security Awareness Training
Flip cardEducational programs designed to inform employees about cybersecurity threats, best practices, and how to recognize and respond to attacks, particularly social engineering.
- Focuses on the human element of security.
- Teaches recognition of phishing, pretexting, etc.
- Crucial for building a 'human firewall'.
Memory trick: Train your people to be the strongest shield.
Security Group (Cloud)
Flip cardA virtual firewall that controls inbound and outbound traffic for one or more cloud instances.
- Operates at the instance level.
- Stateful: automatically allows return traffic for permitted outbound requests.
- Allows specifying rules based on IP address, port, and protocol.
Memory trick: Security Group: Guard at the instance's door.
Cloud Lateral Movement Countermeasures
Flip cardSecurity controls designed to restrict an attacker's ability to move within a compromised cloud environment and escalate privileges or access further resources.
- Granular IAM policies are critical.
- Network segmentation and micro-segmentation limit reach.
- Monitoring and alerting for anomalous activity are essential for detection.
Memory trick: Lock down every door, even inside the house. Don't trust the interior.
Client-Side Encryption (Cloud)
Flip cardEncrypting data on the customer's side before it is transmitted to and stored by the cloud provider, with decryption also occurring client-side.
- Customer retains full control over encryption keys.
- Cloud provider never sees plaintext data.
- Offers strongest confidentiality, but increases client overhead and key management complexity.
Memory trick: Client-side: You hold the key, the cloud only sees the lockbox.
Tailgating (Piggybacking)
Flip cardA social engineering technique where an unauthorized person gains entry to a restricted area by closely following an authorized person.
- Exploits human courtesy or distraction.
- Does not require bypassing physical security controls directly.
- Often relies on the authorized person assuming the follower is also authorized.
Memory trick: Don't let them follow your tail into the building.
Vendor Lock-in (Cloud)
Flip cardA situation where a customer is dependent on a single cloud provider's proprietary products or services, making it difficult to switch to another provider.
- Caused by proprietary APIs, data formats, or service integrations.
- Mitigated by open standards, cloud-agnostic tools, and multi-cloud strategies.
- Can result in higher costs and reduced flexibility.
Memory trick: Don't get stuck in one cloud, build with universal tools.
Impersonation
Flip cardA social engineering technique where an attacker pretends to be a different person or entity to gain trust and access to information or systems.
- Involves assuming a false identity.
- Relies on the victim's trust in the assumed identity.
- Can be done online or offline.
Memory trick: Impersonation is playing a role to steal your data.
Whaling
Flip cardA highly targeted form of spear phishing attack that specifically targets senior executives, CEOs, or other high-profile individuals within an organization.
- Aims for high-value targets with significant authority.
- Often involves extensive reconnaissance to create a convincing lure.
- Typically seeks large financial gains or access to critical information.
Memory trick: Whales are big targets in the ocean of emails.
Private Cloud
Flip cardA cloud deployment model where the cloud infrastructure is provisioned for exclusive use by a single organization.
- Dedicated resources for one organization.
- Can be managed internally or by a third party.
- Offers higher control and security than public clouds.
Memory trick: Private cloud, private property, only one owner.
Multi-tenant Architecture
Flip cardA software architecture where a single instance of a software application or infrastructure serves multiple distinct organizations (tenants).
- Tenants share compute, storage, and networking resources.
- Logical isolation mechanisms ensure data segregation and security.
- Common in SaaS and PaaS offerings for cost efficiency and scalability.
Memory trick: Multi-tenant: Many tenants, one building, separate apartments.
Cloud Secrets Management
Flip cardThe practice of securely storing, retrieving, and managing sensitive information like API keys, database credentials, and certificates in a cloud environment.
- Avoids hardcoding secrets in code.
- Utilizes dedicated secrets management services (e.g., AWS Secrets Manager, Azure Key Vault).
- Rotates secrets regularly and applies least privilege access.
Memory trick: Secrets management: Don't put the keys under the doormat.
Infrastructure as a Service (IaaS)
Flip cardA cloud service model that provides virtualized computing resources over the internet, including virtual machines, storage networks, and operating systems.
- Users manage OS, applications, and data.
- Cloud provider manages virtualization, servers, storage, and networking.
- Offers the most flexibility and control among the 'as a Service' models.
Memory trick: IaaS is like building your own house on rented land.
Insufficient Identity, Credential, and Access Management (ICAM)
Flip cardA cloud security threat arising from weak or poorly configured controls for managing user identities, authentication credentials, and access permissions.
- Leads to unauthorized access.
- Often results from overly permissive roles or misconfigured policies.
- A common vector for data breaches in cloud environments.
Memory trick: IAM is like the bouncer; if they're weak, anyone gets in.
Availability Zone (AZ)
Flip cardA distinct, isolated physical location within a cloud region, designed for fault tolerance and high availability.
- Each AZ has independent power, cooling, and networking.
- Connected to other AZs within the region by low-latency links.
- Allows for deploying applications across multiple data centers for resilience.
Memory trick: AZs are like separate rooms in a house, if one burns, the others are safe.
Principle of Least Privilege
Flip cardA security principle requiring that a user, program, or process be given only the minimum levels of access—or permissions—necessary to perform its function.
- Reduces the attack surface.
- Limits the impact of a compromise.
- Crucial for effective access control in cloud environments.
Memory trick: Least Privilege: Only unlock the doors you need to open.
Authenticated Encryption (AEAD)
Flip cardAuthenticated Encryption with Associated Data (AEAD) is a type of encryption that simultaneously provides confidentiality, integrity, and authenticity for cryptographic data. Examples include AES-GCM and ChaCha20-Poly1305.
- Combines encryption and message authentication.
- Provides confidentiality, integrity, authenticity.
- Protects against tampering and unauthorized disclosure.
- Often more efficient than separate encryption and MAC.
Memory trick: AEAD bundles all three: confidential, authentic, integral.
Two-Time Pad Attack
Flip cardA two-time pad attack occurs when a stream cipher (or one-time pad) reuses the same keystream to encrypt two or more different plaintexts. This allows an attacker to XOR the ciphertexts, which cancels out the keystream and reveals the XOR of the original plaintexts, compromising confidentiality.
- Specific to stream ciphers or one-time pads.
- Occurs with keystream reuse.
- XORing ciphertexts reveals XOR of plaintexts.
- Completely compromises confidentiality.
Memory trick: Stream ciphers fear keystream reuse; two-time pad is doom.
Rainbow Table Attack
Flip cardA rainbow table attack is a precomputed table for reversing cryptographic hash functions, usually for cracking password hashes. It's effective against unsalted hashes as it allows an attacker to quickly find the original password for a given hash.
- Precomputed lookup table.
- Effective against unsalted hashes.
- Vulnerable to common passwords.
- Mitigated by salting and key stretching.
Memory trick: Dictionary checks words, Brute-force tries all, Rainbow tables look up.
Digital Signatures
Flip cardA digital signature is a mathematical scheme for demonstrating the authenticity of digital messages or documents. It provides integrity, authenticity, and non-repudiation by using a sender's private key to sign a hash of the data.
- Uses asymmetric cryptography.
- Provides authenticity, integrity, non-repudiation.
- Sender uses private key to sign.
- Receiver uses sender's public key to verify.
Memory trick: Keys encrypt, hashes check, signatures prove.
Data Integrity
Flip cardData integrity ensures that information has not been altered, destroyed, or corrupted in an unauthorized manner during storage or transmission.
- Protects against unauthorized modification.
- Often achieved using hashing algorithms and digital signatures.
- Crucial for trustworthy transactions and communications.
Memory trick: CIA: Confidentiality, Integrity, Availability – plus Non-repudiation.
Salting
Flip cardSalting is the process of adding a unique, random string (salt) to a password before hashing it. This technique makes rainbow table attacks ineffective and ensures that identical passwords produce different hash values.
- Defeats rainbow table attacks.
- Makes each password hash unique.
- Salt is stored alongside the hash, often in plain text.
Memory trick: Salty stretching makes password hashes strong and unique.
Length Extension Attack
Flip cardA length extension attack is a type of cryptographic attack where an attacker can use a hash value for a secret key and a message to calculate the hash value of a new message that includes the original message plus some chosen data, without knowing the secret key. It applies to hash functions built on the Merkle-Damgård construction when the key is prepended to the message.
- Applicable to Merkle-Damgård hashes (MD5, SHA-1, SHA-2).
- Exploits H(key || message) construction.
- Allows extending message and computing new valid hash.
- Mitigated by HMAC or H(message || key) or H(key || message || key).
Memory trick: Preimages find input, collisions find pairs, length extension extends.
Symmetric Encryption
Flip cardSymmetric encryption, also known as secret-key cryptography, uses a single, shared secret key for both encrypting plaintext into ciphertext and decrypting ciphertext back into plaintext.
- Uses one key for both operations.
- Generally faster than asymmetric encryption.
- Key distribution is a challenge.
Memory trick: Symmetric is single, Asymmetric is two-key strong.
ECB Mode Vulnerability
Flip cardElectronic Codebook (ECB) is a block cipher mode of operation where each plaintext block is encrypted independently. Its primary vulnerability is that identical plaintext blocks will always produce identical ciphertext blocks, revealing patterns in the data.
- Encrypts blocks independently.
- Reveals patterns in plaintext.
- Not suitable for data with repeating blocks (e.g., images, structured data).
- No initialization vector (IV) or chaining.
Memory trick: ECB is an exact copy, CBC chains, CTR counts, GCM does Galois.
Cryptographic Hash Function
Flip cardA cryptographic hash function is a mathematical algorithm that maps data of arbitrary size to a bit array of a fixed size (the 'hash value'). It's designed to be a one-way function, resistant to various attacks, and produces drastically different outputs for even minor input changes.
- One-way (computationally irreversible).
- Fixed-size output.
- Avalanche effect (small input change = large output change).
- Collision resistant.
Memory trick: Hash for integrity, Encrypt for secret, Sign for proof.
Memory Forensics for Crypto Keys
Flip cardMemory forensics involves analyzing a computer's RAM dump to find sensitive information, including active encryption keys for mounted volumes or decrypted data, which reside in memory during operation.
- Keys are in RAM while volume is mounted.
- Memory dump captures RAM state.
- Allows bypassing strong passphrases.
- Requires timely capture before power-off/key purge.
Memory trick: Memory holds keys, but strong passphrases need brute-force.
POODLE Attack
Flip cardThe POODLE (Padding Oracle On Downgraded Legacy Encryption) attack exploits a vulnerability in SSLv3's implementation of CBC mode padding, allowing an attacker to decrypt parts of encrypted messages via a padding oracle side channel.
- Targets SSLv3.
- Exploits padding in CBC mode.
- Compromises confidentiality.
- Led to SSLv3 deprecation.
Memory trick: POODLE bites SSLv3, Heartbleed leaks TLS, FREAK weakens all.
PCI DSS Principle 2
Flip cardA core principle of the Payment Card Industry Data Security Standard (PCI DSS) that mandates the protection of stored cardholder data, specifically requiring encryption and rendering sensitive data unreadable wherever it is stored.
- Part of the 12 PCI DSS Requirements.
- Focuses on securing stored cardholder data.
- Requires encryption for sensitive authentication data.
- Mandates truncation or rendering unreadable of Primary Account Numbers (PANs).
Memory trick: Build, Protect, Manage, Control, Monitor, Test, Policy.
Zero-Day Exploit
Flip cardA cyberattack that exploits a software vulnerability previously unknown to the software vendor or the public. This means there is no patch or fix available for the vulnerability at the time of the attack.
- Vulnerability is unknown to vendor and public.
- No patch or fix exists at the time of discovery/attack.
- Highly dangerous due to lack of immediate defense.
- Often discovered by malicious actors or security researchers.
Memory trick: Zero-day means zero time to patch.
Defense in Depth
Flip cardA strategy that employs multiple, overlapping security controls and mechanisms to protect assets. It aims to create a layered security architecture, so if one control fails, others are in place to provide protection.
- Uses multiple layers of security.
- Protects against various attack vectors.
- No single point of failure.
- Applies to people, technology, and operations.
Memory trick: CIA Triad is the core, but Defense in Depth is the armor.
Advanced Persistent Threat (APT)
Flip cardA sophisticated, prolonged cyberattack campaign where an intruder establishes an illicit presence on a network to steal data over an extended period. APTs are characterized by their stealth, persistence, and highly targeted nature.
- Highly targeted and patient.
- Operates covertly for long periods (stealthy).
- Uses sophisticated tools and techniques.
- Often sponsored by nation-states or large organizations.
Memory trick: APTs are Advanced, Persistent, and Stealthy.
Reconnaissance (Hacking)
Flip cardThe initial phase of an ethical hacking engagement, focused on gathering as much information as possible about the target system, network, or organization, often without direct interaction.
- First stage of a penetration test.
- Can be passive (OSINT) or active (port scanning).
- Aims to understand the target's attack surface.
- Provides data for subsequent attack phases.
Memory trick: RGS M C: Recon, Scan, Gain, Maintain, Clear.
Security by Design
Flip cardAn approach to software and system development where security is considered and integrated into every stage of the lifecycle, from initial planning and design through implementation and deployment.
- Proactive security measure.
- Integrates security early in SDLC.
- Aims to prevent vulnerabilities rather than fix them later.
- Leads to more resilient and trustworthy systems.
Memory trick: Design security early, build it strong, don't hide it.
SYN Flood
Flip cardA type of Denial-of-Service (DoS) attack where an attacker sends a high volume of SYN packets to a target server, but never completes the TCP three-way handshake, thus exhausting server resources.
- Targets the TCP three-way handshake.
- Attacker sends SYN, but not ACK.
- Causes resource exhaustion on the target.
- Common DoS attack vector.
Memory trick: SYN-ful floods deny access, leaving servers stranded.
Gray Box Testing
Flip cardA penetration testing method where the tester has partial knowledge of the internal system, such as user credentials, network diagrams, or access to non-critical internal applications.
- Combines elements of black box and white box testing.
- Simulates an attacker with some internal access or information.
- Efficient for uncovering vulnerabilities from an insider perspective.
- Requires some information sharing from the client.
Memory trick: Color your boxes by how much you know: Black, Gray, White.