EC-Council Certified Ethical Hacker (CEH) v12 flashcards
189 free flashcards. Tap a card to flip it.
SYN Flood
Flip cardA type of Denial-of-Service (DoS) attack where an attacker sends a high volume of SYN packets to a target server, but never completes the TCP three-way handshake, thus exhausting server resources.
- Targets the TCP three-way handshake.
- Attacker sends SYN, but not ACK.
- Causes resource exhaustion on the target.
- Common DoS attack vector.
Memory trick: SYN-ful floods deny access, leaving servers stranded.
Gray Box Testing
Flip cardA penetration testing method where the tester has partial knowledge of the internal system, such as user credentials, network diagrams, or access to non-critical internal applications.
- Combines elements of black box and white box testing.
- Simulates an attacker with some internal access or information.
- Efficient for uncovering vulnerabilities from an insider perspective.
- Requires some information sharing from the client.
Memory trick: Color your boxes by how much you know: Black, Gray, White.
Detective Controls
Flip cardSecurity controls designed to identify and alert about security events, incidents, or policy violations after they have occurred or are in progress, providing visibility into vulnerabilities and attacks.
- Identifies existing issues or ongoing attacks.
- Examples: IDS, SIEM, audits, logging, code reviews, vulnerability scans.
- Crucial for incident response and accountability.
- Provides information for improving preventive controls.
Memory trick: Prevent, Detect, Correct: the PDC of security.
GDPR (General Data Protection Regulation)
Flip cardA comprehensive data privacy and security law enacted by the European Union (EU) that imposes strict rules on how personal data is collected, stored, and processed, granting individuals significant control over their data.
- EU data privacy law.
- Mandates DPO appointment in certain cases.
- Requires Data Protection Impact Assessments (DPIAs).
- Includes data subject rights (e.g., right to be forgotten).
Memory trick: HIPAA for Health, PCI for Cards, SOX for Books, GDPR for EU Data.
OT Direct Internet Exposure
Flip cardOperational Technology (OT) devices, such as PLCs, directly connected to the public internet without protective firewalls or segmentation.
- Creates a direct attack path for remote adversaries.
- Bypasses traditional network perimeter defenses.
- Can lead to physical damage, safety incidents, and production halts.
Memory trick: Exposed OT means direct control over the factory's heart.
Static Application Security Testing (SAST)
Flip cardA white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.
- Identifies vulnerabilities early in the development lifecycle.
- Can find issues like hardcoded secrets, SQL injection, XSS.
- Does not require a running application.
Memory trick: Static analysis 'sees' code flaws without running the firmware.
Trojan Horse
Flip cardMalware that disguises itself as legitimate software to gain access to a system, then performs malicious actions once executed.
- Relies on social engineering to trick users into installing it.
- Does not self-replicate.
- Can deliver various payloads (e.g., backdoors, data theft, ransomware).
Memory trick: Trojans Trick You with a Gift.
Bootkit
Flip cardA malicious program that modifies the boot sector or Master Boot Record (MBR) of a hard drive, allowing it to load before the operating system and hide its presence.
- Infects the boot process (MBR/VBR)
- Loads before the operating system
- Difficult to detect and remove
Memory trick: Boot kits hide deep, ensuring they always greet the machine's first breath.
Mobile App Code Obfuscation
Flip cardThe process of intentionally creating code that is difficult for humans to understand and reverse engineer, while still maintaining its original functionality.
- Protects intellectual property from competitors.
- Makes it harder for attackers to find vulnerabilities.
- Commonly involves renaming variables, classes, and methods, and adding junk code.
Memory trick: To hide mobile app secrets, obfuscation makes the code a puzzle.
Exploit
Flip cardA piece of code or sequence of commands that takes advantage of a software vulnerability to achieve an attacker's goal.
- Targets specific vulnerabilities (e.g., buffer overflows, SQL injection).
- Can lead to remote code execution, privilege escalation, or data theft.
- Often a component of a larger attack chain.
Memory trick: Exploits use flaws to open doors.
Worm
Flip cardA standalone malware computer program that replicates itself to spread to other computers, often without human interaction.
- Self-propagating and self-contained.
- Can spread via networks, email, or removable media.
- Does not require a host program to infect.
Memory trick: Worms Wriggle and Replicate.
Application Whitelisting
Flip cardA security strategy that allows only explicitly authorized applications to run on a computer system, while blocking all other applications by default.
- Blocks unknown and unauthorized executables.
- Highly effective against zero-day malware.
- Requires careful management of the approved application list.
Memory trick: Whitelist: Only the 'White' ones get permission to run.
Spambot
Flip cardA program designed to collect email addresses or to send spam emails from a compromised system.
- Utilizes SMTP (port 25) to send large volumes of unsolicited email.
- Often part of a botnet.
- Can be used for phishing, malware distribution, or advertising.
Memory trick: Spam Bots Send Many Emails.
MDM App Control
Flip cardMobile Device Management (MDM) capabilities that allow organizations to control which applications can be installed, accessed, or run on managed mobile devices.
- Includes app whitelisting (only approved apps allowed).
- Includes app blacklisting (specific apps/sources blocked).
- Mitigates risks from malware, unauthorized software, and data leakage.
Memory trick: MDM 'apps' control what runs, like a strict bouncer.
IT/OT Convergence Risk
Flip cardThe security risks introduced when Information Technology (IT) and Operational Technology (OT) networks are interconnected without proper segmentation and security controls.
- Allows IT-based threats to propagate into the OT environment.
- Exposes critical industrial systems to broader attack surfaces.
- Requires specialized security strategies due to differing IT/OT priorities.
Memory trick: IT/OT merge means IT's open door is OT's direct threat.
IoT Data-in-Transit Protection
Flip cardMeasures implemented to secure data as it travels across networks, particularly for IoT devices transmitting sensitive information wirelessly.
- Primarily uses encryption protocols (e.g., TLS, DTLS).
- Authentication ensures only authorized devices send/receive data.
- Protects against eavesdropping, tampering, and man-in-the-middle attacks.
Memory trick: Encrypt and authenticate to shield IoT data on its journey.
DNS Tunneling
Flip cardA technique that encodes data of other programs or protocols inside DNS queries and responses, creating a covert communication channel.
- Uses DNS protocol for C2 or data exfiltration.
- Can bypass firewalls and security controls that inspect other protocols.
- Often involves small, frequent queries and responses.
Memory trick: Don't Notice Stealthy Data.
Polymorphic Virus
Flip cardA type of malware that changes its executable code and encryption keys each time it infects a new system, making it difficult for signature-based antivirus software to detect.
- Evades signature-based detection.
- Changes its code and signature with each infection.
- Maintains the same malicious functionality.
Memory trick: Poly-morphic means 'many forms' to hide its true face.
Malicious Mobile Data Collection
Flip cardWhen mobile applications or embedded SDKs request and use excessive, unnecessary permissions to gather sensitive user data (e.g., call logs, location, contacts) without explicit user consent or legitimate functional need, often for illicit purposes like surveillance or resale.
- Often hidden within legitimate-looking apps or third-party SDKs.
- Leverages 'over-privileged' apps that request more permissions than required.
- Leads to privacy violations and potential data exfiltration.
Memory trick: An app's permissions are like keys; too many open the wrong doors.
Fileless Malware
Flip cardMalware that operates without leaving a trace on the file system, executing directly in memory by leveraging legitimate system tools.
- Resides only in RAM, making it volatile and difficult to detect.
- Uses 'living off the land' techniques (e.g., PowerShell, WMI).
- Evades traditional signature-based antivirus and forensic analysis.
Memory trick: Fileless Ghosts Live in Memory.
OT Protocol Exploitation Tools
Flip cardSoftware tools specifically designed to interact with, analyze, and exploit vulnerabilities in industrial control system (ICS) communication protocols (e.g., Modbus, S7comm, DNP3).
- Allow sending malicious commands to PLCs, RTUs, HMI.
- Can be used for reconnaissance, manipulation, or denial of service.
- Often require deep understanding of proprietary or specialized protocols.
Memory trick: To 'control' the factory, use protocol tools to speak its language.
OT Micro-segmentation
Flip cardA network security technique that divides a network into small, isolated segments down to the individual workload level, applying granular security policies to each segment.
- Limits lateral movement of threats within a network.
- Reduces the attack surface for each individual device.
- Enhances containment by isolating compromised systems.
Memory trick: Micro-segmentation fences off each robot, stopping malware's 'spread'.
Exploit Prevention System (EPS)
Flip cardSecurity solutions designed to detect and block common exploit techniques (e.g., buffer overflows, ROP, heap spray) used by malware to leverage software vulnerabilities, often before a patch is available.
- Focuses on exploit techniques, not just signatures.
- Protects against zero-day exploits.
- Monitors memory and process behavior for anomalies.
Memory trick: EPS proactively 'Exploit-Proofs' your system's vulnerable spots.
Rootkit
Flip cardA type of malicious software designed to hide its presence and maintain privileged access to a computer while concealing its existence from the user and other system processes.
- Operates at a deep system level (kernel or user mode).
- Hides files, processes, and network connections.
- Can be used to install other malware or facilitate persistent access.
Memory trick: Rootkits hide deep to control the system's core.
IRC-based Botnet
Flip cardA type of botnet where the attacker (botmaster) uses an Internet Relay Chat (IRC) server and channel to issue commands to and receive responses from compromised computers (bots).
- Uses standard IRC protocols and ports (e.g., TCP 6667, 6697).
- Provides a centralized, real-time command and control mechanism.
- Bots join a specific IRC channel to await commands.
Memory trick: IRC C2: Bots 'chat' on a secret channel for commands.
Process Hollowing
Flip cardA code injection technique where a legitimate process is created in a suspended state, its memory is unmapped, malicious code is written into its address space, and then the process is resumed, executing the malicious code.
- Executes malicious code under the guise of a legitimate process.
- Evades detection by standard process monitoring tools.
- Often used by advanced persistent threats (APTs) and rootkits.
Memory trick: Hollowing: The 'hollowed' shell of a good process holds bad code.
IoT Default Credentials
Flip cardPre-set usernames and passwords on Internet of Things (IoT) devices that are often not changed by users, creating a significant security vulnerability.
- Many IoT devices ship with universal default credentials.
- Attackers can easily find lists of these defaults online.
- Failure to change them allows unauthorized remote access.
Memory trick: IoT's door is often open with default keys.
Anti-Debugging
Flip cardA set of techniques used by malware to detect the presence of a debugger and react in a way that hinders analysis, such as terminating or altering execution.
- Checks for debugger-specific artifacts (e.g., process names, breakpoints).
- Can lead to malware termination, altered execution flow, or system crashes.
- Makes dynamic analysis more challenging for researchers.
Memory trick: Malware Doesn't Want to Be Debugged.
Anti-analysis Techniques
Flip cardMethods used by malware to detect and evade analysis environments, such as virtual machines, sandboxes, debuggers, or security tools, to prevent researchers from understanding its full functionality.
- Detects presence of VMs, sandboxes, debuggers.
- Can alter behavior or terminate execution when detected.
- Aims to frustrate and prolong malware analysis efforts.
Memory trick: Anti-analysis says 'No entry' to the security lab.
Insecure Data Transmission (IoT)
Flip cardA vulnerability in IoT devices where data is transmitted between devices or to cloud services without proper encryption or authentication, making it susceptible to eavesdropping and tampering.
- Often due to weak or absent encryption protocols.
- Can expose sensitive user data, device status, or operational information.
- Common in protocols like MQTT or CoAP if not secured properly.
Memory trick: IoT devices need strong locks and secure roads for their data journeys.
APT Malware
Flip cardMalware used in Advanced Persistent Threat (APT) campaigns, characterized by stealth, persistence, modularity, and sophisticated evasion techniques.
- Designed for long-term, targeted espionage or sabotage.
- Often highly modular, allowing for flexible updates and new capabilities.
- Employs advanced evasion and persistence mechanisms.
Memory trick: APTs are Adaptable, Persistent, and Modular.
IoT Insecure Authorization
Flip cardA vulnerability in IoT devices where commands or access to resources are not properly authenticated or authorized, allowing unauthorized users to control the device or access its data.
- Devices accept commands from any source without verifying identity.
- Can lead to unauthorized control, data manipulation, or denial of service.
- Often due to simplified design for ease of use, neglecting security.
Memory trick: No 'auth' on IoT commands is like an open door to the smart light.
Logic Bomb
Flip cardA malicious program or code segment that lies dormant until a specific condition is met, then executes its payload.
- Triggered by specific events (e.g., date, time, user action).
- Often embedded in legitimate software.
- Can cause significant damage upon activation.
Memory trick: Logic bombs wait for a specific moment to explode.
Mobile App Local Storage Inspection
Flip cardThe process of examining an installed mobile application's private data directories on a device to identify insecure storage of sensitive information.
- Requires a rooted/jailbroken device for full access to app's data.
- Targets databases (SQLite), shared preferences, cached files.
- Identifies vulnerabilities like unencrypted credentials, API keys, PII.
Memory trick: Rooted access opens the app's 'data cabinet' for inspection.
Android Kernel Exploit
Flip cardA software vulnerability in the Android operating system's kernel that can be leveraged by malicious applications to gain unauthorized root privileges on the device.
- Bypasses standard Android security mechanisms.
- Grants full control over the device and its data.
- Often involves complex low-level programming to interact with kernel memory.
Memory trick: To root an unrooted Android, the 'kernel' is the king's weak spot.
Client-side Exploit
Flip cardAn attack that targets vulnerabilities in software applications running on a user's computer (the 'client'), such as web browsers, email clients, or document viewers, to gain control or install malware.
- Relies on user interaction (e.g., opening a malicious file, visiting a compromised website).
- Targets common applications like PDF readers, browsers, office suites.
- Often uses techniques like heap spray or remote code execution.
Memory trick: Client-side attacks hit the user's app, not the server's back.
Air Gap with Data Diode (OT Security)
Flip cardAn air gap is a security measure that isolates a secure network from unsecured networks. A data diode is a hardware device that enforces unidirectional data flow, often used to bridge an air gap for monitoring purposes without allowing reverse communication.
- Provides extreme network isolation for critical systems.
- Data diodes are hardware-enforced, preventing software misconfiguration.
- Commonly used in OT/ICS environments to protect against cyberattacks from IT networks.
Memory trick: Separate critical controls like a power plant, with a one-way gate for safety.
Ransomware
Flip cardA type of malicious software that encrypts a victim's files or locks their system, then demands a ransom payment (often in cryptocurrency) in exchange for decryption or access restoration.
- Encrypts files or locks system access.
- Demands payment, usually cryptocurrency.
- Can spread via phishing, compromised websites, or exploits.
Memory trick: Ransomware holds your data 'for ransom', demanding crypto cash.
Dynamic Malware Analysis
Flip cardThe process of executing malware in a controlled environment (e.g., sandbox, virtual machine) to observe and analyze its real-time behavior, including API calls, network activity, and file system changes.
- Effective against obfuscated and polymorphic malware.
- Requires a safe, isolated environment.
- Provides insights into runtime functionality and evasive techniques.
Memory trick: To see the 'dynamic' dance, you must make it perform.
Polymorphic Malware
Flip cardMalware that changes its internal structure and signature with each infection, while retaining its original functionality.
- Uses encryption and different decryption routines.
- Evades signature-based detection.
- Its 'shape' changes, but its 'purpose' remains constant.
Memory trick: Polymorphs Change Shapes, Avoid Detection.
OT Man-in-the-Middle
Flip cardAn attack where an adversary intercepts and potentially alters communication between two OT components, such as an HMI and a PLC/RTU, often leveraging unencrypted or unauthenticated protocols.
- Allows eavesdropping on critical industrial commands and data.
- Enables modification of commands to cause physical disruption.
- Often facilitated by lack of encryption and strong authentication in OT protocols.
Memory trick: Unencrypted OT talks, the 'middle' listens and lies.
Privilege Escalation
Flip cardPrivilege escalation is the act of exploiting a bug, design flaw, or configuration oversight in an operating system or application to gain elevated access to resources that are normally protected from an application or user.
- Can be vertical (to higher privileges) or horizontal (to another user's privileges).
- Often involves exploiting kernel vulnerabilities, misconfigurations, or unpatched software.
- A critical step after initial compromise to gain full control.
Memory trick: Elevate, control, move, hide!
Process Hollowing/Spoofing
Flip cardProcess hollowing (or runpe) is a code injection technique where an attacker creates a legitimate process in a suspended state, hollows out its legitimate code, and then injects and executes malicious code within that process's memory space.
- Aims to evade detection by security software (antivirus, EDR).
- Makes malicious activity appear as legitimate system processes.
- Often involves creating a new process from a legitimate binary in an unusual location, then injecting malicious code.
Memory trick: Malware in disguise, hiding in plain sight!
Dynamic Application Security Testing (DAST)
Flip cardA security testing method that analyzes a running application from the outside by simulating attacks and observing its behavior, without access to the source code.
- Identifies runtime vulnerabilities such as SQL injection, XSS, and authentication flaws.
- Often used in black-box testing scenarios.
- Can be automated and integrated into CI/CD pipelines.
Memory trick: App security: Static for code, Dynamic for run, Interactive for both, Components for fun.
Clearing Logs
Flip cardClearing logs is a post-exploitation activity where an attacker attempts to remove or modify system and application log files to hide their presence and activities on a compromised system.
- Aims to evade detection by security monitoring tools and forensic analysis.
- Can involve deleting, truncating, or modifying log entries.
- Is a common tactic in the 'Clearing Tracks' phase of an attack.
Memory trick: No trace left behind, the ghost was here!
File Integrity Monitoring
Flip cardThe process of validating the integrity of operating system and application software files by comparing their current state to a known, trusted baseline.
- Detects unauthorized changes, deletions, or additions to files.
- Often uses cryptographic hashes (e.g., MD5, SHA256) for comparison.
- Crucial for detecting rootkits and other persistent malware.
Memory trick: To 'analyze' system files for 'integrity', use a 'tripwire' to catch changes.
Gaining Access
Flip cardThe phase in system hacking where an attacker successfully exploits a vulnerability or uses stolen credentials to obtain initial entry into a target system or network.
- Involves direct interaction with the target system (e.g., exploiting, logging in).
- Can be achieved through various means like brute-force, phishing, or software exploits.
- Marks the transition from external probing to internal presence.
Memory trick: To 'get in', you need to 'open the door' (gain access).
Cron Job Misconfiguration
Flip cardA vulnerability where scheduled tasks (cron jobs) on Linux systems are configured to run scripts or commands with elevated privileges (e.g., root) from locations that are writable by lower-privileged users, allowing for privilege escalation.
- Often involves scripts with overly permissive file permissions (e.g., 777).
- Attackers can inject malicious code into the script to be executed as root.
- A common method for local privilege escalation on Linux systems.
Memory trick: Linux escalation: SUID for root, Cron for scripts, Kernel for deep, SUDO for rules.
SYN Stealth Scan (Nmap -sS)
Flip cardA port scanning technique where the scanner sends a SYN packet and analyzes the target's response (SYN/ACK or RST) without completing the TCP three-way handshake, making it less detectable.
- Also known as 'half-open' scanning.
- Less likely to be logged by firewalls and intrusion detection systems.
- Requires raw packet privileges (often root/administrator) to perform.
Memory trick: Scan choices: Connect is loud, SYN is sly, UDP for unknowns, ARP for nearby.
Maintaining Access (Persistence)
Flip cardThe phase in system hacking where an attacker establishes mechanisms to retain control over a compromised system, even if the system is rebooted, patched, or if initial exploits are addressed.
- Ensures long-term control over the target.
- Often involves creating backdoors, modifying system configurations, or establishing covert channels.
- Aims to survive system reboots and administrative actions.
Memory trick: To keep the 'keys' to the kingdom, create a 'backdoor' for re-entry.
Data Carving (Foremost)
Flip cardThe process of extracting files or fragments of files from raw data (like a disk image) based on their file type headers, footers, and internal data structures, even if the file system metadata has been deleted.
- Foremost is a popular open-source tool for data carving.
- Useful for recovering deleted files from compromised systems.
- Works on raw disk images or directly on devices.
Memory trick: Recover files: Carving for deleted, Grep for text, Strings for binary, ls for existing.
Vulnerability Analysis
Flip cardVulnerability analysis is the process of identifying and evaluating security weaknesses in a system, application, or network.
- Precedes exploitation efforts.
- Aims to discover potential entry points.
- Can use automated tools or manual techniques.
Memory trick: Recon, Scan, Gain, Maintain, Clear, Cover your tracks!
Security Information and Event Management (SIEM)
Flip cardA security solution that provides real-time analysis of security alerts generated by network hardware and applications, centralizing log management and correlating events to detect threats.
- Aggregates logs from disparate sources.
- Provides centralized visibility and correlation.
- Aids in compliance reporting and incident response.
Memory trick: To 'see everything' and 'manage events', you need a 'SIEM'.
Persistence Mechanisms (Windows)
Flip cardMethods used by attackers to ensure their malicious code continues to run or can be reactivated on a Windows system after reboots or user logoffs.
- Registry Run keys are popular for auto-starting programs.
- Scheduled Tasks can execute payloads at specific times or events.
- Windows Services can run in the background with high privileges.
Memory trick: To 'stay on' Windows, you need to 'register' your presence or 'schedule' yourself.
Maintaining Access
Flip cardThe phase of system hacking where an attacker establishes mechanisms to ensure persistent access to a compromised system, even after initial exploits are remediated.
- Involves creating backdoors, rootkits, or new user accounts.
- Aims to ensure future access and control over the target system.
- Often includes modifying system configurations or installing persistent malware.
Memory trick: Recon, Scan, Gain, Maintain, Clear, Cover – the hacker's stair.
Scheduled Task Abuse
Flip cardExploiting misconfigured scheduled tasks on a system to execute malicious code with elevated privileges, typically by replacing the legitimate script or executable.
- Often involves tasks running with SYSTEM or administrator privileges.
- Vulnerable if the task's executable path is writable by low-privileged users.
- Common in Windows environments, but also applicable to cron jobs in Linux.
Memory trick: Elevate your access, bypass the gate, exploit the weak link, seal your fate.
Manual Penetration Testing
Flip cardA proactive and authorized attempt to find security weaknesses in a system by simulating real-world attacks using human expertise, creativity, and knowledge of attacker methodologies.
- Identifies complex, chained, and logical vulnerabilities.
- Requires skilled human testers.
- Provides deeper insights into potential attack paths than automated tools.
Memory trick: For 'deep' insights, you need 'human' intelligence, not just 'robot' scanning.
Gaining Access (Initial Foothold)
Flip cardGaining Access is the phase in which an attacker successfully exploits a vulnerability to enter a system or network, establishing an initial foothold.
- Follows reconnaissance and scanning phases.
- Involves exploiting identified vulnerabilities.
- The primary goal is to get initial entry, often a low-privileged shell.
Memory trick: Find the door, unlock it, get a foot inside!
Clearing Linux Logs (Stealth)
Flip cardTechniques used by attackers to remove or modify evidence of their presence from Linux system logs and command histories while attempting to minimize detection by forensic analysis.
- Involves direct manipulation of log files to remove specific entries.
- Disabling or redirecting command history logging.
- Aims to avoid obvious signs of tampering like mass deletion of files.
Memory trick: Anti-forensics: Logs edit, History null, Timestamps touch, Rootkits hide.
Windows Prefetch Files
Flip cardFiles created by the Windows operating system to speed up application startup. They contain information about the executable, its run count, and the files/directories it accessed during the first 10 seconds of execution.
- Located in C:\Windows\Prefetch.
- Contain strong evidence of program execution.
- Difficult for attackers to completely eradicate without leaving traces.
Memory trick: To 'see' what 'ran' on Windows, 'prefetch' the execution data.