EC-Council Certified Ethical Hacker (CEH) v12 flashcards
189 free flashcards. Tap a card to flip it.
Lateral Movement
Flip cardThe technique used by attackers to navigate through a compromised network, moving from one system to another to gain access to more valuable assets or expand their control.
- Often involves exploiting legitimate credentials or vulnerabilities.
- Aims to reach high-value targets or establish broader control.
- Tools like PsExec, Windows Admin Shares, and RDP are commonly used.
Memory trick: After 'getting in', you need to 'move around' to find what you want.
File Integrity Monitoring (FIM)
Flip cardA security control that monitors and detects unauthorized or suspicious changes to critical system files, configuration files, and content files by comparing their current state against a known, trusted baseline.
- Uses hashing algorithms to create file baselines.
- Alerts administrators to any deviations from the baseline.
- Essential for detecting rootkits, malware, and unauthorized system modifications.
Memory trick: Host security: FIM for files, HIDS for events, Antivirus for malware, Firewall for access.
Vulnerability Identification
Flip cardThe initial step in vulnerability analysis where potential security weaknesses are discovered through various methods, such as scanning, manual review, or comparing software versions against known vulnerability databases.
- Involves discovering outdated software, misconfigurations, or known CVEs.
- Often uses automated scanners or manual checks.
- Aims to create a list of potential vulnerabilities.
Memory trick: Identify, Verify, Prioritize, Remediate, Report, Repeat – the vuln cycle's beat.
DLL Side-Loading (DLL Search Order Hijacking)
Flip cardAn attack technique where a malicious Dynamic Link Library (DLL) is placed in a specific directory so that a legitimate application loads it instead of the intended DLL, often due to vulnerabilities in the DLL search order.
- Exploits the order in which Windows searches for DLLs.
- Allows attackers to execute arbitrary code within a trusted process.
- Often effective against applications with weak DLL loading practices or that are vulnerable to search order hijacking.
Memory trick: Code execution: DLL Side-Load for libraries, Process Hollowing for stealth, Injection for hooks, Shellcode for raw.
Web Application Vulnerability Scanner
Flip cardAutomated tools designed to discover security flaws within web applications, including common vulnerabilities like SQL injection, XSS, and broken authentication.
- Interacts with web applications via HTTP/S.
- Identifies vulnerabilities in application code and configuration.
- Examples include Burp Suite, OWASP ZAP, Acunetix.
Memory trick: To 'scan' for 'web' flaws, use a 'web app' specific tool.
Windows Service Persistence
Flip cardEstablishing a persistent backdoor on a Windows system by creating or modifying a legitimate service to execute malicious code, ensuring it runs automatically upon system startup.
- Services run in the background, often with SYSTEM privileges.
- They are designed to start automatically with the operating system.
- Can be created using tools like `sc.exe` or `New-Service` in PowerShell.
- Difficult to detect without specific monitoring of service creation/modification.
Memory trick: Windows attackers love services, startups, and scheduled tasks to stay hidden.
Credential Dumping (Mimikatz)
Flip cardCredential dumping is the process of extracting user logon credentials (e.g., password hashes, plaintext passwords, Kerberos tickets) from a compromised system's memory or storage.
- Mimikatz is a primary tool for this on Windows systems.
- Often targets the Local Security Authority Subsystem Service (LSASS) process.
- A critical step for lateral movement and privilege escalation in Active Directory environments.
Memory trick: Memory holds secrets, Mimikatz reveals them!
Payload Obfuscation
Flip cardThe technique of altering the appearance of a malicious payload (e.g., by encoding, encryption, or character manipulation) to evade detection by security mechanisms like WAFs or antivirus software, while retaining its original malicious functionality.
- Aims to bypass signature-based detection.
- Commonly uses encoding (URL, Base64), encryption, or string concatenation.
- Crucial for advanced exploitation against robust defenses.
Memory trick: To 'hide' your 'attack', you need to 'disguise' the payload.
Clearing Logs (Linux)
Flip cardThe process of removing or altering log entries on a Linux system to erase forensic evidence of an attacker's activities, making it harder to detect and trace the intrusion.
- Targets system logs (e.g., `auth.log`, `syslog`).
- Targets login records (`utmp`, `wtmp`, `btmp`).
- Can involve using tools like `logrotate` or direct file manipulation.
Memory trick: To 'erase' your 'footprints', clean up the 'login records'.