Proctored Exam
An exam supervised to ensure fairness and prevent cheating.
Getting Started: Your CEH v12 Journey
Free knowledge base
Everything from the course in one searchable place: 526 entries. Use it to review before a practice test or look up a word you forgot.
526 results · showing first 300, refine your search
An exam supervised to ensure fairness and prevent cheating.
Getting Started: Your CEH v12 Journey
Exam scoring where question difficulty influences passing score.
Getting Started: Your CEH v12 Journey
Percentage indicating the importance of an exam topic area.
Getting Started: Your CEH v12 Journey
A separate, hands-on exam for applying ethical hacking skills.
Getting Started: Your CEH v12 Journey
Designation for passing both CEH multiple-choice and practical exams.
Getting Started: Your CEH v12 Journey
Official document detailing exam topics and objectives.
Getting Started: Your CEH v12 Journey
The official exam code for the CEH v12 multiple-choice exam.
Getting Started: Your CEH v12 Journey
To remember the exam details: '1-2-5 questions, 4 hours to strive, 60 to 85 to stay alive!'
Getting Started: Your CEH v12 Journey
The CEH v12 exam has 125 multiple-choice questions and a 4-hour time limit. The passing score is variable, typically between 60-85%. Memorize the top three weighted domains: Footprinting and Reconnaissance (21%), Scanning Networks (16%), and Enumeration (10%).
Getting Started: Your CEH v12 Journey
Underestimating the importance of lower-weighted domains; while less frequent, questions from these domains still count.
Getting Started: Your CEH v12 Journey
Not practicing hands-on skills, even if not immediately taking the CEH Practical; practical application solidifies theoretical knowledge.
Getting Started: Your CEH v12 Journey
Focusing solely on memorization without understanding the underlying concepts and why certain tools or techniques are used.
Getting Started: Your CEH v12 Journey
Running multiple OS on one physical machine.
Getting Started: Your CEH v12 Journey
Software managing virtual machines and resources.
Getting Started: Your CEH v12 Journey
A software-based, emulated computer system.
Getting Started: Your CEH v12 Journey
The operating system running on the physical hardware.
Getting Started: Your CEH v12 Journey
An operating system running inside a VM.
Getting Started: Your CEH v12 Journey
A Linux distribution for penetration testing.
Getting Started: Your CEH v12 Journey
A saved state of a VM at a specific point in time.
Getting Started: Your CEH v12 Journey
To remember lab components: 'H.H.A.T.' – Host, Hypervisor, Attacker, Target. You need a HAT to hack!
Getting Started: Your CEH v12 Journey
EC-Council emphasizes practical skills. Expect questions on identifying appropriate tools (e.g., Kali Linux for attacking, Metasploitable for target) and the benefits of virtualization (e.g., isolation, snapshots) for lab setups.
Getting Started: Your CEH v12 Journey
Not allocating enough RAM or CPU to virtual machines, leading to slow performance.
Getting Started: Your CEH v12 Journey
Connecting lab VMs directly to the internet, risking exposure or legal issues.
Getting Started: Your CEH v12 Journey
Forgetting to take snapshots before performing potentially destructive tests.
Getting Started: Your CEH v12 Journey
A potential danger that could exploit a vulnerability.
Foundations of Information Security & Hacking
A weakness in a system that can be exploited.
Foundations of Information Security & Hacking
The path or means by which an attacker gains access.
Foundations of Information Security & Hacking
Unauthorized access to or manipulation of systems.
Foundations of Information Security & Hacking
Hacking with permission to identify vulnerabilities.
Foundations of Information Security & Hacking
Initial phase of gathering information about a target.
Foundations of Information Security & Hacking
Manipulating people to divulge info or perform actions.
Foundations of Information Security & Hacking
Malicious software designed to disrupt, damage, or gain access.
Foundations of Information Security & Hacking
To remember the hacking phases: 'R S G M C' - Really Smart Guys Make Coffee (Reconnaissance, Scanning, Gaining Access, Maintaining Access, Covering Tracks).
Foundations of Information Security & Hacking
The CEH exam frequently asks about the phases of ethical hacking and the CIA triad. Memorize the order of the hacking phases and understand what each phase entails. For the CIA triad, remember Confidentiality, Integrity, and Availability and what each component protects.
Foundations of Information Security & Hacking
Confusing a threat with a vulnerability; a threat is the 'who or what' (e.g., hacker), a vulnerability is the 'weakness' (e.g., unpatched software).
Foundations of Information Security & Hacking
Underestimating the human element in security; social engineering is a highly effective attack vector.
Foundations of Information Security & Hacking
Not understanding the distinct actions performed in each phase of the hacking methodology.
Foundations of Information Security & Hacking
Safeguards to protect confidentiality, integrity, and availability of assets.
Foundations of Information Security & Hacking
Policies, procedures, and guidelines for managing security.
Foundations of Information Security & Hacking
Hardware or software mechanisms enforcing security policies.
Foundations of Information Security & Hacking
Measures to protect physical access to systems and assets.
Foundations of Information Security & Hacking
Controls designed to stop an incident from occurring.
Foundations of Information Security & Hacking
Controls designed to identify and alert about an incident.
Foundations of Information Security & Hacking
Controls designed to minimize impact and restore systems after an incident.
Foundations of Information Security & Hacking
To remember the control types, think 'APT': **A**dministrative (policies), **P**hysical (locks), **T**echnical (firewalls).
Foundations of Information Security & Hacking
The CEH exam frequently tests the classification of controls. Memorize the definitions and examples for administrative, technical, and physical controls, and their functions (preventative, detective, corrective). Look for keywords describing policies, software, or physical barriers.
Foundations of Information Security & Hacking
Confusing the type of control (e.g., administrative vs. technical) with its function (e.g., preventative vs. detective).
Foundations of Information Security & Hacking
Assuming ethical hacking is just about finding vulnerabilities; it also includes reporting and remediation guidance.
Foundations of Information Security & Hacking
Underestimating the importance of administrative controls; technology alone cannot solve all security problems.
Foundations of Information Security & Hacking
General Data Protection Regulation; EU law on data protection and privacy.
Foundations of Information Security & Hacking
California Consumer Privacy Act; US law on consumer data rights.
Foundations of Information Security & Hacking
Health Insurance Portability and Accountability Act; US law protecting health data.
Foundations of Information Security & Hacking
Computer Fraud and Abuse Act; US law prohibiting unauthorized computer access.
Foundations of Information Security & Hacking
Explicit, documented permission to perform an action.
Foundations of Information Security & Hacking
Principles guiding professional conduct and decision-making.
Foundations of Information Security & Hacking
To remember key laws: 'G-C-H-C' - GDPR, CCPA, HIPAA, CFAA. Think of it as 'Good Cyber Hygiene Counts!'
Foundations of Information Security & Hacking
The CEH exam frequently tests your understanding of the legal implications of hacking. Look for keywords like 'authorization,' 'consent,' 'scope,' and 'reporting' in questions related to penetration testing. Memorize that unauthorized access, even without malicious intent, is illegal.
Foundations of Information Security & Hacking
Assuming good intentions justify unauthorized access.
Foundations of Information Security & Hacking
Failing to obtain explicit, written authorization before any security assessment.
Foundations of Information Security & Hacking
Not understanding the scope of an engagement and exceeding it.
Foundations of Information Security & Hacking
A framework outlining the seven phases of a typical cyberattack.
Foundations of Information Security & Hacking
A knowledge base of adversary tactics and techniques based on real-world observations.
Foundations of Information Security & Hacking
A structured approach or framework describing how cyberattacks are conducted.
Foundations of Information Security & Hacking
The process of combining an exploit with a payload for delivery.
Foundations of Information Security & Hacking
The communication channel between an attacker and a compromised system.
Foundations of Information Security & Hacking
A comprehensive framework integrating multiple attack models.
Foundations of Information Security & Hacking
Remember the Cyber Kill Chain with 'R W D E I C A': Really Wicked Dragons Eat Icy Cold Apples!
Foundations of Information Security & Hacking
The CEH exam frequently tests knowledge of the Cyber Kill Chain phases and their order. Be prepared to identify what happens in each phase and recognize common attack vectors associated with them, especially 'Delivery' and 'Exploitation'.
Foundations of Information Security & Hacking
Confusing the linear nature of the Cyber Kill Chain with the more granular, matrix-based MITRE ATT&CK framework.
Foundations of Information Security & Hacking
Underestimating the importance of 'Reconnaissance' – often seen as passive, but critical for an attacker's success.
Foundations of Information Security & Hacking
Failing to understand that a single attack can involve multiple attack vectors and techniques across different phases.
Foundations of Information Security & Hacking
Gathering information about a target before an attack or assessment.
Mastering Footprinting Techniques
Collecting information without direct interaction with the target system.
Mastering Footprinting Techniques
Collecting information through direct interaction with the target system.
Mastering Footprinting Techniques
Open-Source Intelligence; information gathered from publicly available sources.
Mastering Footprinting Techniques
The sum of all possible points where an unauthorized user can try to enter or extract data.
Mastering Footprinting Techniques
A public database containing registration details for domain names and IP addresses.
Mastering Footprinting Techniques
P.A.S.S.I.V.E. = Publicly Available Sources Systematically Searched for Information Via Everything.
Mastering Footprinting Techniques
The CEH exam frequently tests the distinction between passive and active reconnaissance. Remember that 'passive' means no direct contact with the target, leaving no logs or traces on their systems. Keywords like 'publicly available,' 'OSINT,' 'search engines,' and 'social media' usually point to passive methods.
Mastering Footprinting Techniques
Confusing passive and active footprinting: Passive means no direct interaction, active means direct interaction.
Mastering Footprinting Techniques
Underestimating the amount of information available publicly: Many organizations leak more than they realize.
Mastering Footprinting Techniques
Skipping footprinting: This critical first step saves time and increases effectiveness in later phases.
Mastering Footprinting Techniques
Gathering information from a target's Domain Name System.
Mastering Footprinting Techniques
A powerful network scanner for host discovery and port scanning.
Mastering Footprinting Techniques
Identifying open ports on a network host.
Mastering Footprinting Techniques
Determining specific services and their versions running on ports.
Mastering Footprinting Techniques
Tool to identify known security weaknesses in systems.
Mastering Footprinting Techniques
Automated program to browse and index web content.
Mastering Footprinting Techniques
Nmap Needs More Ports! (Nmap for Network Mapping, identifying open Ports).
Mastering Footprinting Techniques
The CEH exam frequently tests the functionality and common uses of specific tools. Memorize that Nmap is for network scanning, nslookup/dig for DNS, and Nessus/OpenVAS for vulnerability scanning.
Mastering Footprinting Techniques
Confusing active reconnaissance with passive reconnaissance; active involves direct interaction.
Mastering Footprinting Techniques
Using aggressive scanning techniques without proper authorization, which can be illegal or trigger alerts.
Mastering Footprinting Techniques
Failing to document findings from active scans, making it difficult to analyze and report vulnerabilities.
Mastering Footprinting Techniques
The trail of data left by online activities.
Mastering Footprinting Techniques
Service to hide domain registrant's personal info.
Mastering Footprinting Techniques
DNS process to replicate domain information.
Mastering Footprinting Techniques
Data about data, often hidden in files.
Mastering Footprinting Techniques
Proactive management of publicly available info.
Mastering Footprinting Techniques
Unintended disclosure of sensitive data.
Mastering Footprinting Techniques
To protect your FOOTPRINT, remember P.R.I.V.A.C.Y.: Protect WHOIS, Restrict DNS, Inspect Metadata, Vet Public Info, Audit Regularly, Control Social Media, Yield Less Data.
Mastering Footprinting Techniques
The CEH exam often asks about specific countermeasures for common footprinting techniques. Memorize that disabling DNS zone transfers, using WHOIS privacy, and reviewing public documents for metadata are key defenses. Look for questions about 'preventing information disclosure' or 'reducing attack surface'.
Mastering Footprinting Techniques
Forgetting to check metadata in publicly shared documents (e.g., PDFs, images).
Mastering Footprinting Techniques
Underestimating the amount of information employees share on personal social media.
Mastering Footprinting Techniques
Believing that obscurity alone is a strong security measure; active defense is needed.
Mastering Footprinting Techniques
Analysis of satellite imagery and geographic data for physical reconnaissance.
Mastering Footprinting Techniques
Government-maintained documents available for public inspection, e.g., business filings.
Mastering Footprinting Techniques
Gathering intelligence on a target's vendors and partners to find indirect attack vectors.
Mastering Footprinting Techniques
Retrieving hidden information from files (e.g., images, documents) that reveals details.
Mastering Footprinting Techniques
Platforms like LinkedIn used to map organizational structures and individual roles.
Mastering Footprinting Techniques
Searching illicit online forums for mentions of a target or leaked credentials.
Mastering Footprinting Techniques
A formal document outlining the scope, limits, and authorization for a penetration test.
Mastering Footprinting Techniques
Combining diverse open-source intelligence sources to form a complete picture.
Mastering Footprinting Techniques
Remember 'P.O.S.T. G.A.P.' for advanced footprinting: Public Records, OSINT, Supply Chain, Technical, Geospatial, Authorization, Privacy.
Mastering Footprinting Techniques
The CEH exam often presents scenario-based questions where you must select the most appropriate footprinting technique for a given situation. Pay close attention to keywords like 'physical security,' 'personnel information,' or 'third-party risk' to guide your answer.
Mastering Footprinting Techniques
Failing to document all gathered information, leading to missed connections or redundant efforts.
Mastering Footprinting Techniques
Crossing legal or ethical boundaries by attempting unauthorized access or social engineering without explicit permission.
Mastering Footprinting Techniques
Over-relying on a single source of information without cross-referencing or validating data from multiple sources.
Mastering Footprinting Techniques
Process of identifying active devices, open ports, and services on a network.
Network Scanning & Enumeration
Half-open scan that doesn't complete the TCP handshake; stealthy.
Network Scanning & Enumeration
Completes the full TCP three-way handshake; less stealthy but reliable.
Network Scanning & Enumeration
Sends UDP packets to determine the state of UDP ports.
Network Scanning & Enumeration
Indicates whether a port is open, closed, or filtered.
Network Scanning & Enumeration
A port blocked by a firewall or other network device.
Network Scanning & Enumeration
Think of port states like a traffic light: Green is 'Open' (go ahead, connect!), Red is 'Closed' (stop, nothing there), and Yellow is 'Filtered' (caution, something is blocking the way!).
Network Scanning & Enumeration
Memorize the characteristics of TCP SYN scan (stealthy, half-open, common for ethical hackers) and TCP Connect scan (full connect, reliable, noisy). The exam often asks to differentiate these or identify which is less likely to be logged by a target.
Network Scanning & Enumeration
Confusing TCP SYN scan with TCP Connect scan: SYN is 'half-open' and stealthier; Connect is 'full-open' and noisier.
Network Scanning & Enumeration
Ignoring UDP scans: While often less reliable, UDP services (like DNS, SNMP) are common attack vectors and must be scanned.
Network Scanning & Enumeration
Misinterpreting 'Filtered' port state: This doesn't mean the port is necessarily closed, just that a firewall is preventing you from knowing its true state.
Network Scanning & Enumeration
Command-line tool for crafting and sending custom TCP/IP packets.
Network Scanning & Enumeration
Fast, asynchronous TCP/UDP port scanner for large networks.
Network Scanning & Enumeration
Commercial vulnerability scanner detecting misconfigurations and weaknesses.
Network Scanning & Enumeration
Open-source vulnerability assessment system, similar to Nessus.
Network Scanning & Enumeration
Breaking large packets into smaller ones to evade IDS/IPS detection.
Network Scanning & Enumeration
Using spoofed IP addresses to hide the true source of a scan.
Network Scanning & Enumeration
Routing network traffic through multiple proxy servers for anonymity.
Network Scanning & Enumeration
The Onion Router, an anonymizing network for internet traffic.
Network Scanning & Enumeration
To remember evasion techniques: 'F-D-P-T': Fragmentation, Decoys, Proxies, Time delays. Think of 'Fighting Drones, Protecting Targets'.
Network Scanning & Enumeration
The CEH exam often tests knowledge of specific tool names and their primary functions. Memorize the key capabilities of Hping3, Unicornscan, Nessus, and OpenVAS. Be prepared to identify evasion techniques like IP fragmentation and decoy IPs.
Network Scanning & Enumeration
Underestimating the importance of slow/randomized scanning; many IDS/IPS systems are tuned to detect rapid, sequential scans.
Network Scanning & Enumeration
Assuming all proxies provide complete anonymity; some proxies log traffic or are easily traceable.
Network Scanning & Enumeration
Not testing evasion techniques against the actual target's security controls, leading to false assumptions about effectiveness.
Network Scanning & Enumeration
Network security system controlling traffic.
Network Scanning & Enumeration
Monitors network traffic for suspicious activity.
Network Scanning & Enumeration
Detects and actively blocks malicious traffic.
Network Scanning & Enumeration
Splitting packets to evade detection.
Network Scanning & Enumeration
Using spoofed source IPs to hide scanner.
Network Scanning & Enumeration
Sending probes at very low rates to evade.
Network Scanning & Enumeration
Examines data part of packets for content.
Network Scanning & Enumeration
F.I.D.S. (Firewall, IDS, Decoy, Slow scan) – Remember these four key defenses and evasions for network scanning.
Network Scanning & Enumeration
Memorize the core difference between IDS (detection) and IPS (prevention/blocking). For the exam, understand that fragmentation, decoy, and slow scans are primary IDS/IPS evasion techniques. Keywords like 'alerting' vs. 'blocking' are key.
Network Scanning & Enumeration
Assuming a firewall alone is sufficient protection against all scanning techniques.
Network Scanning & Enumeration
Ignoring IDS/IPS alerts, leading to undetected reconnaissance.
Network Scanning & Enumeration
Not understanding the difference between signature-based and anomaly-based detection.
Network Scanning & Enumeration
Failing to update and tune IDS/IPS rules, making them ineffective against new threats.
Network Scanning & Enumeration
Process of extracting detailed information about a target system or network.
Network Scanning & Enumeration
Protocol used for naming, discovery, and session services on small networks.
Network Scanning & Enumeration
Server Message Block, a network file sharing protocol often abused for enumeration.
Network Scanning & Enumeration
Lightweight Directory Access Protocol, used to query and modify directory services.
Network Scanning & Enumeration
Simple Network Management Protocol, used for managing network devices.
Network Scanning & Enumeration
A password used to authenticate to an SNMP device, often 'public' or 'private' by default.
Network Scanning & Enumeration
Technique to retrieve information about a service by connecting to it and examining its response.
Network Scanning & Enumeration
Remember 'E.N.U.M.E.R.A.T.E.' for key protocols: **E**very **N**etwork **U**ses **M**any **E**numerated **R**esources **A**nd **T**ools **E**asily.
Network Scanning & Enumeration
The CEH exam frequently tests knowledge of common enumeration protocols (SMB, SNMP, LDAP, DNS, SMTP) and their associated tools (e.g., Enum4linux, snmpwalk, ldapsearch). Be prepared to identify which protocol is used for what type of information gathering.
Network Scanning & Enumeration
Failing to disable unnecessary services, leaving open enumeration vectors.
Network Scanning & Enumeration
Using default or weak community strings for SNMP, exposing device details.
Network Scanning & Enumeration
Not implementing rate limiting, allowing attackers to brute-force enumeration attempts.
Network Scanning & Enumeration
Software or data that takes advantage of a vulnerability.
Vulnerability Analysis & System Exploitation
A scan result indicating a vulnerability that isn't actually present.
Vulnerability Analysis & System Exploitation
Common Vulnerability Scoring System, for severity ranking.
Vulnerability Analysis & System Exploitation
The process of fixing or mitigating identified vulnerabilities.
Vulnerability Analysis & System Exploitation
List of the most critical web application security risks.
Vulnerability Analysis & System Exploitation
To remember the assessment cycle: 'P-S-A-R-R-R' – 'Please Scan All Reports, Remediate, Re-verify.'
Vulnerability Analysis & System Exploitation
The CEH exam frequently tests on the phases of a vulnerability assessment life cycle and the common tools used. Remember the sequence: Planning, Scanning, Analysis, Reporting, Remediation, Re-assessment. Also, be familiar with the primary function of tools like Nessus, OpenVAS, and Nmap.
Vulnerability Analysis & System Exploitation
Ignoring false positives: Always verify findings to avoid wasting time on non-existent issues.
Vulnerability Analysis & System Exploitation
Not prioritizing vulnerabilities: Focus on high-risk items first, don't try to fix everything at once.
Vulnerability Analysis & System Exploitation
Forgetting re-assessment: Always re-scan after remediation to confirm fixes and avoid regressions.
Vulnerability Analysis & System Exploitation
Fraudulent emails to trick recipients into revealing info.
Vulnerability Analysis & System Exploitation
Leveraging weaknesses in systems or software to gain access.
Vulnerability Analysis & System Exploitation
Using leaked username/password pairs from other breaches.
Vulnerability Analysis & System Exploitation
Compromising a trusted vendor to attack their customers.
Vulnerability Analysis & System Exploitation
Cybercriminal selling initial access to compromised networks.
Vulnerability Analysis & System Exploitation
Exploit for a vulnerability unknown to the vendor.
Vulnerability Analysis & System Exploitation
Remember 'SPAM' for common initial access: Social engineering, Physical access, Application/System exploits, Malware.
Vulnerability Analysis & System Exploitation
The CEH exam often tests knowledge of common initial access vectors and the difference between active and passive reconnaissance. Memorize specific social engineering techniques and the role of unpatched systems.
Vulnerability Analysis & System Exploitation
Underestimating the effectiveness of social engineering techniques.
Vulnerability Analysis & System Exploitation
Neglecting physical security as a potential initial access vector.
Vulnerability Analysis & System Exploitation
Failing to conduct thorough reconnaissance before attempting technical exploits.
Vulnerability Analysis & System Exploitation
Techniques to maintain access to a system after reboots or disconnections.
Vulnerability Analysis & System Exploitation
A hidden method to bypass normal authentication for remote access.
Vulnerability Analysis & System Exploitation
Malware providing comprehensive remote control over a compromised system.
Vulnerability Analysis & System Exploitation
A script uploaded to a web server for remote command execution via a browser.
Vulnerability Analysis & System Exploitation
A stealthy set of tools designed to hide its presence and maintain privileged access.
Vulnerability Analysis & System Exploitation
A Linux/macOS utility for scheduling commands to run periodically.
Vulnerability Analysis & System Exploitation
Windows registry entries that automatically launch programs at startup.
Vulnerability Analysis & System Exploitation
To 'Persist' in 'Backdoor' access, remember: 'RATS' (Remote Access Trojans) 'HIDE' (Hardware, IDS bypass, Drivers, Executables) in 'WEBS' (Web shells, Windows Services, Bootkits, Scheduled tasks).
Vulnerability Analysis & System Exploitation
The CEH exam frequently asks about specific Windows Registry keys used for persistence (e.g., HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). Memorize these common paths. Also, know the difference between a RAT and a web shell.
Vulnerability Analysis & System Exploitation
Forgetting to establish persistence, leading to loss of access after a system reboot.
Vulnerability Analysis & System Exploitation
Relying on only one persistence mechanism, which can be easily detected and removed.
Vulnerability Analysis & System Exploitation
Not properly cleaning up persistence mechanisms after a penetration test is complete, leaving a real vulnerability.
Vulnerability Analysis & System Exploitation
Gaining higher access than initially granted on a system.
Vulnerability Analysis & System Exploitation
Moving from lower to higher privilege levels (e.g., user to admin).
Vulnerability Analysis & System Exploitation
Accessing another user's account with similar privileges.
Vulnerability Analysis & System Exploitation
Special permission on Linux that runs an executable with the owner's permissions.
Vulnerability Analysis & System Exploitation
Windows vulnerability where spaces in service paths can lead to arbitrary code execution.
Vulnerability Analysis & System Exploitation
Windows tool to extract plaintext passwords, hash, PIN code, and kerberos tickets from memory.
Vulnerability Analysis & System Exploitation
Deleting or modifying system logs to remove traces of malicious activity.
Vulnerability Analysis & System Exploitation
Security principle granting minimum necessary permissions to users/processes.
Vulnerability Analysis & System Exploitation
P.E.A.C.E. - **P**rivileges **E**levated, **A**nonymity **C**overed, **E**vidence Erased. Remember the goal of post-exploitation!
Vulnerability Analysis & System Exploitation
Memorize common Windows privilege escalation techniques like unquoted service paths and Mimikatz, and Linux techniques like SUID/SGID binaries and kernel exploits. The exam often presents scenarios where you must identify the appropriate escalation method.
Vulnerability Analysis & System Exploitation
Forgetting to check for kernel exploits specific to the target's OS version.
Vulnerability Analysis & System Exploitation
Not thoroughly enumerating the system for all possible privilege escalation vectors.
Vulnerability Analysis & System Exploitation
Failing to clear relevant logs across all affected systems, leaving forensic evidence.
Vulnerability Analysis & System Exploitation
Software that delivers web content to clients via HTTP/S.
Web Server & Application Attacks
Protocols for transferring web data; HTTPS is secure.
Web Server & Application Attacks
Popular open-source web server software.
Web Server & Application Attacks
High-performance web server, often used as a reverse proxy.
Web Server & Application Attacks
Microsoft's proprietary web server for Windows.
Web Server & Application Attacks
Web Application Firewall; filters HTTP traffic for attacks.
Web Server & Application Attacks
Attack accessing files outside the web root.
Web Server & Application Attacks
Attacks overwhelming a server to make it unavailable.
Web Server & Application Attacks
To secure your Web Server, remember 'P-C-L-A-W': Patching, Configuration, Logging, Auditing, WAF.
Web Server & Application Attacks
The CEH exam frequently tests knowledge of common web server software (Apache, Nginx, IIS) and their default ports (HTTP 80, HTTPS 443). Be prepared to identify common attack types like DoS, directory traversal, and misconfiguration, and their corresponding countermeasures.
Web Server & Application Attacks
Forgetting to disable default accounts or unnecessary services.
Web Server & Application Attacks
Not regularly updating web server software and underlying OS.
Web Server & Application Attacks
Relying solely on network firewalls without a WAF for web application protection.
Web Server & Application Attacks
Client-server software accessed via a web browser.
Web Server & Application Attacks
Untrusted data sent to an interpreter, executing unintended commands.
Web Server & Application Attacks
Malicious SQL queries injected to control a database.
Web Server & Application Attacks
Malicious client-side scripts injected into web pages.
Web Server & Application Attacks
Vulnerabilities allowing attackers to assume user identities.
Web Server & Application Attacks
How an application handles user sessions; prone to hijacking.
Web Server & Application Attacks
For common web app attacks, remember 'I BAXS': Injection, Broken Authentication, XSS, Session Management.
Web Server & Application Attacks
The CEH exam frequently tests on the OWASP Top 10. Memorize the top 3-5 categories and be able to provide a brief description and an example attack for each. Pay close attention to Injection, Broken Authentication, and XSS.
Web Server & Application Attacks
Confusing server-side and client-side vulnerabilities; XSS is client-side, SQLi is server-side.
Web Server & Application Attacks
Underestimating the impact of seemingly minor vulnerabilities; they can often be chained for major exploits.
Web Server & Application Attacks
Forgetting that input validation is critical on both the client and server sides, but server-side validation is the ultimate defense.
Web Server & Application Attacks
An intermediary that intercepts and modifies HTTP/S traffic between a browser and server.
Web Server & Application Attacks
A popular integrated platform for web application security testing, including a proxy.
Web Server & Application Attacks
An open-source web application security scanner and proxy, maintained by OWASP.
Web Server & Application Attacks
Sending malformed or unexpected inputs to find vulnerabilities and crashes.
Web Server & Application Attacks
An open-source penetration testing tool that automates SQL injection detection and exploitation.
Web Server & Application Attacks
A tool designed for detecting, exploiting, and bypassing XSS vulnerabilities.
Web Server & Application Attacks
Software that crawls web apps to automatically find common vulnerabilities.
Web Server & Application Attacks
To remember key web app tools: 'P.A.F.S.' - Proxies, Automated scanners, Fuzzers, Specialized tools. Each has a distinct role!
Web Server & Application Attacks
The CEH exam frequently tests knowledge of specific tools like Burp Suite, OWASP ZAP, and SQLMap. Memorize their primary functions and what types of attacks they facilitate. Pay attention to their capabilities in interception, scanning, and exploitation.
Web Server & Application Attacks
Relying solely on automated scanners without manual verification, leading to false positives or missed complex flaws.
Web Server & Application Attacks
Not understanding how to properly configure a web proxy, resulting in missed traffic or incorrect interception.
Web Server & Application Attacks
Using a tool without understanding the underlying vulnerability it targets, making it difficult to interpret results or adapt to defenses.
Web Server & Application Attacks
Server-Side Request Forgery; server makes requests on attacker's behalf.
Web Server & Application Attacks
Application Programming Interface; set of rules for software interaction.
Web Server & Application Attacks
Broken Object-Level Authorization; accessing unauthorized resources by ID.
Web Server & Application Attacks
Broken Function-Level Authorization; accessing unauthorized administrative functions.
Web Server & Application Attacks
Insecure Direct Object Reference; direct access to objects without authorization.
Web Server & Application Attacks
Multi-Factor Authentication; requires multiple verification methods.
Web Server & Application Attacks
To remember API attack types, think 'BAM! Excessive Data Massages'. BOLA, BFLA, Excessive Data Exposure, Mass Assignment.
Web Server & Application Attacks
The CEH exam frequently tests on the *impact* of advanced attacks like SSRF and API vulnerabilities. Know that SSRF can lead to internal network reconnaissance and data exfiltration, and API flaws often result in unauthorized data access or privilege escalation. Memorize the OWASP API Security Top 10 categories.
Web Server & Application Attacks
Confusing SSRF with CSRF (Cross-Site Request Forgery). SSRF involves the server making requests; CSRF involves the user's browser making requests.
Web Server & Application Attacks
Underestimating the impact of seemingly minor API flaws. Small authorization gaps can lead to massive data breaches.
Web Server & Application Attacks
Relying solely on network firewalls for web application security. Web application attacks operate at a higher layer and require WAFs and application-level controls.
Web Server & Application Attacks
A device that creates a wireless local area network (WLAN).
Wireless Network Hacking
Service Set Identifier; the name of a wireless network.
Wireless Network Hacking
Wired Equivalent Privacy; an outdated and insecure Wi-Fi encryption standard.
Wireless Network Hacking
Wi-Fi Protected Access II; a strong Wi-Fi encryption standard using AES-CCMP.
Wireless Network Hacking
Wi-Fi Protected Access III; the latest and most secure Wi-Fi encryption standard.
Wireless Network Hacking
Advanced Encryption Standard; a symmetric block cipher used in WPA2 and WPA3.
Wireless Network Hacking
Simultaneous Authentication of Equals; key exchange in WPA3-Personal for forward secrecy.
Wireless Network Hacking
Wireless standards: 'WEP Was Poor, WPA Was Alright, WPA2 Was Great, WPA3 is Awesome!' (Remember the security progression)
Wireless Network Hacking
The CEH exam frequently tests the differences between WEP, WPA, WPA2, and WPA3. Memorize the primary encryption algorithms (RC4, TKIP, AES-CCMP, AES-SAE) associated with each and their key vulnerabilities. Pay close attention to WPA2-Personal vs. WPA2-Enterprise and the new features of WPA3 like SAE and Enhanced Open.
Wireless Network Hacking
Confusing the encryption algorithms used by each standard (e.g., thinking WPA2 uses TKIP by default).
Wireless Network Hacking
Believing that hiding an SSID provides significant security against discovery.
Wireless Network Hacking
Underestimating the severity of WEP vulnerabilities; it's not just 'weak,' it's broken.
Wireless Network Hacking
Forces clients off a wireless network to capture handshakes.
Wireless Network Hacking
A rogue access point impersonating a legitimate one to intercept traffic.
Wireless Network Hacking
A suite of tools for wireless packet capturing, injection, and key cracking.
Wireless Network Hacking
A powerful, modular framework for performing MITM attacks and network reconnaissance.
Wireless Network Hacking
A passive wireless network detector, sniffer, and intrusion detection system.
Wireless Network Hacking
The process by which a client and AP establish a secure connection using WPA/WPA2.
Wireless Network Hacking
An unauthorized AP installed on a network, often for malicious purposes.
Wireless Network Hacking
Think 'A-C-K' for Aircrack-ng components: Airodump (capture), Aireplay (inject/attack), Aircrack (crack).
Wireless Network Hacking
The CEH exam frequently tests on the specific functions of tools like Aircrack-ng, Bettercap, and Kismet. Memorize which tool performs what action (e.g., 'aircrack-ng for cracking WPA/WPA2 keys'). Be able to distinguish between passive (Kismet) and active (aireplay-ng) attack methods.
Wireless Network Hacking
Confusing the purpose of different tools within the Aircrack-ng suite (e.g., airodump-ng vs. aireplay-ng).
Wireless Network Hacking
Underestimating the importance of a strong passphrase even with WPA2/WPA3, as offline cracking is still possible.
Wireless Network Hacking
Failing to understand the legal and ethical implications of performing wireless attacks without explicit authorization.
Wireless Network Hacking
Port-based network access control for authentication.
Wireless Network Hacking
Centralized authentication, authorization, and accounting protocol.
Wireless Network Hacking
Unauthorized access point connected to a network.
Wireless Network Hacking
Wireless Intrusion Detection/Prevention System.
Wireless Network Hacking
Visibility of a Wi-Fi network's name to nearby devices.
Wireless Network Hacking
Restricting network access based on MAC addresses.
Wireless Network Hacking
WIFI SECURE: WPA3, Isolation, Firmware updates, Internal audits, Strong passwords, Encryption, Rogue AP detection, Employee training.
Wireless Network Hacking
The CEH exam frequently tests knowledge of WPA2/WPA3 differences and the importance of 802.1X for enterprise security. Memorize that WEP and WPA are considered insecure and should not be used.
Wireless Network Hacking
Relying solely on MAC address filtering for security, as MAC addresses can be easily spoofed.
Wireless Network Hacking
Using default administrative credentials on access points, making them easy targets for attackers.
Wireless Network Hacking
Neglecting to update access point firmware, leaving known vulnerabilities unpatched.
Wireless Network Hacking
Wi-Fi Protected Access with Pre-Shared Key, a common wireless encryption method.
Wireless Network Hacking
A type of rogue AP that mimics a legitimate Wi-Fi network's SSID to trick users.
Wireless Network Hacking
A feature for easy device connection, often vulnerable to PIN brute-force attacks.
Wireless Network Hacking
A security feature preventing wireless clients from directly communicating with each other.
Wireless Network Hacking
To remember common wireless attacks: 'We Really Don't Want Cyber-attacks!' (WPS, Rogue AP, Deauth, WPA Cracking, Client-side).
Wireless Network Hacking
The CEH exam frequently tests your understanding of practical attack methodologies. Be prepared to identify the tools used for specific attacks (e.g., Aircrack-ng for WPA cracking, Reaver for WPS), and the steps involved in each scenario. Focus on the 'why' behind each attack type and its impact.
Wireless Network Hacking