Cybersecurity Notes
Cybersecurity Notes
As we become increasingly connected through the Internet by access through the computer, our
phones, and even household devices, security has become a hot topic. Attacks can happen from any
corner. What happens if someone gains control of your computer or phone? Or someone gains control
of just your Google account?
On an enterprise level, attacks on computer systems can also breach millions of pieces of personal data,
including credit card information. Governments are also vulnerable to attacks that expose sensitive data.
Cybersecurity involves everyone and every entity - from you and your neighbors, to organizations, to
companies, to governments.
A robot knight defends against a big attacker wearing a purple robe shooting lightning bolts of 0's and
1's at a tower
The Internet has completely revolutionized the way we communicate with each other and share
information. Many of us spend hours on social media and online group chats. Nearly all institutions have
some sort of computer system administration to keep track of accounts, and buying and selling things on
the Internet is now the norm. One by one, even medical equipment, transportation systems, and
vacuums are connected to the web.
There’s no turning back, even as more connections to the Internet lead to more privacy concerns and
security risks. We don’t want strangers to access our accounts, or our credit card numbers. Along with
practicing personal security, organizations and businesses also need to do their part to implement the
right protections.
Cybersecurity is the field of study and practice that responds to these challenges as technology evolves.
In a formal definition by CISCO:
“Cybersecurity is the practice of protecting systems, networks, and programs from digital attacks.”
Digital attacks can cover a whole range from fraudulent emails to a targeted shutdown of a website’s
traffic. Defenses against these attacks, then, must be learned and implemented at all levels.
A basic, overarching model for cybersecurity, particularly as it relates to information, is the CIA Triad.
CIA stands for Confidentiality, Integrity, and Availability (not the US Central Intelligence Agency). Nearly
all information security policies trace back to this model. Let’s go through each component of this triad.
A triangular diagram shows the three corners Confidentiality, Integrity, and Availability, with Data in the
center of the triad.
Confidentiality
This pillar of the triad refers to protecting private information from eyes that shouldn’t have access to it.
Confidentiality is the need to enforce access - who can see this, and who shouldn’t? For example, we
don’t want to give our social security number to just anyone, but we trust that the institutions we give
them to - like tax services - implement the right security measures to keep it secret. So what tools are
used to guarantee the right access?
Integrity
Integrity refers to data integrity here. We need security controls that protect data from being changed
or deleted. We must also ensure that the damage can be reversed if data was changed accidentally or by
the wrong person. Some techniques related to integrity are:
Keeping backups of the data in its correct state, and logging versions
Availability
This last pillar refers to data being consistently, reliably available to those authorized. For example,
when you login to a social media account and want to set your privacy settings, you expect all the
correct settings you had set before to appear immediately. The social media company ensures that even
with high traffic, information gets to your screen. How is this accomplished?
And on we go!
Again, the CIA triad provides a foundation for information security specifically. We will cover many other
security principles and frameworks, and explore techniques deeper.
In this course, you will gain a foundational understanding of the field of cybersecurity. You will learn:
how cybersecurity has evolved, including how it’s shaped modern standards and regulations
how digital attacks operate, and their different targets and motivations
Cybersecurity is becoming a broader field as more industries migrate onto the Internet and become a
part of the digital landscape. That means there are cybersecurity needs in nearly every industry in
addition to cybersecurity being an industry itself. Security roles are no longer just the hacker stereotype
of cracking into systems and writing code all the time; cybersecurity as a whole encompasses many skills
that work together.
In this article, we’ll break down some of the big domains in the cybersecurity industry. There are lots of
overlap between different domains and cybersecurity careers, so keep in mind that the domains are not
drawn with hard lines, especially as they keep evolving!
Rainbow paths overlapping
Security engineering
Information security, or InfoSec, protects data in any form from being accessed, modified, shared, or
deleted by the wrong people.
Network security is concerned with the network infrastructure of an organization that guards against
unauthorized access or data from being intercepted.
Application security refers to implementing measures that defend an application (mobile, desktop, or
web) from attack, including both software and hardware solutions. Examples of application security
include secure coding, the use of antivirus programs, firewalls, and encryption.
Cloud security refers to the new field of making sure resources uploaded into the cloud are secure.
Companies and users are constantly moving more resources into the cloud, and professionals in this
field need to be familiar with implementing security in this environment.
Cryptography focuses on methods to hide and un-hide information so that data is only readable or
usable by authorized people. This requires familiarity with all types of encryption and hashing
algorithms.
Critical infrastructure security is defending physical systems that are becoming more digital/networked,
such as energy grids, hospitals, water and waste systems, and even schools. Among the issues that come
up are natural disasters and outages.
It’s critical to understand international, federal, and state laws and regulations for security. This has
implications on the security operations for all organizations. Compliance refers to making sure an
organization enforces certain policies, and continuously auditing as well.
This is becoming an increasingly important area of work. While these roles might not require
programming knowledge, these roles require foundational knowledge of cybersecurity as well as all the
laws and regulations that impact a particular industry.
No system will ever be perfect, and there will always be risk, so this area of work is about managing that
risk.
How is risk managed? Through identifying risks, assessing the likelihood and potential threat of security
vulnerabilities, and finding the most cost-effective and efficient security measures.
Threat intelligence is the continuous gathering of knowledge of possible attacks. Intelligence could look
like knowing the motivations behind attacks, what the scale of attacks could be, and what vectors that
might use. These roles often intersect with data science and machine learning because of the need to
process all this information.
Security operations
People who work in this area are responsible for implementing security principles, monitoring for
incidents, and recovering from disasters. They work closely with everyone under the security umbrella
to:
Make sure there are back-ups in case a system is compromised and data is lost.
Education
Security education is a growing area in itself! This domain acknowledges that the most securely designed
technologies are only as strong as the people who use them. User education teaches best practices for
people to protect themselves against cyber threats. Security training also happens in large organizations,
where employees are educated and updated on the organization’s security policies and practices.
This domain can also include the career development and training of new security professionals as well.
Conclusion
There are a broad set of cybersecurity roles that vary in technical expertise and required training. There
are roles that intersect with engineering, roles that intersect with education, and roles that intersect
with administration and management.
We encourage you to do your research with an open mind.
Cybersecurity was invented as soon as the first group of people attempted to defend from digital
attacks. We’ll walk through a brief history of cybersecurity through the 60’s, 70’s, all the way to the
2010’s and the present. The evolution of defensive techniques mirrors the evolution of attack
techniques, making this history rife with interesting challenges. You can see in the graph below just how
quickly cybersecurity needs to keep up with attacks.
A histogram shows that malware infection rates have grown steadily every single year since 2009.
With laws and industry-specific policies, companies and organizations that hold our data are held
responsible for protecting our data and thus, our privacy. This sets a balanced expectation of what is
personal security practice and what should be built into the tools we use every day.
Without enforcing that trust, we would not be able to carry out sensitive or financial transactions on the
web. It would be incredibly difficult to coordinate the training of security professionals. We’ll talk about
some widely implemented security frameworks, what constitutes cybercrime, and laws and policies that
deal with a specific industry like healthcare or finance. Let’s get into it!
When ENIAC, the first modern computer, was brought online in 1945, cybersecurity wasn’t a word you
could find in the dictionary. The only way to interact with the building-sized computers of the era was to
be physically present, so virtual threats weren’t a risk, and access control was a matter of physical
security.
Cybersecurity developed as a distinct field throughout the 1960s and 70s and exploded into the public
consciousness in the late 1980s, after a series of events that highlighted just how dangerous a lack of
security could be. Continuing to grow throughout the 90s, cybersecurity is now a core part of modern
life. Let’s explore the brief history of this field!
Origins
When you hear the word “hacker”, you probably think of a mysterious individual sitting alone in a dark
room, watching information scroll by on multiple windows as they conduct nefarious deeds.
Absurd Hacker Photo
The media often takes creative liberties when depicting hackers. It may surprise you to learn that the
origin of the ‘modern hacker’ was a counterculture of people tinkering with technology or finding new
ways of sharing information. Hacking is not innately tied to breaking into computers. In fact, an early
instance of hacking in 1963 involved hacking a phone system to make long-distance calls for free.
Hacking is the act of working within the confines of a system to produce unintended behavior. That
behavior ranges from cracking passwords to saving a spaceship’s air system using spare parts.
The 1960’s
The more connected we are, the more important cybersecurity is, and the widespread adoption of time-
sharing in the 60s was a big increase in connectivity. Computers of the era were expensive and bulky;
timesharing let multiple people use a single large computer at the same time, which meant that
precautions were needed to prevent unauthorized access to files and to the computer itself. Computing
time was expensive in those days! The solution of protecting accounts with passwords has persisted to
modern times.
The 1970’s
The creation of ARPANET, the earliest form of the internet, gave hackers a lot to think about and
explore. ARPANET was a testing ground for new technologies, and the hacker and technical communities
busied themselves with developing and prototyping new technologies, including email. There were a
few adventures into the development of malware (short for malicious software), including Creeper and
Reaper, the first computer worms, but these were academic exercises more than anything else.
The message you would have seen if you received a visit from Creeper!
In this era of rapid development and experimentation, the security of the technology being developed
was not a concern. The widespread view of ARPANET as a cooperative academic endeavor and the
absence of well-established best practices meant that the motivation and means to design secure
systems and software were limited. However, people were starting to think about security. A 1975 paper
titled The Protection of Information in Computer Systems presented principles and concepts that would
become critical to cybersecurity in the future.
The 1980’s
The 1980s were a chaotic time; the Internet was formed in 1983, and the adoption of the Internet
Protocol Suite by ARPANET and other networks added more potential targets and attackers to the mix.
The first “real” malware emerged during this time, as did the public panic around The Cold War. Tools
and techniques developed during this era would become common in modern cybersecurity; dictionary
attacks used stolen lists of passwords and exploited weak default credentials, while decoy computer
systems trapped attackers.
The first was the discovery that a hacker working for the KGB gained access to sensitive documents from
the U.S. military.
The second was the creation of the world’s truly serious piece of malware: the Morris Worm. It was
originally written to map the size of the internet but quickly grew out of control, choking computers with
multiple copies of itself, and clogging the network as it kept replicating.
These incidences exploited unsecured default settings; default passwords like “admin” ensured a system
or piece of software was easily exploitable.
An image showing two people. One asks "how did you get in?" The other person says "the admin
password was `password`!"
The 1990’s
The 1990s are widely considered to be the era of viruses. Computers that connected to the internet
became more common in households and this increased access. This led to unskilled script kiddies —
individuals who download a piece of code and run it without having to write any code themselves. They
can use that code to launch attacks they don’t understand in order to vandalize or destroy targets for
fun.
The unfocused, scattered attacks of the era led to the rise of the anti-malware industry, evolving from a
curiosity to a core part of modern cybersecurity. Cybersecurity, as a whole, started to be taken much
more seriously. Large companies made public pushes to improve the security of their products.
Household computers were often targeted by the rampant malware of the era, demonstrating the
consequences of poor cybersecurity to their owners.
The 2000’s
More and more data became digitized — particularly monetary transactions. As the script kiddies of the
90s grew up and gained more experience, the scale of threats shifted, and attackers started having
larger targets beyond vandalism and destruction. Credit-card breaches, hacktivism, and holding
corporations’ systems for ransom became increasingly common, as malicious hackers realized there was
real money to be made from cybercrime.
Hundreds of millions of sets of credit card data were breached over the course of the decade.
The threats of data breaches and ransomware attacks forced large businesses to improve their
cybersecurity programs. Being hacked was no longer just a matter of vandalism; it could lead to
extended downtime, loss of customer loyalty, lawsuits, and fines from regulatory bodies.
The 2010’s
During the 2010s, the scale of threats continued to grow: Attacks by nation-states increased in
frequency, and they carried out infiltration and surveillance campaigns and deployed cyberweapons to
attack strategic objectives. Malicious hacker groups targeted major corporations and government
organizations, stealing data and launching ransomware attacks, and the growing number of smart
devices in circulation gave these groups an entirely new type of target.
The most dangerous of these new threat actors are known as APTs: Advanced Persistent Threats. Often
funded by nation-states, APTs possess resources and determination far beyond what smaller threat
actors might have access to. While lesser threat actors might be capable of launching cyber attacks
against a target, APTs are capable of running entire cyber-campaigns, attempting to infiltrate their target
across multiple domains simultaneously.
Large-scale cybersecurity incidents became more and more common: WannaCry and NotPetya caused
global damage, the [Equifax) and Yahoo! breaches revealed hundreds of millions of pieces of personal
information, and countless companies and organizations were hit by ransomware attacks, bringing their
operations grinding to a halt.
The present
This image shows that the malware infection rate has grown by the millions every year from 2009 to
2018
With the world as connected as it is, cybersecurity is about protecting people as much as it is about
protecting computers. People are fallible, and, like computers, we have vulnerabilities that can be
exploited: Emotional manipulation and social engineering are powerful tools, used by hackers to gain
access to secure systems. Many of the systems we rely on run on computers, and the stakes for
protecting them have never been higher. Attacks on those computers can disrupt transportation, power,
economy, healthcare, communication, and even lives.
With computers so integrated into our lives, it’s crucial that we protect them. In cybersecurity, we must
learn from our mistakes, applying the lessons learned in the past to prevent attacks in the future. This is
the domain of security researchers and ethical hackers: Finding and fixing vulnerabilities before they can
be exploited, and helping to make us and our computers as safe as possible.
In this article, you’ll learn about some standards, regulations, and frameworks that govern and support
cybersecurity.
Cybersecurity is serious business; the potential consequences for a security breach can be dire,
particularly if that breach targets sensitive information. In response, regulations and frameworks have
been developed to ensure that the organizations which handle our data have a responsibility to do so
securely and ethically, and have guidelines for how to do so.
Standards and best practices are generally agreed-upon rules for maintaining security, generally within
an organization. Standards may come as individual recommendations, or as part of a framework.
Regulations are sets of standards that organizations must follow, generally due to legal obligation, and
define the responsibilities organizations have.
Frameworks are sets of standards and best practices that organizations can use to ensure their overall
security. These are optional, but good practice for organizations to follow.
In this article, we will look at what constitutes cybercrime, discuss some US legislation setting standards
for defense against cybercrime, and then discuss recommended security frameworks.
Cybercrime
What is Cybercrime?
Cybercrime is, generally speaking, any crime that makes use of or targets a computer. This is a broad
definition because computers are versatile tools that can be used for good or evil. Without broad legal
definitions, it’s difficult to prosecute new and innovative types of criminal activity.
When we think of cybercrime, we might first think of evil viruses on our computer and hackers getting
into company data. What are some other types of cybercrime?
Extortion: commonly in the form of ransomware, where attackers take control of a system and demand
payment from the target.
Fraud: a broad category including identity theft, scams, retail fraud, phishing, and more.
Theft: stealing information during a data breach, or theft of services and resources, such as using other
people’s computers to mine cryptocurrency.
Cybercrime does not always fit cleanly into a single category. For example, a malicious individual might
break into an account using phishing, steal personal data, then threaten to publicly release it unless a
payment is made. As with ‘ordinary’ crime, new types of cybercrime are being created all the time,
limited only by the imagination of those carrying it out.
Multiple choice
Digital Forensics
Digital Forensics is the process of gathering the evidence of a cybercrime in a way that the evidence can
be used in a court of law. It is a broad field with specializations, including:
Disk Forensics: investigation of storage media such as hard drives.
The most important aspect of digital forensics is maintaining a chain of custody to prove that the data
and evidence have not been modified or tampered with. Simply gathering evidence is not enough; the
evidence must hold up to legal scrutiny in order to be useful, and conducting a forensic investigation
incorrectly can destroy the original evidence.
Regulations
The Computer Fraud and Abuse Act (CFAA) is a US law that is used to prosecute cybercrime. At its core,
the act makes it illegal to intentionally access a computer without authorization, or to access a computer
in a way that exceeds authorization that has been granted. The broad scope of the CFAA means that it is
used to prosecute a wide variety of cybercrime, including:
Malware attacks
An image showing a child using a tall stool to barely grab a cookie out of the cookie jar. Their father
catches them and the child says "But you left the cookies where I could reach!
Multiple choice
Logging into someone’s computer with a password they keep on a sticky note.
Logging into your mother’s email account with her permission.
Organizations like companies and public departments are subjected to additional legal obligations.
These regulations make sure organizations act on security concerns to make their platforms as secure as
possible. Many of us interact with and benefit from these regulations without even realizing it; if you’ve
ever been to a doctor in the US, you almost certainly have information being protected by HIPAA.
In this section, we’ll be looking at three different sets of regulations; two of them are U.S federal laws,
while the third is a contractional obligation created by the credit card industry. As we review the
regulations and their requirements, think about how and why those requirements might have been
created, and what they aim to prevent.
HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law designed to
modernize various aspects of healthcare and insurance. More importantly for cybersecurity, it
introduced regulations and standards requiring entities that handle Protected Health Information (PHI)
to ensure its security and privacy.
GLBA
The Gramm-Leach-Bliley Act (GLBA) is a U.S. federal law governing financial institutions, requiring them
to protect sensitive customer information, and disclose how they share that information.
The cybersecurity section defines what steps financial institutions need to take to protect customer
data. They have the following responsibilities:
PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS, or PCI for short) is a regulation developed
by credit card companies and governing merchants that handle credit card data.
The PCI DSS, as of 2021, outlines the following responsibilities for merchants:
Multiple choice
HIPAA
GLBA
PCI DSS
The NIST Cybersecurity Framework is an optional framework published by NIST, originally developed to
protect critical infrastructure in the US from cyber threats.
NIST Logo
Identify - Identify and understand the threats and risks the organization is likely to face.
Protect - Protect the organization’s assets from those threats and risks.
Recover - Recover from incidents, evaluating how to prevent reoccurrence cleaning up any damage that
occurred.
Frameworks are not generally a one-size-fits-all solution to cybersecurity. Instead, they are a starting
point for organizations to customize to their needs and threats. Frameworks and regulations are meant
to work together, helping the organizations we rely on to remain secure, and protecting our information
from those who would misuse it.
The threat landscape is ever-evolving and ever-expanding. The constant conflict between attackers and
defenders pushes attackers to develop new attacks and defenders to develop new ways to stop those
attacks. As new technology is developed, even more new cyber threats will enter the landscape.
The goal of this unit is to explore some current cyber threats, how you can avoid threats like these, and
how you can begin to mitigate them. We will discuss some common threats, such as malware, SQL
injections, phishing, cross-site scripting, and more!
An image showing a triangle in which Confidentiality, Integrity, and Availability all surround the word
"Data".
How do we decide which threats are the most important to protect against? The CIA Triad gives us the
principles of Confidentiality, Integrity, and Availability to use as a measure.
Confidentiality is the principle of protecting private information and keeping it private. It should only be
seen by users who should have access to it.
Integrity is the principle of protecting data from being changed or deleted by unauthorized parties.
Availability is the principle of data being consistently, reliably available to authorized users.
Different cyber threats will threaten these principles. Keep these in mind as we explore the current
threat landscape.
Introduction to Malware
It’s your first day on the job at Cybercademy — a new cybersecurity organization that helps companies
improve their security practices.
Your Task
Identify various types of malware on an infected device and provide suggestions to the client on how
they can prevent this from happening in the future.
But first, what is malware? Malware is malicious hardware, firmware, or software inserted into a system
to cause damage or gain unauthorized access to a network. Any type of malware can greatly
compromise the security principles of Confidentiality, Integrity, or Availability.
Throughout this lesson, you will learn how each type of malware gets into a system, what it does, and a
short suggestion for how to be cautious against this form of malware.
Instructions
Concept Review
Want to quickly review some of the concepts you’ve been learning? Take a look at this material's
cheatsheet!
Community Forums
Still have questions? View this exercise's thread in the Codecademy Forums.
Cyber Threats
Print Cheatsheet
Share
TOPICS
What is Cybersecurity?
Cyber Threats
Malware is malicious software inserted into a system to cause damage to systems or data or to gain
unauthorized access to a network.
Viruses
Adware
Spyware
Scareware
Trojan horses
Rootkits
Ransomware
Worms
Fileless malware
Malware: Viruses
A virus is a type of self-replicating malware that attaches itself to other programs and executables
without the permission of the user.
An image showing an email advertising "Click here for a free Pro Account!!!!". The email window has lots
of evils bugs behind it.
Malware: Worms
A worm is a type of self-replicating malware that copies itself from computer to computer without user
intervention.
A worm could replicate so much that it overloads your client’s system. By doing this, the worm could
bring down the system and violate availability.
Malware: Spyware
Spyware is malware downloaded without a user’s authorization which is used to steal sensitive
information and relay it to an outside party in a way that harms the original user.
The key word here is “spy”. Clicking suspicious links or downloads could result in spyware.
Malware: Adware
Adware is unwanted software designed to throw advertisements up on your screen. This malware is
usually more annoying than dangerous.
Phishing is a type of social engineering attack in which a threat actor, posing as a trustworthy source,
attempts to trick a victim into doing something, either through email, webpages or even by phone.
How To Spot Phishing
Punctuation errors
Typos
Unusual scenarios
Incorrect formatting
If something seems wrong, assume it is! Don’t be afraid to double-check and verify.
Phishing Uses
Phishing is a social engineering tactic that can be used for many things, such as stealing credentials or
getting malware onto a system.
SQL Injection
A SQL injection is a serious vulnerability affecting applications that use SQL as their database language.
Through cleverly constructed text inputs that modify the backend SQL query, threat actors can force the
application to output private data or respond in ways that provide intel. SQL injections attacks can
ultimately be used to steal information and even take complete control of a system.
A login form with "lorenzo_33" as the username and "password'; DROP TABLE Accounts;--" as the
password.
Types of SQL Injections
SQL injections can be broken into multiple types depending on how information is retrieved: union-
based, error-based, boolean-based, time-based, and out-of-band injections.
One way SQL injections can be mitigated is through input sanitization. Sanitization is the process of
removing dangerous characters from user input.
\--
This is important because they allow attackers to extend SQL queries to gain more information from a
database.
Careful, this method is not the perfect defense against SQL injections. Removing characters may have no
effect in some queries and, if an attacker finds a way to bypass the sanitization process, they can easily
inject data into your system.
SELECT username, email FROM users WHERE id = '1' AND '1' = '2';
Union-Based Injections
Uses the UNION SQL keyword to take two separate SELECT queries and combine their results. Consider
the user input:
Results in:
SELECT product_name, product_cost, product_description FROM
This resulting query would expose all the usernames and passwords of the users!
Error-Based Injections
An attacker writes a malicious SQL query to force the application to return an error message with
sensitive data. The inside statement of the following SQL query gets the password for the profile ID 1
but throws an error on the value type that should be returned. This error accidentally gives away the
password!
Boolean-Based Injections
An attacker takes note of the difference in web responses after sending SQL queries that result in either
TRUE or FALSE. Depending on the result, the HTTP response will change or stay the same. Even though
no data is returned from the database, the attacker can gain insight into the database (figure out table
names) and eventually build up for a Union-based injection.
SELECT username, email FROM users WHERE id = '1' AND '1' = '1';
Time-Based Injections
Makes use of several built-in SQL functions, such as SLEEP() and BENCHMARK(), to cause visible delays in
an application’s response time. Like boolean-based injections, this is also used by an attacker to infer
information about the database.
Consider the SQL query in the code block. If there’s a 5-second delay before a response from the server,
an attacker can confirm the admin user’s password is P@ssw0rd123.
SELECT id FROM users WHERE username = 'a' OR IF((SELECT password FROM users WHERE
username='admin')='P@ssw0rd123', SLEEP(5), NULL);-- -';
An image showing that the attacker injections a malicious SQL command, then the web server processes
the injected command, then the database server sends an outbound request to the listening server.
Finally, the attacker collects the captured information.
Cross-Site Scripting (XSS) is a vulnerability that occurs when a web application returns unsanitized input
to the front end of an application.
Stored XSS: when a server saves an attacker’s input into its datastores.
Reflected XSS: when a user’s input is immediately returned back to the user.
DOM-Based XSS: when user input is interpreted by the DOM, an attacker could inject arbitrary code.
The code shows examples of HTML tags that help attackers inject dangerous input.
<script>alert(1);</script>
<body onload=alert('test1')>
XSS can be mitigated by properly sanitizing input, as well as using specialized functions. We can
generally succeed in preventing XSS attacks by removing potentially dangerous keywords or potentially
dangerous characters such as:
<
>
"
Rather than remove characters, we could replace them with the HTML-encoded versions. For example,
the < character would be converted to the “<” string.
Cross-Site Request Forgery is a serious vulnerability that results from poor session management. If the
requests sent by an application aren’t unique, it’s possible for an attacker to craft a special request and
send that to a user. If the user interacts with the crafted request, and sessions aren’t handled properly,
an attacker may be able to assume the session identity of that user and carry out requests on their
behalf.
In many cases of CSRF, a malicious actor crafts a URL embedded with a request like so:
[Link]
Cryptography
Cryptography is the process of encrypting and decrypting data in order to keep that data safe when
storing or transmitting it.
Decryption is a way of revealing encrypted data by decoding it from its encoded format.
Symmetric encryption uses the same key to encrypt and decrypt information.
Asymmetric encryption uses a public key to encrypt data and a different private key to decrypt data.
Asymmetric ciphers can be slower than symmetric ciphers but have additional use-cases in
authentication and non-repudiation.
Hashing
Hashing is a one-way process that takes data of any size and represents it as a unique hash value of a
fixed size. No matter how large or complex your file is, hashing provides a fast, reliable way to compare
files and verify their authenticity.
Hashing lets you check if two pieces of information are the same, without knowing what the information
itself actually is.
A diagram showing that encryption uses keys to encrypt and decrypt data while hashing results in data
being transformed into a hash.
Rainbow Tables
A rainbow table is a massive table of common passwords and password-hash combinations used by
attackers to break into accounts. One common technique we can take to protect ourselves from
rainbow table attacks is the use of salts.
An image showing that adding the salt "abc" to the end of the password "p@ssw0rd" changes the hash
stored in the database. This means that an attacker who has stolen the hash won't find a match in their
rainbow table and discover the user's password is "p@ssw0rd".
Salts
A salt is a secret random string that is combined with a password prior to hashing specifically to defend
against the use of rainbow tables.
Rainbow tables are large lookup databases that consist of pre-computed password-hash combinations
which correlate plaintext passwords with their hashes.
An image showing that adding the salt "abc" to the end of the password "p@ssw0rd" changes the hash
stored in the database. This means that an attacker who has stolen the hash won't find a match in their
rainbow table and discover the user's password is "p@ssw0rd".
Authorization is what you can do. Only being allowed into non-VIP sections of the site is an example of
authorization.
An image showing that Authentication is when you log in and Authorization is what you are allowed to
do.
Then, receiving a One-Time Passcode (OTP) that needs to input into the same website
An image showing that the user needs a password, a code sent to their phone, and that same code
inputted into the website before they can gain access.
OAuth
OAuth is a secure framework that makes use of a trusted third-party for authentication.
When a service asked if you want to “Sign in with ____”, this an example of OAuth.
OSI Model
The OSI Model is a conceptual, implementation-neutral model that describes networking in seven
separate layers, where each layer covers a set of functions and tasks.
TCP/IP Model
The TCP/IP Model is an implementation-specific networking model that revolves around the TCP
protocol and IP addressing which anchor the Internet as we know it.
OSI Layers
The OSI layers include: Physical, Data Link, Network, Transport, Session, Presentation, and Application.
The Data Link layer includes data framing and local MAC addressing
The Network layer includes connecting to the larger web and IP addressing
The Transport layer includes protocols that make sure reliable delivery happens
The Session layer authenticates and maintains communication over a period of time
The Presentation layer en/decrypts and translates data into presentable form
The Application layer includes all the applications we interact with that render data
Network Categories
Local Area Network (LAN), a smaller-sized network that connects multiple devices in a small area
Campus Area Network (CAN), a larger network that connects multiple computers and devices over a
slightly larger area
Wide Area Network (WAN), the largest-sized network that connects multiple computers, over a
geographically large area
Network
A network is two or more computers or devices that are linked in order to share information.
Networking refers to a large set of standards and protocols that organize and regulate the sharing of
information.
Network Protocols
SSH
FTP
Network Segmentation
Network Segmentation is the practice of breaking larger networks into smaller, functionally similar
networks. This improves both security and performance.
Access Points
Access points are the systems and nodes used to distribute wireless signals.
If an attacker can physically hack an access point, they may be able to attack the users on the network!
This is why you should be careful which access points you connect your devices to.
All wireless activity should be securely encrypted. Currently, the accepted standard for security is WPA2.
WPA2-Personal will require a single password to access Wi-Fi
Attackers can use credential stuffing to test username/password combinations. Attackers will use
information from one hacked site to infiltrate accounts on other sites.
Reuse passwords
Using Multi-Factor Authentication (MFA) can make your accounts even more secure, even if your
password is compromised.
Virtual Private Networks (VPNs) keep you safe by providing both network security and anonymity.
They can protect against attacks like Man-in-the-Middle attacks because of their ability to encrypt web
traffic.
Software Updates
Keeping your knowledge and your software up to date will protect you against many cyberattacks.
Software updates often include updates that can protect against recently discovered threats.
Security
Usability
You should base your decisions on the risks associated with the asset being hardened.
Malicious actors might suggest fake security tips in order to gain access to your machine
Security Culture
In Cybersecurity, Security Culture is the attitude towards security within an organization, and the
members of that organization. Poor security culture can lead to poor security. Everyone in the company
needs to respect important security practices.
Even large organizations can have “simple” vulnerabilities within their systems and security practices.
For example, using the username admin and the password password for their admin account.
If breaches happen, organizations have a duty to respond promptly and ethically to those data breaches.
Adware
First, you open the web browser. The first page it opens to is a strange page about a computer cleaner
that’s “guaranteed to make your computer run 10X faster!!”. What an odd choice for a homepage.
As you navigate the web, you notice lots of ads popping up all over the place. There are so many
popping up on your screen that it’s actually slowing down the webpage and increasing page load times.
It’s clear this computer has adware. Adware is unwanted software designed to throw advertisements on
your screen. While not overly malicious on the surface, sometimes adware can come bundled with
other, more harmful malware.
With enough adware on your machine, this could become a real performance issue.
Your Suggestion
You tell your client to make sure to not click on any strange links or download any untrustworthy files.
Instructions
Click the “Click HERE to Download!” button on the sample webpage to the right.
Wow, that’s a lot of ads! Now, try clicking on the link on one of the ads and see what happens.
Potential adware won’t always be so obvious (and look so badly made) so don’t click on anything you’re
not 100% sure of!
Virus
You navigate to your client’s email. Immediately, you see that your client opened some emails sent from
an odd email address. You open the emails and see that the client clicked on links and likely downloaded
files from these suspicious emails. Uh oh. Did your client download a virus?
A virus is a malicious self-replacing application that attaches itself to other programs and executables
without the permission of the user. It’s possible a downloaded virus could alter or delete data on the
computer.
If the virus was able to access or alter data, the confidentiality and integrity of that data is now in
question.
Your Suggestion
Just like with adware, avoid suspicious links and install trustworthy antivirus software.
What type of virus is this? You check your client’s “Sent Emails” folder and notice your client recently
sent the same email to everyone on their contacts list. The emails have the same subject line as the
malicious email they received. It almost seems like the email replicated itself…
Aha! Rather than a virus, which needs to be attached to a file or application to spread, you may have
found a worm.
A worm is self-replicating code that copies itself from computer to computer without user intervention.
This worm could be just as dangerous as a virus.
The worm could also replicate so much that it overloads your client’s system. By doing this, the worm
could bring down the system and violate availability.
Your Suggestion
Monitor the computer for any unexpected changes! Is it slower than usual? Is there less hard drive
space than expected? Have files mysteriously appeared or disappeared? These could all be signs of
worms.
Instructions
1.
How does a worm work? While worms don’t attach themselves to files, we’ll use files to simulate their
duplicative nature!
First, let’s look at some innocent files that our “worm” will infect.
2.
Press “Run” to run infect_me.txt. (Nothing will happen because it’s a text file!)
3.
Make sure you’ve closed the infect_me.txt file. You should now see the why_infect_me.py file in the
workspace.
4.
Now, click the folder button in the workspace to look at the [Link] image showing a cursor pressing the
folder icon
Open the dont_infect_me.py, infect_me.txt, and why_infect_me.py [Link] image showing a cursor
opening dont_infect_me.py by clicking on it
The “worm” should have copied itself into the files with the .py extension.
If you didn’t close those files, you will need to close and reopen them to see your worm in ac emails to
your IT department and never open them.
Spyware
Wow, what a disaster computer. Hm, when you type, there seems to be a slight delay before some of
the characters show up. What’s going on?
Oh no! It looks like your client may be in deeper trouble — they may have downloaded spyware as well.
Spyware is malicious code downloaded without a user’s authorization which is used to steal sensitive
information and relay it to an outside party in a way that harms the original user. If the spyware
contained a keylogger, a program that can record what a victim types into their computer, a threat actor
could potentially gain access to sensitive information.
This means any sensitive data, like passwords, will soon be in the hands of a malicious third-party. While
spyware usually isn’t used to alter data, it definitely violates the principle of confidentiality. A malicious
actor may have been spying on sensitive data your client was typing.
Your Suggestion
Noticing a trend? Be careful what you click on and install that trustworthy antivirus already!
Instructions
An image showing that "node [Link]" has been typed into the terminal
Press the circular arrow button on the right side of the screen to load the [Link] image showing a
cursor pressing the refresh button to refresh the iframe on the right side of the screen
Now, try typing in a fake username and password. What prints to the terminal when you type in the
password field?
Hint: Not working? Make sure you don’t have this exercise open in any other tabs! Then, refresh this
page and try again.
rojan Horses
While the presence of spyware makes it obvious something nefarious was installed on the computer,
was anything else installed?
Ugh, of course. After more digging, you find a Trojan Horse. Wow, is there any download link your client
didn’t click on?
While similar to Spyware, the Trojan Horse, sometimes just called a “Trojan”, does more than just
monitor what’s happening on a system. Trojans are a type of contained, non-replicating malware that
disguises itself as legitimate software in order to allow scammers and hackers access to a user’s system.
Just like the Greeks hid inside a giant wooden horse to sneak into the city of Troy, this malware snuck
right onto your client’s computer while pretending to be a legitimate antivirus software!
Your Suggestion
Be wary of disk or computer cleaners as well as unknown antivirus software. Trojan horses often
pretend to be trustworthy software in order to convince you to download them onto your machine.
Rootkits
What exactly is the Trojan Horse up to? What was it trying to do? You have to find the answer.
Scanning the device, you find that this horrible device just keeps getting worse; the Trojan horse was
used to sneak a rootkit onto the system.
Rootkits are a collection of malicious programs that secretly provide continued, privileged access to a
system for an unauthorized user. A rootkit can create a backdoor on a computer to let a hacker in. This
rootkit was able to gain admin access to this computer, and it will be incredibly hard to remove.
In this case, the Trojan Horse pretended to be a trustworthy antivirus software in order to install a
rootkit. This means that a malicious, third-party somewhere has admin access to this computer and its
data. This is a nightmare scenario for the confidentiality and integrity of your client’s system. While
some specialized tools can remove a rootkit, it isn’t easy.
Your Suggestion
Ransomware
The rootkit allowed someone access to this computer. What did they do with that access? You realize
that the rootkit was used to deny the user access to files on their system that contain lots of important
company data.
If the malicious actors block access to data or threaten to publish the sensitive data unless the client
pays them money, that could be a case ransomware. The use of ransomware has been skyrocketing as
threat actors have realized it’s safer and easier to rob a virtual location rather than a physical one!
Ransomware is one of the largest cybersecurity threats facing industries today.
Blocking a user’s access to data greatly threatens availability. While availability might not seem
important, it can be devastating to some organizations. Imagine if a hospital or flight system lost access
to their system or data!
Your Suggestion
Have a procedure in place for ransom requests. They should include a step in which the authorities are
alerted.
Fileless Malware
It seems like nothing else could go wrong with this computer. If this was a game of malware bingo, you
would be one step away from winning the jackpot. For fun, you investigate some command-line
programs to see if they’ve been altered. Aaaand, did someone say bingo?
Fileless malware is a type of malware that ‘lives off the land’ and uses legitimate tools and the user’s
operating system to perform malicious activities like privilege escalation, data collection, and more. It’s
incredibly hard to detect and almost always missed by antivirus software.
Unlike a Trojan Horse, fileless malware is not pretending to be legitimate software, it actually is a part of
legitimate software. Fileless malware hides itself within the code of legitimate software, often altering
existing code to make it malicious.
Certain programs, like Microsoft PowerShell, are particularly vulnerable to these attacks. Someone could
use this attack vector to gather data, use your device resources to mine cryptocurrency, or even install
other malware.
Your Suggestion
Did you download that antivirus yet? Still avoiding those suspicious links?
Keep your applications and system up to date for the latest security updates.
Review
Malware: Malicious code inserted into a system to cause damage or gain unauthorized access to a
network
Virus: A malicious self-replacing application that attaches itself to other programs and executables
without the permission of the user
Worm: Self-replicating code that copies itself from computer to computer without user intervention
Spyware: Malicious code downloaded without a user’s authorization which is then used to steal
sensitive information and relay it to an outside party in a way that harms the original user
Trojan Horse: A type of contained, non-replicating malware that disguises itself as legitimate software in
order to allow scammers and hackers access to a user’s system
Rootkit: A collection of malicious programs that secretly provide continued, privileged access to a
system for an unauthorized user
Ransomware: Malicious code that will block a user’s access to data or threaten to publish sensitive data
until they pay money to the malicious actor
Fileless Malware: A type of malware that ‘lives off the land’ and uses legitimate tools and the user’s
operating system to perform malicious activities like privilege escalation, data collection, and more. It’s
incredibly hard to detect and almost always missed by antivirus software
What’s Next
While this may seem like a lot, the world of security is full of so many more potential threats! Let’s read
some articles and do some research on other attack vectors.
Phishing
In this article, you will learn about how attackers use psychology to bypass technical security measures.
Note: Attempting to phish the credentials of someone without their express consent is illegal. The
information presented in this course in no way encourages or condones phishing, and should not be
used to attempt a phishing attack.
A fun image showing "phish" swimming with a computer trying to catch them on a fishing hook.
Phishing is one of the most well-known types of cyber attacks. The average internet user has never
heard of Kali Linux or written Python scripts to guess passwords, but everyone knows not to respond to
an email from a down on their luck Nigerian Prince (well, almost everyone).
One of the reasons that phishing is so common is because it works! No matter what technical controls
are in place to secure a system, humans within the system are still hackable. The practice of tricking
humans to get important data or access is also known as social engineering.
Estimates range on how effective phishing is, but given that it can be used for everything from credential
theft to loading malware in systems, Verizon labeled it the biggest threat to small organizations in 2020.
Sometimes phishing attacks can seem comically implausible, such as this phishing email from an
unfortunate astronaut lost in space below. However, with phishing attacks becoming both more
common and more sophisticated, it’s vital to be able to identify and stop phishing attacks.
An image showing an email from the so-called cousin of a Nigerian astronaut. They're asking for money
to bring him home from space.
Multiple choice
Phishing, a practice that targets humans to get money, information, or access, is a type of what?
Smishing
Brute-Forcing
Social Engineering
Authorization
Vishing (from “voice phishing”), which refers to the spam calls in which an attacker claims to be from a
victim’s bank or law enforcement and tries to extract information.
Smishing (from “SMS phishing”) is when an attacker attempts to do the same thing over text message,
by sending a malicious link.
Phishing is also categorized by who it targets. Many phishing campaigns send out mass spam emails to
individuals and organizations, hoping to catch a victim in a wide net. But sometimes, an attacker has a
specific target in mind and sends that target a dedicated, personalized email. This is known as spear
phishing. If the target is extremely sought after, like the CEO of a company, it is known as whaling.
Whether it is used to trick someone into sending money, to harvest login credentials, or to download
malware, phishing targets humans as an initial attack vector.
Multiple choice
Whaling
Sealing
Vishing
Smishing
How Does Phishing Work?
Sometimes phishing attacks are just emails or phone calls that attempt to get a victim to send an
attacker money or payment information. Others, such as those that get people to click on links that
download malware onto their systems, require more technical finesse. For example, an attacker could:
Social engineer a user into downloading and opening it, executing the malicious code.
Often, this malicious code contains the functionality to further spread the virus by sending more
phishing emails to the user’s contacts.
Multiple choice
They write malicious JavaScript directly into the body of the email.
Email Spoofing
Email spoofing refers to when an attacker falsifies their email headers to make it appear as though the
email is coming from someone else. Spoofing is a common component in phishing emails, used in as
many as 90% of email fraud attacks.
When you typically send an email, the “from” field is automatically filled out. If my email is
john_johnson[@]gmail[.]com, and I send an email to my friend, my friend will see that the email came
from my email address. However, you can also send emails with simple scripts (here are instructions for
sending an email in Python).
When you write and send an email using a programming script, you can configure the email headers to
be whatever you want - meaning that an attacker can put any email as the “sender”, even yours. In
order to really see what is going on in an email, you can download it and open it in a code editor, but
most email providers allow you to see the email headers from within your email. For example, in Gmail,
if you open an email of interest, click on the three vertical dots in the upper right-hand corner, and click
on “Show original”, you can see the email headers.
These email headers provide valuable information that can help detect phishing, such as the “return-to”
address, sender IP, and whether the email failed any protections such as SPF and DKIM, which help to
fight spoofing (they are the reason emails are automatically sent to your spam folder). If you see a
suspicious email, it is always wise to open the headers before responding in order to see if any
protection fields “failed”, and to look at the original sender IP. You can read more about email spoofing
here.
An image showing that many of the protection fields in this email failed.
Multiple choice
Whether the email passed or failed authentication protections such as SPF and DKIM.
Webpages that harvest credentials are especially effective phishing tools. Because these pages often
forward victims to a legitimate webpage after stealing their login information, the user never realizes
they were phished. These webpages can also encourage you to download malware unknowingly.
If someone were trying to steal Codecademy logins they could occupy a typo-squatting domain like
[Link] or [Link] in the hopes that a user would accidentally type in the wrong
domain. A malicious actor could also disguise their domain with a link shortener like bitly to get
someone to click through to a disguised domain.
Below, we’ve set up our own credential harvesting webpage that looks identical to the Codecademy
login page. We did this by downloading the HTML files for Codecademy. In the screenshot, the page is
on a local server we can monitor, but we could choose to host it on any domain we owned.
When someone lands on this page, they think it’s the real [Link]! When they enter their
username “admin” and password “password” and log in, that login information gets sent to our
backend.
An image showing that the backend of this fake page discovered that the username is probably "admin"
and the password is probably "password".
Because we can program the “Log in” button to redirect to the real Codecademy page, unless a potential
victim had looked at the domain and noticed that something was off, they would have had no indication
that the page just sent their information to us. This is one potential way that an attacker can use a
website to trick someone into handing over their credentials. It seems like there are a million ways we
can be expertly deceived on the web. Let’s talk about how to detect these!
Phishing is a type of attack that can take many forms. For example, , (voice phishing), and (SMS
phishing) are all threats. Attackers can also send emails that look like they are from legitimate senders
by using spoofing.
malware
vishing
DDoS
smishing
sealing
social engineering
Detection Techniques
Fortunately, there are ways that we can train both ourselves and our organizations not to fall for
phishing! Although many phishing websites are near copies of the originals, phishing emails can be
easier to spot. Below are three examples of phishing, two emails and one webpage. Can you spot the
indications on each that it isn’t legitimate?
Example One:
This one is pretty convincing. Did you spot the giveaway? The sender is paypal[.]accounts@gmail[.]com.
Remember, anybody can register a @[Link] address. The real PayPal will always use a business
domain: @[Link]. Another method? You can open developer tools on any buttons in an email to
see where they are taking you. Developer tools is a cybersecurity expert’s best friend. It can reveal many
secrets that attackers don’t want you to see.
Example Two:
An image showing an email from Tom Atwood. Tom is asking if Laurie will open a link to read and review
Tom's resume at [Link].
This is also a pretty convincing email, especially if Tom Atwood is in your contacts. In fact, once an
attacker compromises an email address, they can use it to distribute more phishing emails to the people
in the victim’s contacts list, utilizing email spoofing to make the emails appear to come from known
contacts. The fact that the attacker addresses the victim by name would also make this an example of
spear phishing. What’s the giveaway here? Take a closer look at that URL - the second “g” in “google” is
really a “d”. This means that the link is probably taking you to a malicious fake website which will ask
you to log in to Google Drive and steal your credentials.
Example Three:
An image showing the Social Security website at [Link]. There is a username and password field with a
"Sign In" button.
This webpage is very similar to the real Social Security webpage, visible here. However, two things are a
bit off. Firstly, all official U.S. government websites should have a .gov domain, not a .com, and secondly,
have you ever seen a username and password field without an option for “forgot password?” Looking at
the domain will probably provide the best information, but paying attention to small details such as
missing or malfunctioning buttons, and grammar or punctuation mistakes, are key in identifying phishing
pages.
Multiple choice
Check to see if the site or email is from a domain that doesn’t end in .com.
The variety of phishing types, the low cost to create phishing pages, and the ease with which someone
can create one, all make phishing a difficult threat to counter. Additionally, regardless of how complex a
system is, no system in the world can guarantee against a human employee clicking on a malicious link.
This is why it is important to always report suspicious emails or links at work to the appropriate
department so that they can block suspicious senders and domains. If you are paying attention to small
details and reporting suspicious content, one person can do much to protect an organization and
themselves against phishing attacks.
While we’ve talked about some strategies for phishing, you should never use them to harm others. If
you’re on the security team at your work, you could run a phishing campaign to see if employees know
what types of content to avoid.
You can use certain tools like Passive DNS to find real live phishing pages online, or check out some real
examples of phishing campaigns. You can also see them in your email’s spam folder, and even examine
the email headers to see where the mail is coming from, but be careful not to click on anything! Finally,
you can check out some famous phishing attacks. Phishing is everywhere - but if you equip yourself and
equip others, you should be safe!
SQL Injection
In this article, you’ll learn various SQL Injection techniques and strategies to mitigate these attacks.
When you log in to Codecademy, you provide a username and password which are used to authenticate
you. But how does this work under the hood? When you provide these credentials, the Codecademy
server will take your input and compare it against user data inside a database.
That step of checking the input against the database can be abused by attackers. Through a cleverly and
carefully crafted input an attacker can inject code directly into the database query, getting precious
data!
In this article, we’ll be talking about SQL Injection, which is this type of attack on a SQL database. You
will be introduced to:
For web applications, SQL is the most common solution for storing and interacting with data. SQL is
short for Structured Query Language, which helps communicate and manage a relational database.
What does a relational database look like? It is a collection of tables each with rows and columns. Take a
look at the image below:
orders items
order_number int PK
item_id int FK
cost float
item_id int PK
price int
description longtext
In this database, we have two separate tables - the orders and items tables. In the orders table, we have
three separate rows - the order_number, item_id, and cost. In this diagram, there is a relationship
between the item_id field in the orders table to the item_id field in the items table. The item_id field is
the primary key (PK) in the items table. A primary key is used to relate one table to another table.
This is how most websites organize their data, and SQL is the key to retrieving and updating data.
An SELECT statement to select the list of all customers from the orders table
UPDATE items
Fill in the correct SQL keyword to choose data from the User table.
* from Users;
UPDATE
INSERT
SELECT
A SQL injection is a common vulnerability affecting applications that use SQL as their database language.
A hacker can use their knowledge of the SQL language to cleverly construct text inputs that modify the
backend SQL query to their liking. They can force the application to output private data or respond in
ways that provide intel.
An XKCD comic in which a mother named her son "Robert'); DROP TABLE Students;--" which caused the
school database to drop the whole "Students" table.
Using the following injection techniques, threat actors may be able to access information they shouldn’t
have, change database records, or even take complete control of the system!
Union-Based Injections
A union-based injection leverages the power of the SQL keyword UNION. UNION allows us to take two
separate SELECT queries and combine their results. Union-based injections can allow an attacker to
quickly steal information from a system.
Say this is how the query is created when a customer searched for a product name (USER_INPUT):
This input would create a valid SQL statement that grabs information for “soap” but UNIONS all the
usernames and passwords of the users!
Error-Based Injections
In an error-based injection, an attacker writes a SQL query to force the application to return an error
message with sensitive data.
Let’s take a look at the example below from an actual vulnerability. In this example, the attacker’s input
causes an error that spits out the password.
SQL query:
SQL completes that inside statement getting the password for the profile ID 1, but errors on the value
type that should be returned. This is the error that accidentally gives away the password!
Boolean-Based Injections
Boolean-based injections involve SQL statements that can confirm TRUE/FALSE questions about the
database. When using this method, the attacker takes note of the difference in the web response
(changes in HTML, HTTP response code, or other web session data) when the result of their question is
true or false.
Suppose a website has a search box that will return the username and email of a specific user ID. The
SQL query below is used:
In a normal search for id 1, the website will give back the username admin and email admin@[Link]
and display everything as normal.
Someone sneaky can use the AND keyword to see what happens on the website when the SQL
statement is false.
SELECT username, email FROM users WHERE id = '1' AND '1' = '2';
We won’t be getting a username and email back, since 1 is never equal to 2. At this point, the attacker
makes note of what happens on the website when the statement is false.
The attacker would also make note of what happens when the modified SQL statement is true (1 is
always equal to 1).
SELECT username, email FROM users WHERE id = '1' AND '1' = '1';
Using this technique with the AND keyword, the attacker could write in any boolean statement on the
other side of the AND, and based on the website’s response figure out if the statement is true.
Boolean injections are often used to figure out the name of a database table (possibly to build up for a
Union-based injection), manipulating one query at a time to confirm one character at a time.
Time-Based Injections
Not all SQL injections will provide visible output. A time-based injection makes use of several built in SQL
functions, such as SLEEP() and BENCHMARK(), to cause visible delays in an application’s response time.
While the output of a command isn’t visible, delays in the response time can be used to infer some
information!
Suppose we have a database query that will check to see if a certain username USER exists within the
database.
SELECT id FROM users WHERE username = 'USER';
Someone could write this SQL syntax as the text input to confirm if the admin‘s password is
P@ssw0rd123
SELECT id FROM users WHERE username = 'a' OR IF((SELECT password FROM users WHERE
username='admin')='P@ssw0rd123', SLEEP(5), NULL);-- -';
If there’s a 5-second delay before a response from the server, an attacker could confirm the admin user
had a password of P@ssw0rd123.
Out-of-Band injections are generally the rarest and most difficult injections to execute for attackers.
Unlike the other methods, which return the results via the web application, an out-of-band injection will
leverage a new channel to retrieve information from a query.
Generally, these SQL injections will cause the database server to send HTTP or DNS requests containing
SQL query results to an attacker-controlled server. From there, the attacker could review the log files to
identify the query results.
Again, these injections are extremely difficult to execute. They rely on permissions to database functions
that are most often disabled, and would have to bypass firewalls that might stop requests to the
attacker’s server.
An image showing that the attacker injections a malicious SQL command, then the web server processes
the injected command, then the database server sends an outbound request to the listening server.
Finally, the attacker collects the captured information.
Multiple choice
While testing a web application you try out SQL injection into input boxes. You find you’re unable to get
visible output, but you notice that you can cause the database to delay its response. Which type of SQL
injection would you use to gather additional information from this database?
Out-of-Band Injection
Boolean Injection
Error-Based Injection
Time-Based Injection
Multiple choice
While working as a cyber consultant for an organization, you learn an attacker recently breached their
database! While looking through the web request logs you see thousands of requests containing queries
with the SLEEP() command. What type of injection did this attacker likely use?
Out-of-Band Injection
Time-Based Injection
Boolean Injection
Error-Based Injection
There are two main methods for preventing injection attacks: sanitization and prepared statements.
Sanitization
Sanitization is the process of removing dangerous characters from user input. When it comes to SQL
injections, we would want to escape dangerous characters such as:
'
\--
These sorts of characters can allow attackers to extend queries to output more data from a database.
While this does provide a layer of protection, this method isn’t perfect. If a user finds a way to bypass
your sanitization process, they can easily inject data into your system.
Additionally, depending on your query, removing certain characters may have no effect! Therefore, this
shouldn’t be your only defense mechanism.
Prepared Statements
Writing prepared statements (also known as parameterized queries) in backend code is a common,
reliable, and secure solution against SQL injections. Prepared statements are nearly foolproof.
How does it work? We provide the database the query we want to execute in advance.
First, a SQL query template is sent to the database. Certain values, called parameters, are left
unspecified. For example, user input.
Then we pass in the parameters/user input. Any input, regardless of whether the content has SQL
syntax, is then treated only as a parameter and will not be treated as SQL code.
Here is an example of what a prepared statement looks like in PHP web application backend code:
$username= $_GET['user'];
$stmt->bind_param("s", $username);
$stmt->execute();
In addition to providing added security, prepared statements also make queries far more efficient.
Multiple choice
Removing characters such a ', ;, and \-- to prevent them from impacting a query
Programming a firewall to drop network packets containing potential SQL injection attacks
Multiple choice
Prepared statements improve query efficiency, while also adding additional security when implemented
properly.
Prepared statements active search through the input and remove potentially dangerous characters.
They are 100% secure from SQL injection attacks, regardless of how they are implemented.
Conclusion
Since databases are a crucial part of many applications, SQL injection flaws continue to persist. Whether
you’re developing an application or doing penetration testing to improve security, it’s crucial to
understand the different forms of these SQL exploits!
In this article, you will learn about two types of web attacks: Cross-Site Scripting and Cross-Site Request
Forgery.
Cross-Site Scripting (XSS) is a common web application vulnerability that occurs when a web application
returns unsanitized input to the front end of an application. In an XSS attack, an attacker takes
advantage of this vulnerability by inputting malicious code, generally in the form of JavaScript, through
the browser. This can lead to the attacker stealing information from a user, redirecting users to
malicious pages, or taking control of their browser!
The three categories of XSS attacks are Stored XSS, Reflected XSS, and DOM-Based XSS, which differ in
how the payload is stored and executed.
Stored XSS
Stored XSS attacks are generally considered the most serious. A stored XSS vulnerability occurs when a
web server saves an attacker’s input into its datastores. Because this input is saved, it may be harder for
a user to detect. In a worst-case scenario, this input will be saved, and then returned to numerous
victims. The below image provides a basic overview detailing this process.
An image showing that in Stored XSS an attacker creates a comment with code, the web server saves the
comment, the user requests to see the comments, then the server sends the comment to the victim's
browser where the code is executed.
A common example of a Stored XSS attack would be a poorly designed comment function. If a developer
does not properly sanitize a user’s comment, it may be possible for an attacker to add arbitrary
JavaScript to their comment. If this were to occur, then any time their comment was loaded by the
server, the attacker’s code would execute in the victim’s browser.
Reflected XSS
Reflected XSS occurs when a user’s input is immediately returned back to the user. This return may
come in the form of an error message, a popup, or a search term. In these instances, the payload is
never stored by the server. Rather, it exists as a value in the URL or request. Despite this, these payloads
still pose a risk to users. Through social engineering, an attacker could spread their payload to
unsuspecting victims as shown below.
An image showing in Reflected XSS that an attacker sends a script injected link to the victim, the victim
clicks on it, the victim's browser loads the legitimate site while also executing the malicious script, and
then the malicious script sends the user's information to the attacker.
DOM-Based XSS
DOM is an abbreviation for Document Object Model. The DOM is used to help scripts and the underlying
webpage interact. However, when user input is interpreted by the DOM, an attacker is able to inject
arbitrary code. These types of vulnerabilities do not cause any changes in how the server responds.
Rather, these attacks are completely client-side.
For example, a web page may use client-side Javascript to customize a welcome page, displaying their
name based on a value in the URL. Depending on how the javascript runs, an attacker may be able to
replace the name value with a malicious script. If a victim loaded the page with the attacker’s code, the
vulnerable javascript may execute the code!
An image with the following steps: 1) Attacker sends link containing malicious code, 2) Victim opens link,
3) Victim's browser sends request to server, 4) Server responds with page 5) Victim's browser loads
vulnerable Javascript and executes the attacker's payload.
Multiple choice
A web application allows users to post public messages that are displayed to other users. These
messages are saved in a backend database. Unfortunately, it appears as if a hacker has figured out a way
to inject arbitrary JavaScript into these messages. Their code impacts any user who loads the public
messages. What type of XSS attack would this be considered?
Reflected XSS
Dynamic XSS
Stored XSS
Multiple choice
While exploring a site you find you a value in the URL is reflected back to you. After some careful fuzzing
you find you can inject arbitrary JavaScript into the site via this URL. The payload does not appear to be
a result of client side code. What type of XSS attack is this?
Stored XSS
DOM Based XSS
Mirrored XSS
Reflected XSS
As with any vulnerability, it is important that we investigate any potential input areas. When looking at
the application, consider all possible fields. Comments, usernames, custom settings, and parameters all
provide great starting points.
Once we have identified a potential inject point, we can begin testing various inputs to create a proof-
of-concept payload (POC). A POC payload will demonstrate that an issue exists, without causing damage.
The most basic POC payload is shown below.
<script>alert(1);</script>
If a web server is not properly sanitizing user input, this will return a pop-up box similar to the below
image.
This image shows "<script>alert(1)</script>" was injected into the URL which caused a Javascript alert to
show up on the screen.
If this payload does not work, that does not necessarily mean the system is secure. In fact, many
systems will take a flawed approach to protection and block certain words. If a blocklist is in effect your
request may be blocked, or your <script> tags could be removed. If this happens, we can look to
alternative mechanisms to execute JavaScript. In fact, there are numerous ways we can execute code,
without ever using a <script> tag. Below are some potential workarounds.
<img src="X" onerror=alert(1);>
<body onload=alert('test1')>
After exploring a web application, you found an injection point that allows you to enter arbitrary HTML.
Unfortunately, when you attempted to inject a payload with the <script> tags, the application removed
them. Create a payload which could circumvent this protection mechanism, given that you are able to
use tags such a <b>.
<b "alert(1)"></b>
<b javascript="alert(1)"></b>
<b onload="alert(1)"></b>
Similar to SQL injections, XSS is preventable with both application-level firewalls and sanitization. Similar
to the SQL injections, firewalls should be used to aid defense, but should not be used as your only line of
defense.
Sanitization
Sanitization is the process of removing/replacing problematic characters with safe versions. Depending
on the backend language, there may or may not be built-in functions to aid in this process.
However, if these functions do not exist, we can generally succeed in preventing XSS attacks by
removing characters such as <, >, ", =, and potentially dangerous keywords.
Rather than remove characters, we can also replace them with HTML-encoded versions of the
characters. This allows us to retain the characters, but remove their capacity to affect the page’s HTML.
For example, the < character would be converted to the “<” string. The browser will render this string as
the “<” character, but it will not interpret it as actual HTML, preventing the attack.
It is important to note, however, that depending on how the data is used, this type of escaping may not
be enough. It’s important to consider all potential avenues for an attack.
Cross-Site Request Forgery (CSRF) is another class of vulnerability focused on poor session controls and
session management. When we log into Codecademy, we create an active user session, and this session
allows us to interact with our courses, profile, and the site in general. By sending the right request, we
can change our password, email, and what classes we are enrolled in.
However, in some cases, the way these sessions, and the requests we send, are handled is flawed.
Sometimes, the requests sent by an application aren’t unique. As such, it’s possible for an attacker to
craft a special request and send that to a user. If the user interacts with the crafted request, and
sessions aren’t handled properly, an attacker may be able to make changes on behalf of a user.
Suppose our web application allows users to change their password via the following link, where [USER
PASSWORD] would contain the new desired password.
[Link] PASSWORD]
If the developers didn’t consider the impact of cross-site request forgery attacks, a threat actor may be
able to create a new password link and send it to the user. When the user opens the link, they would
initiate the password change, but with the attacker-supplied password! This would allow a hacker to
take over their account!
Because the request considers nothing but the current session, a user would have their password
changed.
Preventing CSRF
While the impacts of CSRF can be large, they are relatively easy to mitigate.
One of the simplest ways to prevent these attacks is to add a CSRF token. This token is a unique value
that is added to each request. This value is dynamically generated by the server and used to verify all
requests.
Since this value is unique for every request, and constantly changing, it is nearly impossible for an
attacker to pre-create the URLs/requests for an attack.
While a CSRF token can prevent many malicious requests, it can still fail. If an application is vulnerable to
XSS a hacker could use their XSS attack to extract this token! In some cases, we may want a user to
manually enter additional information prior to a critical request.
For example, prior to changing a username, email, or password, we may want the user to enter their
current password. By ensuring the request has the correct password, we can ensure that an attacker
isn’t able to compromise a user, even with XSS.
Multiple choice
By using cookies.
Conclusion
While cross-site scripting and cross-site request forgery both pose a serious risk to users, and the
systems they interact with, developers can take many steps to prevent these attacks. However, when
developers fail, attackers can execute arbitrary code, steal information, and cause serious harm.
Through careful control of sessions, we can prevent cross-site request forger attacks. And through
careful handling of data and sanitization, we can easily prevent cross-site scripting attacks.
In this article, you’ll learn about zero-day and DDoS attacks as well as some of the strategies they use.
This article will introduce two unique threats to organizations: zero-day and DDoS attacks. These are
threats that enterprises must understand and protect themselves against.
Zero-Day Attacks
A “zero-day” (also called “0-day”) vulnerability is a newly-discovered software bug that a developer was
not aware of before the software was released. Therefore, after it is discovered, the developer has
“zero” days to patch it before it can be exploited. When a “zero-day attack” occurs, the vulnerability
quickly becomes known and is patched by the developer.
For example, in one well-known case, malware referred to as Stuxnet was used to attack Iran’s nuclear
program. Using four separate zero-days, the Stuxnet worm ruined up to one-fifth of Iran’s Nuclear
Centrifuges. The malware was widely believed to have been developed jointly by the United States and
Israel. Zero-day attacks were also responsible for the 2014 attack on Sony pictures and Russia’s 2016
attack on the DNC.
A political cartoon showing two men looking at a broken rocket as one says "Do we have a backup?" The
computer says "Stuxnet VIRUS".
[Link]
Because zero-days are difficult to discover and exploit, they are more often leveraged by nation-state
actors, who have the resources and infrastructure to find and exploit these vulnerabilities. Although
rare, new attacks occur each year.
Finding and Classifying Vulnerabilities
The vast majority of cyber attacks exploit existing vulnerabilities. These vulnerabilities are catalogued
and numbered as CVEs, or “Common Vulnerabilities and Exposures” and are maintained in places like
the Mitre Corporation’s database or the National Vulnerability Database (NVD).
An image showing a CVE report CVE-2020-27918. It was for "A use after free issue was addressed with
improved memory management".
Thousands of CVEs are recorded every year and are typically found first by either security companies or
researchers participating in companies’ bug bounty programs. Bug bounty programs offer money (a
bounty) to anyone able to find a vulnerability in their systems. Once the vulnerability is found, the
organizations are able to implement a patch and release a software update as soon as possible. It is
much more difficult to attack an organization that keeps its software up to date!
Multiple choice
Why are zero-day attacks less common than attacks which leverage existing CVEs?
Zero-day attacks must be done on the very first day something is released so attackers have “zero days”
to find it.
Zero-day attacks are actually more common than attacks exploiting existing CVEs.
Zero-day attacks are less profitable than attacks that leverage existing CVEs.
Zero-days are expensive and difficult to find, whereas existing CVEs are cataloged and can be used
against any organization that has not secured its systems.
DDoS
DDoS stands for Distributed Denial of Service. A DDoS attack is when an attacker attempts to make a
resource, such as a website’s various servers, go offline by overwhelming it with web traffic. It is similar
to trying to drive during rush hour: the more cars there are, the slower everyone goes. How does an
attacker do this? They make requests to a resource with a large number of computers, overwhelming
the resource and making it run slower and slower until eventually, it goes offline entirely.
An image showing a computer looking tired and overwhelmed as it's swarmed by lots of bugs. The bugs
represent requests to the computer.
Because an attacker must use a large number of computers, the attack is “distributed” across multiple
devices. The goal is to knock the resource offline so that it “denies service”; hence the name “distributed
denial of service”.
Multiple choice
An attack in which many devices attempt to bring down a server by overloading its resources.
An attack in which a single computer brings down a server by overloading its resources.
But where does an attacker get all of these computers from? Large websites are equipped to handle
thousands of visits per day, so it takes a lot of web traffic to overwhelm them. This traffic comes from
botnets. Botnets are “robot networks” made up of computers infected by malware. These botnets can
be made up of millions of bots, and can even include IoT devices. A single attacker can spread malware
to many devices, and then use all of those devices in concert to act together, oftentimes without the
victims ever knowing that their devices are infected.
An image showing an attacker in charge of many evil computers that are marching to spread more
attacks.
Because botnet services can be rented out to other cybercriminals for specific attacks, anyone with the
money to rent a botnet can carry out a DDoS attack, leveraging the power of millions of computers,
making DDoS attacks ever more powerful.
Multiple choice
DDoS Attacks leverage the power of botnets to carry out a more powerful attack than a single device is
capable of.
When a server is brought down as part of a DDoS attack, it becomes part of a botnet.
A single botnet that is made up of millions of devices is responsible for all DDoS attacks.
Network connections are defined by layers with each layer responsible for a different part of data
transmission. Different types of DDoS attacks target different network layers, specifically, layers 3, 4, and
7, known respectively as the Network, Transport, and Application layers. Different DDoS attacks target
different layers in different ways.
For example, one attack that targets the application layer is called “HTTP Flooding”. This is because the
attacker sends lots of HTTP requests — the kind of requests your browser makes when you visit a
webpage. In effect, it is like refreshing a website over and over again, making a server load content
repeatedly until it becomes overwhelmed.
On the other hand, “SYN Flooding” targets the Transport layer by taking advantage of something called a
TCP Handshake. Basically, it asks the server to wait for confirmation of a connection, but then never
gives that confirmation. This is like a large group of people all asking the same person to hold something
for them, but no one ever takes their item back, until the person holding everything eventually becomes
overwhelmed.
You can read more about different types of DDoS attacks here.
Multiple choice
DDoS attacks are classified by whether they are carried out by individuals or Nation-States.
Some types of DDoS attacks utilize existing vulnerabilities, whereas others use zero-days.
DDoS attacks are categorized as red, yellow, or white, depending on their severity.
Fighting DDoS
There are a number of ways that websites try to guard against DDoS attacks, for example, by rate-
limiting: limiting the number of requests a server will accept in a single time. CAPTCHAs can also provide
some protection. Theoretically, a CAPTCHA can determine whether a user is a human or a “bot”,
allowing legitimate web traffic to attempt to log in while blocking malicious automated traffic.
In general, it is difficult to guard against DDoS attacks. This is why websites seek protection from
organizations such as Cloudflare, which provides protection against DDoS attacks by sitting between the
server and the client, and forwarding legitimate traffic to the server while hiding malicious traffic.
However, the rise of Cloudflare and similar protective services has raised other ethical issues, as these
services can protect (and profit from) illicit and/or terrorist organizations, raising the question of
whether all sites deserve equal treatment.
Multiple choice
Signing up for the Mitre corporation’s international “Do not DDoS” list.
Conclusion
Zero-Day and DDoS attacks are each unique and significant threats that organizations have to protect
themselves against, although they represent only two of the myriad dangers that businesses face in
today’s world. As attackers become more creative and institutional, and as businesses migrate even
more of their operations online, the kinds of threats facing them are only going to increase. This is why it
is key to both understand the types of threats organizations encounter, and to understand the steps you
can take to mitigate them. Cybersecurity is a dynamic and diverse field, but the greater your breadth of
knowledge, the better placed you are to defend against evolving threats.
In the upcoming section of this course, we will discuss what cryptography is and how it is used for
security. This is a good opportunity to also introduce the concepts of authentication, authorization, and
non-repudiation that complement the CIA (Confidentiality, Integrity, Availability) triad for information
security.
Cryptography is used almost everywhere online. In fact, you even used it to communicate with this
website — the https that comes before many domain names indicate that encryption is being used to
exchange data between your browser and the server. That data could be your login credentials, whether
you have visited this site already, your device type, or sensitive personal information. This is ALL data
you want to keep private! We also pay attention to how cryptography is leveraged by hackers to lock
systems.
You’ll learn some basics about encryption and [Link] that demonstrates the act of encryption
up top (key opening and deciphering a text) and hashing at the bottom (using a hashing algorithm to
generate a hash value)
According to CISA,
Authentication and authorization go hand in hand. Users must be authenticated before carrying out the
activity they are authorized to perform. Security is strong when the means of authentication cannot
later be refuted—the user cannot later deny that [they] performed the activity. This is known as non-
repudiation.
Cryptography is the science of hiding data and making it available again. In cryptography, hiding data is
called encryption and unhiding it is called decryption. When data is securely exchanged, it is first
encrypted by the sender, and then decrypted by the receiver using a special key.
One of the earliest well-known instances of cryptography was the use of coded messages between Julius
Caesar and his military generals during Roman times. This is called the “Caesar cipher”. To use it first
draw the alphabet in a circle like this:
If our key was the number “3”, we would take every letter of the message and rotate it (move it) three
places to the right, so the letter “A” would become “D”. Using this method, the word “Hello” would
become “Khoor”.
This image shows the letter "A" rotated three spaces to become "D".
This is actually a very simple form of encryption, and as long as the person who receives your message
knows that you used “3” as the “key” to encrypt your message, they can decrypt it as well.
The Caesar cipher above is easily readable by a human. But how do computers, that interpret everything
as binary 0s and 1s, encrypt and decrypt? The answer is the XOR operation, a key component of many
complex algorithms used today, such as AES, the encryption algorithm used by the US government to
protect classified information.
What is XOR? XOR is an operation that compares two bits and returns True (1) if only one of the bits is 1,
and returns False (0), if the bits are the same value (both 0’s or both 1’s).
XOR gives the same string back if you perform XOR on it twice. For example, if you XOR 1100 with the
key 1001, it returns 0101, and if you XOR 0101 with the same key, 1001, you get 1100 again. This may
seem confusing to you, a human, but this is how computers… compute!
XOR encryption takes advantage of this reflexive property, so whatever key we XOR with a binary
sequence to encrypt it, we can use that same key to decrypt the sequence. XOR is the foundation of all
the common encryption methods!
The following is a secret message that was XOR-encrypted with the key cybersecurity. Try to decrypt it
using this XOR Decryptor!
2b-1c-1b-45-0b-1c-10-4f-55-11-06-1a-1e-11-18-16-10-1e-12-11-0a-1a-1c-1a-54-16-0d-59-10-00-11-16-
0c-15-1c-1c-0e-54-0d-0b-10-11-45-01-16-06-11-10-06-49-19-1c-10-0a-03-02-17-52-45-33-07-17-1d-00-
00-43-1c-1a-06-1b-07-0c-0d-12-5e-49-06-10-04-11-16-5a
Types of Encryption
Symmetric encryption uses the same key to both encrypt and decrypt data.
Asymmetric encryption uses two different keys to encrypt and decrypt data.
Symmetric Encryption
Both of the examples we looked at, Caesar Cipher and basic XOR encryption, used the same key to
encrypt and decrypt our data.
Symmetric encryption is the fastest way to encrypt data, and the most common for sending large chunks
of data, however, it has one major vulnerability: if you send someone your key, then it’s in a form that
any other person can read. That means your data is vulnerable to being stolen.
An image showing the sender and recipient encrypting and decrypting with the same key.
Asymmetric Encryption
Asymmetric encryption differs from symmetric encryption in one way: Instead of one key, you have a
key pair. A key pair is made up of a public key and a private key.
The public key can be given to anyone and is only used to encrypt data.
The private key is kept secret and is only used to decrypt data.
What’s the use of having two keys? Having two keys mean you are the only person who ever has access
to the private key used to decrypt data, so it is impossible for someone to intercept and read your
messages.
For example, if you want to receive an encrypted message from someone, you would first generate a
key pair and give them the public key. Then, they would write a message and encrypt it using the public
key you gave them. Finally, they would send you the message and you would decrypt it with your
private key. You never share your private key with anyone, including the recipient, so it never has a
chance to be stolen. Having two keys makes sure you are the only person who can decrypt and read
those messages since you are the only one with the private key.
An image showing the sender using one key to encrypt the data and the recipient using a different key
to decrypt the data.
If you wanted to send a message back to the original sender they would generate a key pair as well,
provide you with their public key, and you would repeat the process.
Asymmetric encryption is the most secure way to transmit data; however, it is slower and more complex
than symmetric encryption. Therefore, it is primarily used to exchange smaller pieces of data.
There are a wide variety of asymmetric encryption algorithms. The most common is RSA, which is based
on the factoring of prime numbers, and is functionally unbreakable if a large enough key is used
(although quantum computing could change this). Another asymmetric approach is Elliptical Curve
Cryptography (ECC).
Multiple choice
Symmetric encryption uses public key pairs; asymmetric encryption uses private key pairs.
Symmetric encryption encrypts and decrypts with the same key; asymmetric encryption uses a
public/private key pair.
Symmetric encryption is used for letters and numbers; asymmetric encryption is used for binary.
Symmetric encryption is used to receive data; asymmetric encryption is used to send data.
Encryption is used everywhere! Think this topic is fascinating and want to explore more? You can read
up on what it takes to become a professional cryptographer!
If you are running a UNIX based operating system such as Mac or Linux you can run basic encryption
algorithms such as “Rot13” with a single command. Windows operating systems do not come
preinstalled with an equivalent command; however, you can encrypt and decrypt messages with letter
rotation by using the rot13 website.
If you are interested in how cryptography can be used in programming, you can build your own Caesar
Cipher program with Codecademy’s projects in Swift or Python
In addition to using cryptography to keep things secret, you can also use cryptography to make sure
your data matches what you expect. This is where hashing comes in.
Unlike the methods we’ve already looked at, which are designed to both encrypt and decrypt data,
hashing is different. Hashing does not encrypt data. Instead, hashing is a one-way process that takes a
piece of data of any size and uses a mathematical function to represent that data with a unique hash
value of a fixed size. You cannot compute the original data from its hash.
A diagram showing that encryption uses keys to encrypt and decrypt data while hashing results in data
being transformed into a hash.
Because each hash should be unique, hashing allows us to see if changes have been made to
documents. For example, when you make edits to a file on Github, GitHub hashes the file to see
whether you made any changes. Similarly, if you wanted to know whether a website had changed, you
could download the CSS and HTML files, hash them, and then see if you get the same value when you
hash them later. If the value is different the second time, something on the website changed. No matter
how large or complex your file is, hashing provides a fast, reliable way to compare files and verify their
authenticity.
Ideally, hash functions always generate unique values for different inputs. When they don’t it’s called a
hash collision. While it’s hypothetically possible to encounter a hash collision with nearly any hashing
algorithm, with modern algorithms like SHA-256, it would take so long to result in a collision that it’s
functionally impossible. Earlier hashing algorithms, like MD5 and SHA-1, are more likely to result in hash
collisions.
Multiple choice
What is it called when two different inputs generate the exact same hash?
Hash Bombing
Hash Collision
Rainbow Tables
Multiple choice
SHA-256
SHA-1
MD5
It’s easy to get the hash value of some types data. If you are on a Unix-based operating system, open
your terminal and type:
That will give you the SHA-256 hash of the string “Hello World”. Try changing the string slightly, and
you’ll see that the resulting hash changes as well.
Windows does not have a built-in function to generate hashes of Strings (although you can use Get-
FileHash in Powershell to hash files), but you can easily get the SHA-256 hash of a string online.
Hashes are widely used in order to store passwords in online databases. If passwords are stored in
plaintext and a database is breached, so are all of the passwords! However, if they are stored as hash
values, even if someone hacks into a website’s database, only the password hashes are exposed. For
example, if your password for a website is:
CodecademyIsGr8t
But that website is storing it as a SHA-256 hash, even if someone hacked into that website, all they
would see is the hash value.
d04f855e71ad9d495d91e666175d593b669f45970f885a258f6dbbaab262ac8b
Remember, an attacker has no way of “decrypting” a hash value to get the original value.
Attackers can still come up with a list of common passwords, generate hashes, and find which lines in
the database match those hashes. Rainbow tables, massive tables of common passwords and password-
hash combinations, speed up that process even more. However, It is practically impossible for an
attacker to guess and match the hash of a complex password!
Organizations can further protect hashed information by using something called a salt. A salt is a secret
random string that is combined with a password prior to hashing specifically to defend against the use of
rainbow tables.
Multiple choice
Multiple choice
Which of the following is NOT a use of hashing?
Conclusion
Cryptography is a dynamic field, with new algorithms being invented, tested, and solved all the time, it is
also an essential part of keeping up information security. You will continue to see the applications as you
learn more about cybersecurity!
Authentication is the verification of who you are and Authorization is the verification of what you have
the right to do.
When it comes to securing systems, there are two key concepts to be aware of: authentication and
authorization. Although these terms may sound similar, they represent two very different things, and
understanding the difference is key to keeping yourself, your devices, and your systems secure.
An image showing that Authentication is when you log in and Authorization is what you are allowed to
do.
Usually, you have to be authenticated before you can be authorized and the cyber world is no different.
There are many different kinds of authentication, the most common of which is a password. However,
the PIN number you enter when you withdraw money from an ATM, the fingerprint or face ID you use to
unlock your phone, and personal information such as your phone number, social security number, or
address are all forms of authentication.
The number of ways you need to authenticate yourself before you can access a resource is also
important. As a general rule, the more forms of authentication required to access an asset, such as a
bank account or a secure webpage, the more secure the asset is.
Multiple choice
Authentication is used in the physical world; authorization is used in the cyber world.
Single-Factor Authentication
An image showing that the user only needs a password to log in to the website.
Single-Factor authentication refers to when only one form of authentication is used. For example, when
you log in to a webpage using only a username and password and are granted access, that is single-
factor authentication. Single-factor authentication is more common than Multi-Factor Authentication
because it is the most convenient for users and involves less engineering. Users don’t have to remember
or have on hand as many means of authentication, so they can more easily access resources.
Unfortunately, due to evolving threats against common methods of single-factor authentication, this
method is becoming increasingly insecure.
Passwords are the most common type of authentication used in Single-Factor Authentication and are
vulnerable to credential stuffing, brute forcing, phishing, social engineering, and malware. In fact, with
some studies suggesting that 80% of data breaches in 2019 were caused by password compromise, it’s
clear that passwords are not a sufficient means of securing systems.
How about PIN codes? Well, let’s say you go to your local coffee shop to work on your Codecademy
Cybersecurity course and are so focused that you don’t notice your wallet is missing. Now that they have
your debit card, how hard would it be for them to guess the PIN?
Unfortunately, probably not very hard. If your PIN code is 1234, then you are one of about 11% of
Americans to have used this secret number. Is your pin 1111? Then you’re one of the 6%! Maybe you
thought you’d be clever and use your birthdate? Unfortunately, that’s written down on the driver’s
license that’s in your wallet next to your debit card. In fact, a study of 3.4 million PIN codes showed that
over a quarter of them were guessable in under 20 tries.
RankingPIN Frequency
#1 1234 10.713%
#2 1111 6.016%
#3 0000 1.881%
#4 1212 1.197%
#5 7777 0.745%
#6 1004 0.616%
#7 2000 0.613%
#8 4444 0.526%
#9 2222 0.516%
What if instead of your wallet, somebody got their hands on your new phone? There are tools that can
be used to disable the maximum number of wrong attempts, and once that is done, a four-digit pin code
takes only six and a half minutes to crack on average. A six-digit pin code will buy you 11 and a half
minutes.
There are other forms of Single-Factor Authentication too; however, for every method of
authentication, there are many ways to bypass it. That’s why it’s much more secure to use Multi-Factor
Authentication.
Multi-Factor Authentication
An image showing that the user needs a password, a code sent to their phone, and that same code
inputted into the website before they can gain access.
Multi-Factor Authentication (MFA) is the use of multiple types of authentication in order to access a
single resource. The most common form of Multi-Factor Authentication is Two-Factor Authentication
(2FA). For example, if you log into your bank’s website with a username and password, and then receive
a text message with a One-Time Passcode (OTP) that you also need to enter to gain access to your bank
account. That is an example of 2FA (and MFA).
MFA can take many forms. For example, instead of sending an OTP in a text message, many
organizations utilize app-based codes. Apps like Google Authenticator and YubiKey provide passcodes to
services that partner with it through free applications on your phone. These codes regenerate every few
seconds so an attacker doesn’t have time to brute force (try every single combination of) your OTP.
Am image showing the code for multiple gmail [Link] of the Google Authenticator App
from the Play Store
MFA is far more secure than Single-Factor Authentication and should always be used with important
accounts such as your bank. With Single-Factor Authentication, all an attacker needs is your password or
PIN. But with MFA, the attacker would need both your password and access to your cell phone or email
to receive a passcode, something they are far less likely to have.
Nevertheless, MFA is still vulnerable to certain kinds of attacks such as SIM Swapping, a social
engineering attack in which an attacker remotely steals a victim’s telephone number to receive a text-
based OTP. App-based codes are secure against sim swapping, but vulnerable to certain types of mobile
malware that can infect your phone and steal these codes. Certain operating systems and phone models
(particularly iOS) are more secure against mobile malware, but any form of authentication is vulnerable
to being stolen.
Not all applications have MFA; it is up to each organization’s security engineering team to make it
available. However, even though MFA makes it slightly less convenient for you, the user, enabling MFA
on your accounts when available is one of the single biggest things you can do to protect yourself online.
Multiple choice
You use your PIN code at an ATM with your debit card.
You enter a username and password and then receive a text message with a passcode.
You enter your username and password and receive access to a website.
Multiple choice
Why is Multi-Factor Authentication (MFA) more secure than Single-Factor Authentication?
More authentication methods make it less secure because it creates a wider attack surface.
Now that we’ve looked at the different ways that users authenticate themselves, we have to think about
how that data is securely communicated to a service we want to use. When the user enters their
username and password on a website and hits “Submit”, what happens? Your web browser submits that
information to the server’s API to authenticate you. An API is the part of a server that sends and receives
data. There are three main types of API authentication:
API Keys
OAuth
HTTP Basic Auth is the oldest (since 1999) and simplest method of authentication. It simply requires you
to send your username and password every time you communicate with the web page. The reason this
isn’t necessary when you use your browser is because of something called cookies. Cookies store your
credentials so that you don’t need to send them every time you click on a button.
API Keys
API Keys are similar to HTTP Basic Auth except, instead of a username and password, you use something
called an API token. An API token is a unique string of letters and numbers generated for each user. API
Keys are frequently used by developers to authenticate their own scripts or applications when
interacting with another application’s API. For example, you can use them to authenticate a script that
queries a website for large amounts of data or to authenticate a bot on Discord. API Keys have the
added advantage of being long and difficult to guess.
Unfortunately, API Keys are too long and complex to be practical for everyday users to use them to log
in, and like the credentials used in HTTP Basic Auth, they are vulnerable to interception when they are
submitted for authentication.
OAuth
Sometimes we don’t even have to create a username and password for a new account. Instead, we can
sign in with Google, LinkedIn, Twitter, and more. This is possible because of OAuth. How does this work?
Here’s how it looks on Codecademy:
If you go to the Codecademy sign-up screen, at the bottom you have the option to authenticate using
LinkedIn, Google, Facebook, or Github. Let’s say you choose the “Sign in with GitHub” option.
An image of the Codecademy login screen. It has multiple options for OAuth.
[Link]
That will redirect you to a specific Github login screen that looks like this:
An image showing a login screen that says "Sign in to GitHub to continue to Codecademy" and asks for a
username and password.
You can now log in to your GitHub to authenticate yourself — without Codecademy ever receiving your
GitHub password. All of the normal login protocols on Github will still be active. For example, if you have
MFA enabled on your GitHub (and you should!) this will be the next screen you see:
An image showing that GitHub has sent a 6-digit code to an email address.
Once you input the OTP sent to your email, GitHub will tell you exactly what permissions Codecademy is
requesting, and will ask you whether you want to grant Codecademy access to these permissions.
If you choose to authorize Codecademy, you will be redirected back to Codecademy along with a short
authorization code. Codecademy will request an access token from the GitHub API, which will then
provide the authorization code and other authentication details in a POST request.
Finally, after receiving this request, GitHub can either generate one or two tokens. If it only generates
one, then it will generate an access token. The access token grants the requested permissions to
Codecademy so that you can log in.
An image showing the back and forth steps between the consumer and service provider in OAuth before
access is granted to the consumer.
Multiple choice
True or False:
When you use OAuth to create an account on a third-party website by utilizing your Gmail credentials,
that third-party website stores your Gmail credentials.
False
True
OAuth tokens are great at defending users against data breaches since they eliminate the need to store
passwords. However, OAuth is still vulnerable to attacks. Imagine that an attacker sets up a malicious
website and tells users that they must authenticate with OAuth through GitHub. Instead of asking for
just an email, the website asks for access to private repositories and secret gists! If a user grants this
access to the malicious application, the attacker would have access to all of the user’s private
information on Github — without ever knowing their password! This was the method successfully used
by the hacking group Fancy Bear (also known as APT28 and Pawn Storm) to attack the Democratic
National Convention in 2016.
All methods of authorization have advantages and vulnerabilities and OAuth is no exception; however, it
remains a generally secure and convenient way to authenticate yourself on trusted applications.
Finally, now that we’ve talked about authentication, authorization, and the ways that APIs do this, there
is an important concept called Role-Based Access Control (RBAC).
Role-based access is exactly what it sounds like: you have permissions to access certain things
(authorization) based on your role/responsibilities (authentication). For example, a professor and a
student may both have access to enter the same university. However, the student may have access to
the dorms whereas the professor does not, and the professor may have access to the faculty offices
whereas the student does not.
In an enterprise environment, role-based access is usually controlled through a system of users and
roles. Each user is placed in a role and given access to all of the systems that come with that role. By
ensuring that each user has only the access necessary for their role, systems become more secure while
streamlining operational efficiency.
Implementation is similar in a web application. For example, in an online forum users may be forum
guests, members, or administrators. Guests may only have permission to view posts, members to view
and create posts, and administrators to view, create, and delete posts.
Multiple choice
It is more convenient than giving every user different permissions and more secure than giving every
user the same permissions.
It encourages people across an enterprise to interact with the IT department.
It should not be used as it is less efficient and secure than granting each user a different set of
permissions.
Authentication is a challenging concept, not least because of how many ways there are for users to
authenticate themselves. For example, there are other authentication protocols that are similar to
OAuth, such as SAML. If you are interested in developing authentication systems, you can check out
Mozilla’s framework for this.
You can also learn more about role-based access systems or threats to MFA.
Remember, there is a ton of information out there, and you don’t need to be an expert in everything all
at once! The best way to start is to observe how each topic relates to your everyday experience, and
explore any small changes you can make.
Networking is how you’re able to access this Codecademy webpage right now! In this chunk of the
course, we’ll tackle some of the basics behind networking. You will learn what a network is and how the
Internet operates on a system of standards and protocols.
A person is accessing the Internet through their computer. The connections form a road for trucks
carrying data.
How we are able to exchange such large amounts of information over the web and between our devices
may seem a bit mystical. How we keep this exchange secure is the whole field of network security!
We will cover some basic network defenses, like firewalls, wireless network security practices, and
monitoring tools. There are two hands-on activities to practice with.
What happens when we access Codecademy? How are we able to access the content provided by this
course? Networking!
Your device uses a network connection and goes through a series of defined network protocols to send
and receive information.
A network is two or more computers or devices that are linked in order to share information.
Our computers and devices are able to communicate due to a large set of standards, much like we have
road systems and traffic protocols when we drive a car. These network standards have been built by the
community over the decades, and these standards guide engineers and security professionals.
In this lesson, we’ll learn about types of networks, conceptual models to describe all the layers of
networking, and important network protocols.
Types of Networks
When we talk about a network, that could be anything connecting two or more devices. It’s important
we understand the different types of networks. Networks are broken into different subsets based on
their size and function. Here are some of the most common network types:
LAN
A Local Area Network (LAN) is a smaller network that connects multiple devices in a limited area.
Examples of LANs include small offices, a home, or any other network contained within a small area.
CAN
A Campus Area Network (CAN) connects multiple computers and devices over a slightly larger area. In
many cases, these types of networks will connect multiple buildings located in the same vicinity. You
may see these networks in a university where multiple buildings and outdoor spaces provide students
with network access.
WAN
A Wide Area Network (WAN) connects multiple computers over a geographically large area. Large,
international organizations may operate these types of networks. To ensure that computers spread over
large regions are able to communicate, companies may use a VPN (Virtual Private Network) to connect
systems securely. A VPN can allow systems across large regions to connect and interact with one
another on the same network.
Since we’re all connected to the Internet, the whole Internet can technically be classified as a WAN!
The OSI (Open Systems Interconnection) Model was developed in the 1970s and 1980s, and it is a
conceptual model that breaks networking into seven separate layers. Each layer refers to a set of
functions that are responsible for specific tasks. The layers start from physical signals all the way up to
the web applications we interact with. Each layer generally only interacts with the layer below it and
provides useful tools or information to the layer above it.
This is a conceptual model, meaning it is neutral to specific implementations or standards. We will talk
about the TCP/IP Model, which maps to specific implementations, later in this lesson. OSI is used to help
us categorize network processes so we can communicate about them during troubleshooting and while
improving security.
We’ll talk about the seven layers over the next few exercises.
Layer 1 – Physical
The Physical, and lowest layer of the model, covers how unstructured data, like bits, is transmitted.
Some concrete examples of this are the ways wires are configured, the way signals are transferred over
those wires, and the radio frequencies computers use. Technology such as WiFi, Bluetooth, and cable
standards such as CAT5 and CAT6 all operate at this layer. This layer also includes the hardware part of
modems, adapters, and repeaters.
Over these wires and signals, the raw data bits are received as a stream of 0s and 1s. Fixing errors that
occur just at this layer means considering physical damage or interference.
It involves physical addresses of devices, called Media Access Control (MAC) address. All devices have a
unique 48-bit MAC address where the first 24 bits relate to the manufacturer, and the last 24 bits make
it unique to each device.
It routes data frames to the correct physical addresses. A switch (could be your computer or router)
keeps track of local devices and their MAC addresses and makes sure data frames get to the correct
physical location.
It ensures the flow of data is synchronized between devices, so data doesn’t jam up the memory of a
slow receiving physical device.
It detects errors within data frames. This involves a system ofOSI Layers 3 and 4
In layers 3 and 4, we begin to see how data is routed between different networks and how
transportation protocols function within these layers!
Layer 3 – Network
The Network layer describes how data packets are routed between wider networks such as the Internet.
Whereas a data frame at the data link layer travels to local MAC addresses, a data packet at the network
layer is routed from a source IP (Internet Protocol) address to a destination IP address.
Think of a data packet as an envelope. IP addresses are assigned to every computer or device connected
to the Internet, and these addresses are formatted into four numbers each ranging from 0 to 255.
Example:
[Link]
At this layer, there are routing protocols designed to help packets (aka, our envelopes) get from point A
to point B as quickly as possible over the Internet. Your nearest router is one of the many routers
connected to the Internet that help packets find where they need to go!
Layer 4 – Transport
The Transport layer refers to how data is actually transferred. Let’s say you wanted to upload a photo
from your phone onto social media. The transport layer handles how the image data from that photo is
split (segmentation), the rate at which the packets are sent, and how errors are handled if data packets
don’t make it to the site’s server.
The most common transport protocols on the Internet are TCP (Transmission Control Protocol) and UDP
(User Datagram Protocol). We’ll go into these two protocols later in this lesson! error control!
OSI Layers 5, 6, 7
Layer 5 – Session
When two computers or devices have started an exchange of information, we call that a session. The
Session layer in OSI is responsible for opening, closing, and maintaining sessions.
In terms of opening and closing, the session layer includes authentication and authorization measures.
For example, without logging in or having the right permissions, you may not be able to connect to parts
of a website. But if you are logged in, your access permission is stored for a set amount of time, or
session length.
Layer 6 – Presentation
The Presentation layer includes all the methods that convert data into a format usable by an application.
This layer handles functions such as encoding/decoding, encryption/decryption, and
compression/decompression of files.
Layer 7 – Application
The final layer of the OSI model is the Application layer. This layer includes websites, browsers, email,
mobile applications, and how they render Internet data so that we can interact with it.
Right now, you are witnessing the application layer in action as you see Codecademy content
successfully rendered on your browser!
The OSI Model isn’t the only model that describes networking.
You will hear more often about the TCP/IP model, which is a 4-layered model that makes direct
reference to current Internet implementations. Its foundational protocols are TCP and IP.
Application Layer
This includes the opening and closing of sessions, translating data, and the interaction with content at
the application level. Here, there are multiple protocols for web content, email, and accessing files,
including HTTP, FTP, SMTP, and more.
Transport Layer
TCP is a connection-oriented protocol, where a more rigorous acknowledgment between one sender
and one receiver must happen before any data can be sent. This protocol also includes flow control and
error recovery, and it is used when larger amounts of data need to be sent and timing is less of a
concern.
UDP is a more lightweight protocol that does not require a fixed channel between a sender and receiver.
It is often used when the amount of data sent is piecemeal and needs to be transmitted quickly.
Sometimes called the Link layer, this layer encompasses the sending or receiving of network data at the
local network level.
Take a look at the diagram, and you’ll see how the TCP/IP model covers the responsibilities outlined in
each OSI layer.
What are network protocols? They are simply a set of standards for devices interacting on the Internet!
It’s important to understand these protocols from the angle of network security. Threat actors often
abuse the rules of a protocol to gain access to sensitive information.
In this exercise, we’ll talk about a few protocols within the TCP/IP implementation Application layer.
DNS
The Domain Name System (DNS) protocol converts domain names to IP addresses. Think of it as a
phonebook for the Internet. It’s hard to remember an exact IP address when we want to access a
website. When we request the URL [Link], our computer sends a DNS request to a DNS
server. The server then returns the correct IP addresses to route data to and from Codecademy.
HTTP
The HTTP (The Hyper Text Transfer Protocol) handles our web requests to servers. HTTP uses a set of
verbs, like GET, POST, PUT, and HEAD, to retrieve and send data. Anytime a page is loaded, there are
multiple web requests to retrieve content like images, text, and formatting code.
How does email work? IMAP (Internet Message Access Protocol) and POP (Post Office Protocol) allow
users to access emails stored on a remote web server. In IMAP, servers store your email and return
copies to you, allowing you to access the same email on multiple devices. In POP3 (POP version 3),
however, emails are generally downloaded from the server onto just a single device.
How do data packets get routed to these services from the transport layer? Specific numbers called
ports are reserved so that packets for different services can come in at the same time. Think of ports as
lanes for network traffic!
Instructions
Let’s see some HTTP requests in real-time! Open up your browser’s “Inspection”/“Developer” tools. You
can generally search for it in your browser’s “Settings” or in the “Tools” menu. Once you’re there, go to
the “Network” tab.
Refresh this page to see all the HTTP requests that are required to load this lesson!
Concept Review
Want to quickly review some of the concepts you’ve been learning? Take a look at this material's
cheatsheet!
Community Forums
Still have questions? View this exercise's thread in the Codecademy Forums.
OSI Model
The OSI Model is a conceptual, implementation-neutral model that describes networking in seven
separate layers, where each layer covers a set of functions and tasks.
TCP/IP Model
The TCP/IP Model is an implementation-specific networking model that revolves around the TCP
protocol and IP addressing which anchor the Internet as we know it.
OSI Layers
The OSI layers include: Physical, Data Link, Network, Transport, Session, Presentation, and Application.
The Data Link layer includes data framing and local MAC addressing
The Network layer includes connecting to the larger web and IP addressing
The Transport layer includes protocols that make sure reliable delivery happens
The Session layer authenticates and maintains communication over a period of time
The Presentation layer en/decrypts and translates data into presentable form
The Application layer includes all the applications we interact with that render data
Network Categories
Local Area Network (LAN), a smaller-sized network that connects multiple devices in a small area
Campus Area Network (CAN), a larger network that connects multiple computers and devices over a
slightly larger area
Wide Area Network (WAN), the largest-sized network that connects multiple computers, over a
geographically large area
Network
A network is two or more computers or devices that are linked in order to share information.
Networking refers to a large set of standards and protocols that organize and regulate the sharing of
information.
Network Protocols
A network protocol is a set of standards for Internet traffic.
SSH
FTP
Network Segmentation
Network Segmentation is the practice of breaking larger networks into smaller, functionally similar
networks. This improves both security and performance.
Access Points
Access points are the systems and nodes used to distribute wireless signals.
If an attacker can physically hack an access point, they may be able to attack the users on the network!
This is why you should be careful which access points you connect your devices to.
All wireless activity should be securely encrypted. Currently, the accepted standard for security is WPA2.
Attackers can use credential stuffing to test username/password combinations. Attackers will use
information from one hacked site to infiltrate accounts on other sites.
To protect yourself you should never:
Reuse passwords
Using Multi-Factor Authentication (MFA) can make your accounts even more secure, even if your
password is compromised.
Virtual Private Networks (VPNs) keep you safe by providing both network security and anonymity.
They can protect against attacks like Man-in-the-Middle attacks because of their ability to encrypt web
traffic.
Software Updates
Keeping your knowledge and your software up to date will protect you against many cyberattacks.
Software updates often include updates that can protect against recently discovered threats.
Security
Usability
You should base your decisions on the risks associated with the asset being hardened.
Malicious actors might suggest fake security tips in order to gain access to your machine
The protocols in the last exercise are all involved in everyday Internet activity. Below are some other
Application-layer protocols that are more commonly used by IT professionals.
SSH
Secure Shell (SSH) is used to access a remote terminal or virtual machine (VM) over a secure connection.
IT professionals and engineers use this to help configure and program a system remotely and securely.
For example, accessing Github from the command line uses SSH!
FTP
The File Transfer Protocol (FTP) is used to transfer files from one system to another. Modern
implementations of FTP can include encryption as well.
SMB
The Server Message Block (SMB) protocol allows multiple users to interact with a remote system like a
file share or printing services. Multiple people can view and modify shared resources and files in a
centralized server.
Again, these are some of the protocols that are most often used and configured by IT professionals. They
are central to the behind-the-scenes work of maintaining the web.
Review
Networks, and the technology behind networking, help us connect to the world around us. Through
following multiple protocols, we’re able to use physical technologies to exchange a massive amount of
information every single day.
To review, we’ve:
Discussed the difference between Local Area Networks (LAN), Campus Area Networks (CAN), and Wide
Area Networks (WAN)
Physical Layer
Networking Layer
Transport Layer
Session Layer
Presentation Layer
Application Layer
Introduced the TCP/IP model, also known as the Internet protocol suite that revolves around TCP and IP
Learned about essential protocols like DNS, HTTP, and email protocols
Learned about SSH, SMB, and FTP protocols that are important for accessing specific resources securely
While networking technology has helped connect people all throughout the world, it has also created
new risks. Only by understanding network architecture more and more can we make educated decisions
on network security!