0% found this document useful (0 votes)
3 views28 pages

Unit 3 Notes

Uploaded by

jainathak7
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views28 pages

Unit 3 Notes

Uploaded by

jainathak7
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Tools & Methods Used in Cybercrime

UNIT-III (NOTES)
Proxy Server
A proxy server acts as a gateway between your device and the internet, masking your IP address
and enhancing online privacy. But what exactly does it do, and why is it critical for businesses,
developers, and everyday users? In this guide, we’ll break down proxy servers in simple terms
exploring how they work, their key benefits (like bypassing geo-blocks and securing sensitive
data), and the different types (residential, data Center, and mobile proxies).

For example, Smartproxy has been offering unique solutions for online anonymity and web
data collection since 2018. It has a 55M+ residential proxy pool that opens horizons for block-
free web scraping and geo-targeting. They provide access to 195+ locations worldwide,
including city-level and 50 US states targeting.

The proxy server also prevents the identification of the client’s IP address when the client
makes any request to any other servers. In this guide, well explain proxy servers, explore their
benefits (and limitations), and reveal how they power everything from anonymous browsing to
global market research.

• Internet Client and Internet resources: For Internet clients, Proxy servers also act as
a shield for an internal network against the request coming from a client to access the
data stored on the server. It makes the original IP address of the node remain hidden
while accessing data from that server.

• Protects true host identity: In this method, outgoing traffic appears to come from the
proxy server rather than internet navigation. It must be configured to a specific
application such as HTTP or FTP. For example, organizations can use a proxy to
observe the traffic of their employees to get the work efficiently done. It can also be
used to keep a check on any kind of highly confidential data leakage. Some can also
use it to increase their website rank.
Need of Proxy Server

The need for a proxy server can vary depending on the specific use case, organization, or
individual requirements. Here are some common reasons and needs for proxy server:

• Enhanced Privacy & Anonymity: Proxy servers act as an intermediary, masking the
user’s original IP address and providing a level of anonymity while browsing the
internet.
• Bypassing Internet Restrictions: In regions where certain websites or services are
blocked, a proxy server allows users to bypass these restrictions and access blocked
content.
Types of Proxy Server

Explore the different types of proxy servers—residential, data center, mobile, and more. Learn
how each works, and ideal use cases for privacy, security, and data tasks.

1. Reverse Proxy Server

A reverse proxy does the opposite of forward proxy. A forward proxy acts on behalf of clients
(or requesting hosts). Forward proxies can hide the identities of clients whereas reverse proxies
can hide the identities of servers. The job of a reverse proxy server to listen to the request made
by the client and redirect to the particular web server which is present on different servers.
Reverse proxies have several use cases, a few are:
• Load balancing: distribute the load to several web servers.

• Cache static content: offload the web servers by caching static content like pictures,
HTML pages.
• Compression: compress and optimize content to speed up load time.
2. Web Proxy Server

Web Proxy forwards the HTTP requests, only URL is passed instead of a path. The request is
sent to particular the proxy server responds. Examples, Apache, HAP Proxy.

3. Anonymous Proxy Server

This type of proxy server does not make an original IP address instead these servers are
detectable still provides rational anonymity to the client device.

4. Highly Anonymity Proxy

This proxy server does not allow the original IP address and it as a proxy server to be detected.

5. Transparent Proxy

This type of proxy server is unable to provide any anonymity to the client, instead, the original
IP address can be easily detected using this proxy. But it is put into use to act as a cache for the
websites. A transparent proxy when combined with gateway results in a proxy server where the
connection requests are sent by the client , then IP are redirected. Redirection will occurs
without the client IP address configuration. HTTP headers present on the server-side can easily
detect its redirection .

6. CGI Proxy
CGI proxy server developed to make the websites more accessible. It accepts the requests to
target URLs using a web form and after processing its result will be returned to the web
browser. It is less popular due to some privacy policies like VPNs but it still receives a lot of
requests also. Its usage got reduced due to excessive traffic that can be caused to the website
after passing the local filtration and thus leads to damage to the organization.
7. Suffix Proxy
Suffix proxy server basically appends the name of the proxy to the URL. This type of proxy
doesn’t preserve any higher level of anonymity. It is used for bypassing the web filters. It is
easy to use and can be easily implemented but is used less due to the more number of web filter
present in it.
8. Distorting Proxy

Proxy servers are preferred to generate an incorrect original IP address of clients once being
detected as a proxy server. To maintain the confidentiality of the Client IP address HTTP
headers are used.

9. Tor Onion Proxy


This server aims at online anonymity to the user's personal information. It is used to route the
traffic through various networks present worldwide to arise difficulty in tracking the users’
address and prevent the attack of any anonymous activities. It makes it difficult for any person
who is trying to track the original address. In this type of routing, the information is encrypted
in a multi-folds layer. At the destination, each layer is decrypted one by one to prevent the
information to scramble and receive original content. This software is open-source and free of
cost to use.
10. 12P Anonymous Proxy

It uses encryption to hide all the communications at various levels. This encrypted data is then
relayed through various network routers present at different locations and thus I2P is a fully
distributed proxy. This software is free of cost and open source to use, It also resists the
censorship.

11. DNS Proxy

DNS proxy take requests in the form of DNS queries and forward them to the Domain server
where it can also be cached, moreover flow of request can also be redirected.

12. Rotating Proxy

A rotating proxy assign a new or different IP address to each user that connects to proxy. As
users connect, the unique address is assign to it.

How Does the Proxy Server Operates?

Every computer has its unique IP address which it uses to communicate with another node.
Similarly, the proxy server has its IP address that your computer knows. When a web request
is sent, your request goes to the proxy server first. The Proxy sends a request on your behalf to
the internet and then collect the data and make it available to you. A proxy can change your IP
address So, the webserver will be unable to fetch your location in the world. It protects data
from getting hacked too. Moreover, it can block some web pages also.
What is the reason of using Proxy Server?

There are some reasons why everyone should proxy server because it provide following
advantages including privacy, web scraping, fast speed, saves bandwidth etc.

Advantages of Proxy Server

Proxy server has multiple benefits like

• Security: Proxy Server provides security between internet and system. They help your
system from unauthorized user to access your network

• Saves Bandwidth: A proxy server can save bandwidth, especially in those


environments where the same resources are accessed by multiple users.

• Performance: Proxy server improves performance, when a person requests for a


resource, then the proxy can serve it from its cache rather than fetching it from the
original server this helps to increase performance.

• Filteration: Proxy servers are used to filter content based on keywords or file types.

• Access Control: There are some content which is restricted in various countries, so
proxy server helps to control geographical access.
Disadvantages of Proxy Server

• Proxy Server Risks: Free installation does not invest much in backend hardware or
encryption. It will result in performance issues and potential data security issues. If you
install a "free" proxy server, treat very carefully, some of those might steal your credit
card numbers.

• Browsing history log: The proxy server stores your original IP address and web request
information is possibly unencrypted form and saved locally. Always check if your proxy
server logs and saves that data – and what kind of retention or law enforcement
cooperation policies they follow while saving data.

• No encryption: No encryption means you are sending your requests as plain text.
Anyone will be able to pull usernames and passwords and account information easily.
Keep a check that proxy provides full encryption whenever you use it.

Anonymizers
An anonymizer, also known as an anonymous proxy, is a tool that hides your IP address and
other identifying information when accessing the internet. This allows you to browse the web
without directly revealing your location or identity to the websites you visit.

An anonymizer refers to a proxy server designed to minimise the data a user discloses while
browsing the internet.

How an anonymizer operates?


1. IP Address Masking: Anonymizers act as an intermediary between the user’s device
and the internet. When a user sends a request to access a website or online resource, the
request is sent through the anonymiser, which substitutes the user’s IP address with its
own. This prevents the target website from identifying the user’s actual IP address.
2. Encryption of Traffic: Anonymisers often encrypt the user’s internet traffic,
providing an additional layer of security. This encryption helps protect the user’s data
from being intercepted or monitored by third parties.
3. Anonymity Layer: An anonymiser adds a layer of anonymity by obscuring the user’s
original IP address and other identifying information associated with the request.
4. Access to Blocked Content: Anonymisers allow users to bypass internet
restrictions and access blocked websites or services, particularly in regions where
certain content is restricted or censored.
5. Privacy Enhancement: By hiding the user’s IP address and encryption their traffic,
anonymisers significantly enhance privacy and make it difficult for websites, ISP’s, or
other entities to track and trace their online activities.
6. Secure Connection: Anonymisers ensure that the user’s internet connection is secure
and private, making it safer to browse the web, especially on public or unsecured
networks.

Uses of Anonymiser
1. Privacy and Security:
• Preventing Tracking:
Anonymizers hide a user's IP address, making it difficult for websites and third-party
trackers to follow their online activity.
• Protecting Personal Information:

By masking online activity, anonymizers can help prevent the collection and misuse of
personal information, such as search history or browsing patterns.
• Minimizing Risk of Identity Theft:

Anonymizers can reduce the risk of identity theft by making it harder for malicious actors
to link online activity to a user's identity.

2. Bypassing Geographic Restrictions:

• Accessing Region-Locked Content:

Anonymizers can help users access websites and content that are blocked or restricted in
their region.

• Circumventing Censorship:

In some countries, anonymizers can be used to bypass internet censorship and access
otherwise restricted websites and information.

3. Targeted Advertising and Personalization:

• Avoiding Targeted Advertising:

Anonymizers can make it harder for websites to track a user's browsing history and show
them personalized ads based on their location or preferences.

• Accessing Objective Information:

By avoiding targeted advertising and personalization, anonymizers can help users access a
more objective view of information.

4. Other Uses:

• Bypassing Security Controls:


Anonymizers can be used to bypass security controls in certain environments, such as
corporate networks or schools.
• Testing Websites:

Anonymizers can be used to test websites in different regions or with different IP


addresses.

• Enhanced Security:

Anonymizers can help protect against certain types of cyber threats, such as hacking and
phishing, by making it harder for attackers to identify and target users.

Types of Anonymizers:
They can be broadly categorized into two main types: networked anonymizers and single-
point anonymizers.

Networked Anonymizers: These involve routing your internet traffic through a network of
servers, making it difficult to trace your origin back to your device. Examples include:

• Tor (The Onion Router):

A free and open-source software that encrypts your internet traffic and routes it through a
distributed network of volunteer-operated servers, making it very difficult to track your
activities.

• VPNs (Virtual Private Networks):

Create an encrypted tunnel between your device and a VPN server, masking your IP address
and location.

Single-Point Anonymizers: These involve using a proxy server, which acts as an


intermediary between your device and the internet. They can be further categorized as:

• Proxies:

These are servers that act as a middleman between your device and the internet, masking
your IP address and potentially hiding your origin from websites.

• Public Proxies:

These are freely available proxy servers that can be used by anyone.

• Residential Proxies:

These are proxy servers that appear to be originating from a home IP address, which can
be more difficult to identify as proxies.

• Tor Exit Nodes:

These are specific computers within the Tor network that act as the final point of exit for
anonymized traffic, and they can be vulnerable.
PHISHING:
Phishing is a type of social engineering where attackers attempt to trick individuals into
revealing sensitive information like passwords, credit card details, or personal
information. This is typically done through fraudulent emails or messages that appear to
come from legitimate sources.

Types of Phishing:
Email phishing

In an email phishing scam, the attacker sends an email that looks legitimate, designed to
trick the recipient into entering information in reply or on a site that the hacker can use to
steal or sell their data.

Example of email phishing

Hackers used LinkedIn to grab contact information from employees at Sony and targeted
them with an email phishing campaign. They got away with over 100 terabytes of data.

Spear phishing

Spear phishing involves targeting a specific individual in an organization to try to steal


their login credentials. The attacker often first gathers information about the person before
starting the attack, such as their name, position, and contact details.

Example of spear phishing

An attacker tried to target an employee of NTL World, which is a part of the Virgin Media
company, using spear phishing. The attacker claimed that the victim needed to sign a new
employee handbook. This was designed to lure them into clicking a link where they would
have been asked to submit private information.
Whaling

A whaling attack is a phishing attack that targets a senior executive. These individuals
often have deep access to sensitive areas of the network, so a successful attack can result
in access to valuable info.

Example of whaling
A founder of Levitas, an Australian hedge fund was the target of a whaling attack that led
the individual to a fake connection using a fraudulent Zoom link. After following the link,
they had malware installed on their system, and the company lost $800.000.

Smishing

Smishing is phishing through some form of a text message or SMS.


Example of smishing
Hackers pretended to be from American Express and sent text messages to their victims
telling them they needed to tend to their accounts. The message said it was urgent, and if
the victim clicked, they would be taken to a fake site where they would enter their personal
information.
Vishing

Vishing, which is short for "voice phishing," is when someone uses the phone to try to steal
information. The attacker may pretend to be a trusted friend or relative or to represent them.
Example of vishing

In 2019, there was a vishing campaign that targeted members of the UK’s parliament and
their staffers. The attack was part of an assault that involved at least 21 million spam emails
targeting UK lawmakers.

Clone phishing
A clone phishing attack involves a hacker making an identical copy of a message the
recipient already received. They may include something like “resending this” and put a
malicious link in the email.

Example of clone phishing


In a recent attack, a hacker copied the information from a previous email and used the same
name as a legitimate contact that had messaged the victim about a deal. The
hacker pretended to be a CEO named Giles Garcia and referenced the email Mr. Garcia
had previously sent. The hacker then proceeded to pretend to carry on the previous
conversation with the target, as if they really were Giles Garcia.

Impact of Phishing:
• Financial Loss:

Phishing scams can lead to unauthorized transactions, identity theft, and financial
exploitation says the OCC.

• Identity Theft:

Phishers can steal sensitive information like Social Security numbers and bank details,
leading to identity theft and its consequences.

• Malware Infections:

Phishing emails may contain malicious links or attachments that install malware, including
ransomware, on the victim's device states UT Southwestern Medical Center.

• Data Loss:

Compromised accounts and systems can lead to the loss of personal data, including photos,
documents, and financial records mentions Proofpoint.
PASSWORD CRACKING

Password cracking is the process of using an application program to identify an unknown


or forgotten password that allows access to a computer or network resource. It can help
users to recover forgotten passwords and enterprise admins to check if weak passwords are
being used in their organizations. Threat actors also attempt to crack passwords to obtain
unauthorized access to resources and, sometimes, to compromise the accounts of authorized
users.

A password cracker recovers passwords using various techniques. The process can involve
comparing a list of words to guess passwords or the use of an algorithm to repeatedly guess
the password.

Types of Password Attacks:


1. Non-Electronic Attacks: Non-electronic attacks are the go-to method for
hackers seeking to obtain a target system’s password. These attacks don’t
require technical hacking skills but instead rely on social engineering or non-
technical methods like dumpster diving or shoulder surfing
2. Active Online Attacks: Active online attacks involve gaining unauthorized
administrator-level access to mainframe. Attackers attempt to crack passwords
by interacting with the target machines, often using techniques like dictionary
attacks, brute-forcing, password guessing, or phishing.
3. Password online Attacks: Passive online attacks are deliberate and don’t alter
the system in any way. Attackers monitor or record information passing through
communication channels to and from the mainframe. This acquired data is then
used to infiltrate the system. Techniques include replay attacks, wire-sniffing,
and man-in-the- middle attacks.
4. Offline Attacks: Offline attacks involve attempts to recover plaintext
passwords from a password hash dump. While these hacks can be time-
consuming, they can also be effective. Attackers use pre-processed hashes from
rainbow tables to conduct offline and distributed network hacks.

KEYLOGGER
A keylogger or keystroke logger/keyboard capturing is a form of malware or hardware that
keeps track of and records your keystrokes as you type. It takes the information and sends it to
a hacker using a command-and-control (C&C) server. The hacker then analyzes the
keystrokes to locate usernames and passwords and uses them to hack into otherwise secure
systems.

Types Of Keyloggers

A software keylogger is a form of malware that infects your device and, if programmed to do
so, can spread to other devices the computer comes in contact with. While a hardware
keylogger cannot spread from one device to another, like a software keylogger, it transmits
information to the hacker or hacking organization, which they will then use to compromise
your computer, network, or anything else that requires authentication to access.

1. Software keyloggers

Software keyloggers consist of applications that have to be installed on a computer to steal


keystroke data. They are the most common method hackers use to access a user’s keystrokes.

A software keylogger is put on a computer when the user downloads an infected application.
Once installed, the keylogger monitors the keystrokes on the operating system you are using,
checking the paths each keystroke goes through. In this way, a software keylogger can keep
track of your keystrokes and record each one.
After the keystrokes have been recorded, they are then automatically transferred to the hacker
that set up the keylogger. This is done using a remote server that both the keylogger software
and the hacker are connected to. The hacker retrieves the data gathered by the keylogger and
then uses it to figure out the unsuspecting user’s passwords.

The passwords stolen using the key logger may include email accounts, bank or investment
accounts, or those that the target uses to access websites where their personal information can
be seen. Therefore, the hacker's end goal may not be to get into the account for which the
password is used. Rather, gaining access to one or more accounts may pave the way for the
theft of other data.

2. Hardware keyloggers
A hardware keylogger works much like its software counterpart. The biggest difference is
hardware keyloggers have to be physically connected to the target computer to record the user's
keystrokes. For this reason, it is important for an organization to carefully monitor who has
access to the network and the devices connected to it.
If an unauthorized individual is allowed to use a device on the network, they could install a
hardware keylogger that may run undetected until it has already collected sensitive information.
After hardware keystroke loggers have finished keylogging, they store the data, which the
hacker has to download from the device.

The downloading has to be performed only after the keylogger has finished logging keystrokes.
This is because it is not possible for the hacker to get the data while the key logger is working.
In some cases, the hacker may make the keylogging device accessible via Wi-Fi. This way,
they do not have to physically walk up to the hacked computer to get the device and retrieve
the data.

SPYWARE
Spyware is a type of malicious software (malware) that is installed on a computing device
without the user's knowledge or consent. It gathers information about the user's activity,
including their online behavior, browsing habits, and even personal information, and then
transmits this data to third parties without their permission. This data can be used for various
malicious purposes, including data theft, advertising targeting, or even financial fraud.

Spyware is one of the most commonly used cyberattack methods that can be difficult for users
and businesses to identify and can do serious harm to networks. It also leaves businesses
vulnerable to data breaches and data misuse, often affects device and network performance,
and slows down user activity.

The term "spyware" first emerged in online discussions in the 1990s, but only in the early 2000s
did cybersecurity firms use it to describe unwanted software that spied on their user and
computer activity. The first anti-spyware software was released in June 2000, then four years
later, scans showed that around 80% of internet users had their systems affected by spyware,
according to research by America Online and the National Cyber Security Alliance.
However, 89% of users were unaware of the spyware’s existence and 95% had not granted
permission for it to be installed.

Types of spyware
1. Adware: This sits on a device and monitors users’ activity then sells their data to
advertisers and malicious actors or serves up malicious ads.
2. Infostealer: This is a type of spyware that collects information from devices. It scans
them for specific data and instant messaging conversations.

3. Keyloggers: Also known as keystroke loggers, keyloggers are a type of infostealer


spyware. They record the keystrokes that a user makes on their infected device, then
save the data into an encrypted log file. This spyware method collects all of the
information that the user types into their devices, such as email data, passwords, text
messages, and usernames.

4. Rootkits: These enable attackers to deeply infiltrate devices by exploiting security


vulnerabilities or logging into machines as an administrator. Rootkits are often difficult
and even impossible to detect.
5. Red Shell: This spyware installs itself onto a device while a user is installing specific
PC games, then tracks their online activity. It is generally used by developers to enhance
their games and improve their marketing campaigns.

6. System monitors: These also track user activity on their computer, capturing
information like emails sent, social media and other sites visited, and keystrokes.

7. Tracking cookies: Tracking cookies are dropped onto a device by a website and then
used to follow the user’s online activity.

8. Trojan Horse Virus: This brand of spyware enters a device through Trojan malware,
which is responsible for delivering the spyware program.
VIRUS
A computer virus is a malicious software program (malware) that replicates itself by modifying
other programs and inserting its code. It's designed to infect, replicate, and damage computer
systems. Unlike a biological virus, a computer virus needs a host to attach itself to and spread,
often through infected files or programs.

Types of Computer Virus


[Link] Virus: Attaches to the end of a file and modifies how a program starts to run the virus's
code first.

2. Boot Sector Virus: Attacks the part of the computer that starts up when you turn it on. Boot
Sector Virus can also spread through devices like floppy disks. Often called a memory virus.

3. Macro Virus: Activates by running a program capable of executing macros, often found in
documents like spreadsheets.

4. Email Virus: Hides in email messages and activates by clicking a link, opening an
attachment, or interacting with the email.

5. Polymorphic Virus: Changes its form every time it installs to avoid detection by antivirus
software.

6. Multipartite Virus: Infects the computer’s boot sector, memory, and files, making it
difficult to detect and remove.

7. Encrypted Virus: Uses encryption to hide from antivirus software, includes a decryption
algorithm to run before executing.
8. Stealth Virus: Modifies detection code, making it very difficult to detect.

9. Resident Virus: Saves itself in the computer's memory and can infect other files even after
the original program stops.

10. Direct Action Virus: Tied to an executable file, it activates when the file is opened but
does not delete files or affect system speed; blocks file access.
11. Browser Hijacker Virus: Changes browser settings without permission, can redirect to
malicious sites.

How To Prevent Your Computer from Viruses?


Keeping your computer safe from viruses is a lot like keeping yourself from catching a cold.
Just as you might wash your hands regularly or avoid sick friends, there are simple steps you
can take to protect your computer. Here are some easy tips:

1. Install Antivirus Software: Think of antivirus software as your computer's doctor. It works
around the clock to detect and block viruses before they can infect your system. Make sure to
keep it updated!
2. Update Regularly: Keep your operating system, software, and apps up to date. Updates
often include fixes for security vulnerabilities that viruses could exploit.

3. Be Cautious with Emails and Downloads: Don't open emails or download attachments
from unknown sources. If an email looks suspicious, even if you know the sender, it's best to
delete it.

4. Use Strong Passwords: Protect your accounts with strong, unique passwords. Consider
using a password manager to keep track of them all.
5. Backup Your Data: Regularly back up your data to an external drive or cloud storage. If
a virus does slip through, you won't lose everything.
By following these steps, you can help keep your computer virus-free and running smoothly.

WORM:
A worm is a type of malicious software (malware) that replicates itself and spreads across
networks without requiring any user interaction. Unlike a virus, which needs a host file to infect
a system, a worm can self-propagate and infect multiple computers independently. Worms
often exploit network vulnerabilities and can cause significant damage by consuming
bandwidth, disrupting services, and potentially stealing data.

Key Characteristics of Worms:


• Self-replication:

Worms can copy themselves to other computers within a network without needing user
interaction.

• Standalone:
They don't need a host program to operate, unlike viruses, which need a file or application to
infect a system.

• Network-based:

Worms spread through network connections, like email, instant messaging, or shared network
drives.

• Exploit vulnerabilities:

They often target security weaknesses in software or operating systems to gain access and
spread.

• Resource consumption:

Worms can consume significant network bandwidth, leading to slowdowns, system crashes,
and even denial-of-service attacks.
• Potential for harm:
They can cause data loss, system damage, and even theft of sensitive information.

How Worms Spread:

• Phishing emails: Worms can be attached to emails that look legitimate, tricking users
into opening them.

• Infected websites: Visiting compromised websites can lead to worm downloads.

• Network-connected devices: Sharing files or devices (like USB drives) can spread
worms.

• Instant messaging: Worms can spread through instant messaging platforms.

• File-sharing networks: Worms can be found in peer-to-peer file-sharing networks.

Types of Worms:
• Email worms: Spread through emails, often with malicious attachments.

• Instant messaging worms: Spread through instant messaging networks.


• Network worms: Spread through network connections, using shared resources.

• Internet worms: Infect websites and spread to visitors who browse those sites.

• File-sharing worms: Spread through peer-to-peer file-sharing networks.

• Cryptoworms: Encrypt data on the victim's system, demanding ransom for its release.

Difference Between Worms and Viruses:


Aspects WORM VIRUS
Definition A Worm is a form of malware that A Virus is a malicious executable
replicates itself and can spread to code attached to another executable
different computers via a Network. file that can be harmless or can
modify or delete data.
Objective The main objective of worms is to The main objective of viruses is to
eat the system's resources. It modify the information.
consumes system resources such
as memory and bandwidth and
makes the system slow in speed to
such an extent that it stops
responding.
Host It doesn't need a host to replicate It requires a host is needed for
from one computer to another. spreading.
Harmful It is less harmful as compared. It is more harmful.
Detection and They can be detected and removed Antivirus software is used for
Protection by the Antivirus and firewall. protection against viruses.
Controlled by They can be controlled by remote. They can’t be controlled by remote.
Execution They are executed via weaknesses They are executed via executable
in the system. files.
Comes from Worms generally come from the They generally come from shared
downloaded files or through a or downloaded files.
network connection.
Symptoms 1. Hampering computer 1. Pop-up windows linking to
performance by slowing down it malicious websites
2. Automatic opening and running 2. Hampering computer
of programs performance by slowing down it
3. Sending of emails without your 3. After booting, starting of
knowledge unknown programs.

Examples Examples of worms include Examples of viruses include


Morris worm, storm worm, etc. Creeper, Blaster, Slammer, etc.
Interface It does not need human action to It needs human action to replicate.
replicate.
Speed Its spreading speed is faster. Its spreading speed is slower as
compared to worms.

TROJAN-HORSES
A Trojan horse is a type of malware that disguises itself as legitimate software to trick users
into installing it. Once installed, it can perform various malicious activities, such as data theft,
remote access, or system damage. Trojans don't self-replicate like viruses or worms; they rely
on user interaction for distribution.

Key Characteristics:

• Disguise: Trojans are designed to look like ordinary programs, files, or software.

• Delivery: They are often distributed through email attachments, fake software updates,
or by embedding themselves within legitimate software.

• Malicious Actions: Once installed, they can steal data, give attackers remote access, or
cause other harm to the system.

Examples of Trojan Types:

• Backdoor Trojans: Provide attackers with remote access to the infected system.
• Downloader Trojans: Install other malicious software on the device.

• Banking Trojans: Target online banking accounts to steal financial data.

• Remote Access Trojans (RATs): Give attackers full control of the victim's computer.

Prevention and Protection:

• Be cautious about email attachments and suspicious links: Avoid clicking on links
or opening attachments from unknown senders.
• Update your antivirus software regularly: Ensure you have a strong antivirus or
security suite with up-to-date definitions.
• Use strong passwords and enable two-factor authentication: Protect your accounts
from unauthorized access.

• Be aware of social engineering techniques: Recognize attempts to trick you into


downloading or installing malware.

BACKDOORS
A backdoor is a hidden entry point that bypasses a system's normal security measures, granting
unauthorized access. It's a way for malicious actors to gain access without triggering standard
security alerts, potentially leading to data theft, malware installation, and persistent control of
a system.

How they are created:

Backdoors can be unintentionally created by developers through software flaws, deliberately


left in for maintenance purposes, or installed by attackers to maintain access.

• Examples:
• Default passwords: Unchanged default credentials can act as backdoors,
allowing easy access for attackers.

• Vulnerable software: Exploiting flaws in software can enable attackers to


install backdoors.

• Web server vulnerabilities: Exploiting vulnerabilities like remote file


inclusion (RFI) can lead to backdoor installation.

Detection and Prevention:

• Security tools: Use security tools and strategies to detect and prevent backdoor
attacks.

• Patch management: Regularly update software and firmware to address


vulnerabilities that could be exploited.

• Security awareness: Train users to be aware of phishing attempts and other


tactics used to install malware.

• Network segmentation: Segment networks to isolate vulnerable systems and


limit the impact of breaches.

• Incident response: Have a plan in place to respond to and contain backdoor


attacks.

STEGNOGRAPHY
Steganography, the art of concealing data within seemingly ordinary media, plays a significant
role in cybersecurity, particularly in both legitimate security practices and malicious
cyberattacks. It's used to hide secret messages, data, or even malware within images, audio,
video, or text files, making them difficult to detect by unauthorized parties.

• Legitimate Uses:

Cybersecurity professionals employ steganography for secure communication, data masking,


and digital watermarking. It can be used to embed secret messages or data in files to protect
sensitive information from unauthorized access.

• Cyberattack Applications:

Malware developers and cybercriminals use steganography to hide malicious code within
seemingly harmless files, such as images or audio, to evade detection by antivirus
software. This "stegomalware" can be used in various attacks, including data exfiltration and
ransomware.
• Data Exfiltration:

Steganography can also be used in the data exfiltration stage of a cyberattack, allowing
malicious actors to extract stolen data from a compromised system without being detected.

• Stealth and Evasion:

By concealing data within ordinary files, steganography enables threat actors to bypass security
measures and maintain a low profile.

Examples of Steganography Techniques:

• LSB (Least Significant Bit) Steganography:

This technique involves modifying the least significant bit of each pixel or data unit to embed
the secret message.

• Other Media Types:


Steganography can be applied to various media types, including images, audio, video, and even
text files.

Steganography in cybersecurity involves both legitimate uses for security professionals and
malicious applications by cybercriminals. It's a powerful tool for concealing data, and
understanding its techniques and applications is crucial for cybersecurity professionals to
effectively detect and prevent attacks.

Difference between Steganography and Cryptography


Steganography and cryptography are critical components of network security. Network security
has emerged as an essential part of today's communication infrastructure. There was an urgent
need for network security to protect confidentiality and data integrity. It protects the user
against unauthorized access. Steganography hides communication traces, while cryptography
uses encryption to make the message unreadable.

Aspect Steganography Cryptography


Definition Steganography means cov Cryptography means secret writing.
ered writing.
Popularity Steganography is less While cryptography is more popular
popular than Cryptography. than Steganography.
Attack Name The attack's name in In cryptography, the Attack's name
Steganography is is Cryptanalysis.
Steganalysis.
Data In steganography, the While in cryptography, the structure of
Alteration structure of data is not data is altered.
usually altered.
Security Steganography Cryptography
Principles supports Confidentiality a supports Confidentiality and Authent
nd Authentication securit ication security principles as well
y principles.
as Data integrity and Non-
repudiation.

Visibility In steganography, the fact While in cryptography only a secret


that a secret message is hidden.
communication is taking
place is hidden.
Mathematical In steganography, not many Cryptography involves the use of
Involvement mathematical number theory, mathematics, etc. to
transformations are modify data
involved.
Information In Steganography the In cryptography, the information is
Handling information is hidden. transformed.
Information The hidden information is Transformed information is visible.
Visibility not visible.
Security Steganography Provides Cryptography Provides
Services Confidentiality only. Confidentiality, Integrity, Non-
repudiation.
Algorithms Steganography doesn't Cryptography has Various recognized
have specific algorithms. and approved algorithms.
Goal The goal of steganography The main goal of cryptography is to
is to make the information keep the contents of the message secret
invisible to anyone who from unauthorized access.
doesn't know where to look
or what to look for

Denial of Service (DoS)


A Denial of Service (DoS) attack in cybersecurity is a type of cyberattack where an attacker
aims to disrupt normal service by overwhelming a system or network with excessive traffic or
requests, rendering it unavailable to legitimate users.

Key characteristics of DoS attacks:


• Disrupting service:

DoS attacks aim to prevent users from accessing online services, websites, email, or other
resources.

• Overwhelming the target:

Attackers flood the target with traffic, often using fake requests, to overload the system's
resources.

• No direct access:

Unlike some attacks that aim to steal data, DoS attacks primarily focus on disrupting
functionality, not gaining access to the system.
• Various methods:

DoS attacks can be launched from a single attacker's computer or distributed across multiple
computers (Distributed Denial of Service - DDoS).

• Impact on users:

DoS attacks can cause significant disruption to individuals and businesses, impacting their
ability to access online services and conduct business.

Examples of DoS attacks:

• Flooding a website with traffic:

An attacker could send a large number of requests to a website, making it unavailable to


legitimate users.

• Overloading a network with fake requests:

An attacker can flood a network with excessive traffic, causing it to become congested and
slow.

• Exploiting vulnerabilities:
Attackers may exploit vulnerabilities in a system's software or configuration to disrupt its
operation.

Distributed Denial-of-Service (DDoS)


Distributed Denial of Service (DDoS) is a type of DOS attack where multiple systems, which
are trojan infected, target a particular system which causes a DoS attack.

A DDoS attack uses multiple servers and Internet connections to flood the targeted resource. A
DDoS attack is one of the most powerful weapons on the cyber platform. When you come to
know about a website being brought down, it generally means it has become a victim of a DDoS
attack. This means that the hackers have attacked your website or PC by imposing heavy traffic.
Thus, crashing the website or computer due to overloading.
Example: In 2000, Michael Calce, a 15-year-old boy who used the online name “Mafiaboy”,
was behind one of the first DDoS attacks. He hacked into the computer networks of various
different universities. He used their servers to operate a DDoS attack that brought down several
websites such as eBay and Yahoo. In 2016, Dyn was hit with a massive DDoS attack that took
down major websites and services such as Netflix, PayPal, Amazon, and GitHub.

Difference between DoS and DDoS

DoS DDoS
DoS Stands for Denial-of-service attack. DDoS Stands for Distributed Denial of
service attack.
In Dos attack single system targets the victim In DDoS multiple systems attack the victim's
system. system.
Victim's PC is loaded from the packet of data Victim PC is loaded from the packet of data
sent from a single location. sent from Multiple locations.
Dos attack is slower as compared to DDoS. A DDoS attack is faster than Dos Attack.
Can be blocked easily as only one system is It is difficult to block this attack as multiple
used. devices are sending packets and attacking
from multiple locations.
In DOS Attack only a single device is used In a DDoS attack, the volumeBots are used
with DOS Attack tools. to attack at the same time.
DOS Attacks are Easy to trace. DDOS Attacks are Difficult to trace.
Types of DOS Attacks are: Types of DDOS Attacks are:
1. Buffer overflow attacks 1. Volumetric Attacks
2. Ping of Death or ICMP flood 2. Fragmentation Attacks
3. Teardrop Attack 3. Application Layer Attacks
4. Flooding Attack 4. Protocol Attack.

Types of DDoS Attacks


There are various types of DDoS attacks mentioned below:
1. Volumetric Attacks: Volumetric Attacks are the most prevalent form of DDoS attacks.
They use a botnet to overload the network or server with heavy traffic but exceed the
network’s capabilities of processing the traffic. This attack overloads the target with
huge amounts of junk data. This leads to the loss of network bandwidth and can lead to
a complete denial of service.

2. Protocol Attacks: TCP Connection Attacks exploit a vulnerability in the TCP


connection sequence which is commonly referred to as the three-way handshake
connection between the host and the server. The work is explained as follows. The
targeted server receives a request to start with the handshake. In this attack, the
handshake is never accomplished. This leaves the connected port as busy and
unavailable to process any further requests. Meanwhile, the cybercriminal continues to
send multiple requests overwhelming all the working ports and shutting down the
server.

3. Application Attacks: Application layer attacks (Layer 7 attacks) target the applications
of the victim in a slower fashion. Thus, they may initially appear as legitimate requests
from users and the victim becomes unable to respond. These attacks target the layer
where a server generates web pages and responds to HTTP requests. Application-level
attacks are combined with other kinds of DDoS attacks targeting applications, along
with the network and bandwidth. These attacks are threatening as it is more difficult for
companies to detect.

4. Fragmentation Attacks: The cybercriminal exploits frangibility in the datagram


fragmentation process, in which IP datagrams are divided into smaller packets,
transferred across a network, and then reassembled. In such attacks, fake data packets
are unable to be reassembled.

How do DDoS Attacks Work?

The logic of a DDoS attack is very simple, although attacks can be highly different from each
other. Network connections consist of various layers of the OSI model. Various types of DDoS
attacks focus on particular layers. Examples are illustrated below:

• Layer-3: Network layer - Attacks are known as Smurf Attacks, ICMP Floods, and
IP/ICMP Fragmentation.

• Layer-4: Transport layer - Attacks include SYN Floods, UDP Floods, and TCP
Connection Exhaustion.

• Layer-7: Application layer - HTTP-encrypted attacks.

How to Protect Yourself from DDoS Attacks?

1. Take quick action: Sooner the DDoS attack is identified, the quicker the harm can be
resisted. Companies should provide DDoS services or a certain kind of technology so
that the heavy traffic can be realized and worked upon as soon as possible.

2. Configure firewalls and routers: Firewalls and routers should be configured in such
a way that they reject bogus traffic and you should keep your routers as well as firewalls
updated with the latest security patches.
3. Consider artificial intelligence: While present defenses of advanced firewalls and
intrusion detection systems are very common, Artificial Intelligence is being used to
develop new systems.

4. Secure your Internet of Things devices: To keep your devices from becoming a part
of a botnet, it's smart to make sure your computers have trusted security software. It's
important to keep it updated with the latest security patches.

BUFFER OVERFLOW
A buffer is a temporary area for data storage. When more data (than was originally allocated
to be stored) gets placed by a program or system process, the extra data overflows. It causes
some of that data to leak out into other buffers, which can corrupt or overwrite whatever data
they were holding.
In a buffer-overflow attack, the extra data sometimes holds specific instructions for actions
intended by a hacker or malicious user; for example, the data could trigger a response that
damages files, changes data or unveils private information.
Attacker would use a buffer-overflow exploit to take advantage of a program that is waiting on
a user's input. There are two types of buffer overflows: stack-based and heap-based. Heap-
based, which are difficult to execute and the least common of the two, attack an application by
flooding the memory space reserved for a program. Stack-based buffer overflows, which are
more common among attackers, exploit applications and programs by using what is known as
a stack memory space used to store user input.

Buffer overflow consequences


Common consequences of a buffer overflow attack include the following:
1. System crashes: A buffer overflow attack will typically lead to the system crashing. It
may also result in a lack of availability and programs being put into an infinite loop.

2. Access control loss: A buffer overflow attack will often involve the use of arbitrary
code, which is often outside the scope of programs’ security policies.

3. Further security issues: When a buffer overflow attack results in arbitrary code
execution, the attacker may use it to exploit other vulnerabilities and subvert other
security services.

Types Of Buffer Overflow Attacks


There are several types of buffer overflow attacks that attackers use to exploit organizations’
systems. The most common are:

1. Stack-based buffer overflows: This is the most common form of buffer overflow
attack. The stack-based approach occurs when an attacker sends data containing
malicious code to an application, which stores the data in a stack buffer. This overwrites
the data on the stack, including its return pointer, which hands control of transfers to
the attacker.

2. Heap-based buffer overflows: A heap-based attack is more difficult to carry out than
the stack-based approach. It involves the attack flooding a program’s memory space
beyond the memory it uses for current runtime operations.

3. Format string attack: A format string exploit takes place when an application
processes input data as a command or does not validate input data effectively. This
enables the attacker to execute code, read data in the stack, or cause segmentation faults
in the application. This could trigger new actions that threaten the security and stability
of the system.

WIRELESS ATTACKS:
A wireless attack involves identifying & examining the connections between all devices
connected to the business’s wifi. These devices include laptops, tablets, smartphones, and any
other internet of Things (IoT) devices. This attack refers to the unauthorized exploitation of
vulnerabilities in wireless networks or devices to gain unauthorized access, intercept data, or
disrupt network communication.

Types of Wireless Attack:

1. Wireless Eavesdropping (Passive Attacks)


Attackers use tools like packet sniffers to intercept and monitor wireless communications
between devices. By capturing data packets transmitted over the air, they can potentially obtain
sensitive information, such as login credentials, financial data, or personal information.

2. Wireless Spoofing (Man-in-the-Middle Attacks)

In these attacks, the attacker positions themselves between the wireless client and the legitimate
access point, intercepting and manipulating data transmissions. The attacker may then relay the
information back and forth, making it appear as if they are the legitimate access point. This
enables them to snoop on data or perform other malicious actions unnoticed.

3. Wireless Jamming (Denial-of-Service Attacks)


Attackers flood the wireless frequency spectrum with interference signals, disrupting
legitimate communications between devices and access points. By creating excessive noise,
they can render the wireless network unusable for legitimate users.

4. Rogue Access Points

Attackers set up unauthorized access points, mimicking legitimate ones, to deceive users into
connecting to them. Once connected, the attacker can eavesdrop, capture data, or launch further
attacks on the unsuspecting users.

5. Brute-Force Attacks
Attackers try various combinations of passwords or encryption keys in rapid succession until
they find the correct one to gain unauthorized access to the wireless network.

6. WEP/WPA Cracking

Attackers exploit vulnerabilities in older wireless security protocols like Wired Equivalent
Privacy (WEP) and Wi-Fi Protected Access (WPA) to gain unauthorized access to encrypted
wireless networks.

7. Evil Twin Attacks

Attackers create fake access points with names similar to legitimate ones, tricking users into
connecting to the malicious network. Once connected, the attacker can intercept sensitive data
or execute further attacks.

8. Deauthentication/Disassociation Attacks

Attackers send forged deauthentication or disassociation frames to wireless devices, forcing


them to disconnect from the network, leading to service disruptions or potential vulnerabilities
when devices automatically reconnect.

IDENTITY THEFT
Identity Theft also called Identity Fraud is a crime that is being committed by a huge number
nowadays. Identity theft happens when someone steals your personal information to commit
fraud. This theft is committed in many ways by gathering personal information such as
transactional information of another person to make transactions.

Example: Thieves use different mechanisms to extract information about customers' credit
cards from corporate databases, once they are aware of the information they can easily degrade
the rating of the victim's credit card. Having this information with the thieves can make you
cause huge harm if not notified early. With these false credentials, they can obtain a credit card
in the name of the victim which can be used for covering false debts.

Types of Identity Thefts:

There are various amount of threats but some common ones are :
• Criminal Identity Theft - This is a type of theft in which the victim is charged guilty
and has to bear the loss when the criminal or the thief backs up his position with the
false documents of the victim such as ID or other verification documents and his bluff
is successful.

• Senior Identity Theft - Seniors with age over 60 are often targets of identity thieves.
They are sent information that looks to be actual and then their personal information is
gathered for such use. Seniors must be aware of not being the victim.

• Driver's license ID Identity Theft - Driver's license identity theft is the most common
form of ID theft. All the information on one's driver's license provides the name,
address, and date of birth, as well as a State driver's identity number. The thieves use
this information to apply for loans or credit cards or try to open bank accounts to obtain
checking accounts or buy cars, houses, vehicles, electronic equipment, jewelry,
anything valuable and all are charged to the owner's name.

• Medical Identity Theft - In this theft, the victim's health-related information is


gathered and then a fraud medical service need is created with fraud bills, which then
results in the victim's account for such services.

• Tax Identity Theft - In this type of attack attacker is interested in knowing your
Employer Identification Number to appeal to get a tax refund. This is noticeable when
you attempt to file your tax return or the Income Tax return department sends you a
notice for this.

• Social Security Identity Theft - In this type of attack the thief intends to know your
Social Security Number (SSN). With this number, they are also aware of all your
personal information which is the biggest threat to an individual.

• Synthetic Identity Theft - This theft is uncommon to the other thefts, thief combines
all the gathered information of people and they create a new identity. When this identity
is being used than all the victims are affected.
• Financial Identity Theft - This type of attack is the most common type of attack. In
this, the stolen credentials are used to attain a financial benefit. The victim is identified
only when he checks his balances carefully as this is practiced in a very slow manner.

Techniques of Identity Thefts: Identity thieves usually hack into corporate databases for
personal credentials which requires effort but with several social-engineering techniques, it is
considered easy. Some common identity theft techniques are:

• Pretext Calling - Thieves pretending to be an employee of a company over phone


asking for financial information are an example of this theft. Pretending as legitimate
employees they ask for personal data with some buttery returns.

• Mail Theft - This is a technique in which credit card information with transactional
data is extracted from the public mailbox.

• Phishing - This is a technique in which emails pertaining to be from banks are sent to
a victim with malware in it. When the victim responds to mail their information is
mapped by the thieves.

• Internet - Internet is widely used by the world as attackers are aware of many
techniques of making users get connected with public networks over Internet which is
controlled by them and they add spyware with downloads.

• Dumpster Diving - This is a technique that has made much information out of the
known institutions. As garbage collectors are aware of this they search for account
related documents that contain social security numbers with all the personal documents
if not shredded before disposing of.
• Card Verification Value (CVV) Code Requests - The Card Verification Value number
is located at the back of your debit cards. This number is used to enhance transaction
security but several attackers ask for this number while pretending as a bank official.

Steps Of Prevention from Identity Theft:

Following are some methods by which you can enhance your security for identity thefts:

1. Use Strong Passwords and do not share your PIN with anyone on or off the phone.

2. Use two-factor notification for emails.

3. Secure all your devices with a password.

4. Don't install random software from the internet.


5. Don't post sensitive information over social media.

6. While entering passwords at payment gateway ensure its authenticity.

7. Limit the personal information to be carried without.

8. Keep a practice of changing your PIN and password regularly.

9. Do not disclose your information over phone.

10. While traveling do not disclose personal information with strangers.

11. Never share your Aadhaar/PAN number (In India) with anyone whom you do not
know/trust.

12. Never share your SSN (In US) with anyone whom you do not know/trust.

13. Do not make all the personal information on your social media accounts public.
14. Please never share an Aadhaar OTP received on your phone with someone over a call.

15. Make sure that you do not receive unnecessary OTP SMS about Aadhaar (if you do,
your Aadhaar number is already in the wrong hands).

16. Do not fill personal data on the website that claims to offer benefits in return.

17. Last, be a keeper of personal knowledge.

You might also like