Unit 3 Notes
Unit 3 Notes
UNIT-III (NOTES)
Proxy Server
A proxy server acts as a gateway between your device and the internet, masking your IP address
and enhancing online privacy. But what exactly does it do, and why is it critical for businesses,
developers, and everyday users? In this guide, we’ll break down proxy servers in simple terms
exploring how they work, their key benefits (like bypassing geo-blocks and securing sensitive
data), and the different types (residential, data Center, and mobile proxies).
For example, Smartproxy has been offering unique solutions for online anonymity and web
data collection since 2018. It has a 55M+ residential proxy pool that opens horizons for block-
free web scraping and geo-targeting. They provide access to 195+ locations worldwide,
including city-level and 50 US states targeting.
The proxy server also prevents the identification of the client’s IP address when the client
makes any request to any other servers. In this guide, well explain proxy servers, explore their
benefits (and limitations), and reveal how they power everything from anonymous browsing to
global market research.
• Internet Client and Internet resources: For Internet clients, Proxy servers also act as
a shield for an internal network against the request coming from a client to access the
data stored on the server. It makes the original IP address of the node remain hidden
while accessing data from that server.
• Protects true host identity: In this method, outgoing traffic appears to come from the
proxy server rather than internet navigation. It must be configured to a specific
application such as HTTP or FTP. For example, organizations can use a proxy to
observe the traffic of their employees to get the work efficiently done. It can also be
used to keep a check on any kind of highly confidential data leakage. Some can also
use it to increase their website rank.
Need of Proxy Server
The need for a proxy server can vary depending on the specific use case, organization, or
individual requirements. Here are some common reasons and needs for proxy server:
• Enhanced Privacy & Anonymity: Proxy servers act as an intermediary, masking the
user’s original IP address and providing a level of anonymity while browsing the
internet.
• Bypassing Internet Restrictions: In regions where certain websites or services are
blocked, a proxy server allows users to bypass these restrictions and access blocked
content.
Types of Proxy Server
Explore the different types of proxy servers—residential, data center, mobile, and more. Learn
how each works, and ideal use cases for privacy, security, and data tasks.
A reverse proxy does the opposite of forward proxy. A forward proxy acts on behalf of clients
(or requesting hosts). Forward proxies can hide the identities of clients whereas reverse proxies
can hide the identities of servers. The job of a reverse proxy server to listen to the request made
by the client and redirect to the particular web server which is present on different servers.
Reverse proxies have several use cases, a few are:
• Load balancing: distribute the load to several web servers.
• Cache static content: offload the web servers by caching static content like pictures,
HTML pages.
• Compression: compress and optimize content to speed up load time.
2. Web Proxy Server
Web Proxy forwards the HTTP requests, only URL is passed instead of a path. The request is
sent to particular the proxy server responds. Examples, Apache, HAP Proxy.
This type of proxy server does not make an original IP address instead these servers are
detectable still provides rational anonymity to the client device.
This proxy server does not allow the original IP address and it as a proxy server to be detected.
5. Transparent Proxy
This type of proxy server is unable to provide any anonymity to the client, instead, the original
IP address can be easily detected using this proxy. But it is put into use to act as a cache for the
websites. A transparent proxy when combined with gateway results in a proxy server where the
connection requests are sent by the client , then IP are redirected. Redirection will occurs
without the client IP address configuration. HTTP headers present on the server-side can easily
detect its redirection .
6. CGI Proxy
CGI proxy server developed to make the websites more accessible. It accepts the requests to
target URLs using a web form and after processing its result will be returned to the web
browser. It is less popular due to some privacy policies like VPNs but it still receives a lot of
requests also. Its usage got reduced due to excessive traffic that can be caused to the website
after passing the local filtration and thus leads to damage to the organization.
7. Suffix Proxy
Suffix proxy server basically appends the name of the proxy to the URL. This type of proxy
doesn’t preserve any higher level of anonymity. It is used for bypassing the web filters. It is
easy to use and can be easily implemented but is used less due to the more number of web filter
present in it.
8. Distorting Proxy
Proxy servers are preferred to generate an incorrect original IP address of clients once being
detected as a proxy server. To maintain the confidentiality of the Client IP address HTTP
headers are used.
It uses encryption to hide all the communications at various levels. This encrypted data is then
relayed through various network routers present at different locations and thus I2P is a fully
distributed proxy. This software is free of cost and open source to use, It also resists the
censorship.
DNS proxy take requests in the form of DNS queries and forward them to the Domain server
where it can also be cached, moreover flow of request can also be redirected.
A rotating proxy assign a new or different IP address to each user that connects to proxy. As
users connect, the unique address is assign to it.
Every computer has its unique IP address which it uses to communicate with another node.
Similarly, the proxy server has its IP address that your computer knows. When a web request
is sent, your request goes to the proxy server first. The Proxy sends a request on your behalf to
the internet and then collect the data and make it available to you. A proxy can change your IP
address So, the webserver will be unable to fetch your location in the world. It protects data
from getting hacked too. Moreover, it can block some web pages also.
What is the reason of using Proxy Server?
There are some reasons why everyone should proxy server because it provide following
advantages including privacy, web scraping, fast speed, saves bandwidth etc.
• Security: Proxy Server provides security between internet and system. They help your
system from unauthorized user to access your network
• Filteration: Proxy servers are used to filter content based on keywords or file types.
• Access Control: There are some content which is restricted in various countries, so
proxy server helps to control geographical access.
Disadvantages of Proxy Server
• Proxy Server Risks: Free installation does not invest much in backend hardware or
encryption. It will result in performance issues and potential data security issues. If you
install a "free" proxy server, treat very carefully, some of those might steal your credit
card numbers.
• Browsing history log: The proxy server stores your original IP address and web request
information is possibly unencrypted form and saved locally. Always check if your proxy
server logs and saves that data – and what kind of retention or law enforcement
cooperation policies they follow while saving data.
• No encryption: No encryption means you are sending your requests as plain text.
Anyone will be able to pull usernames and passwords and account information easily.
Keep a check that proxy provides full encryption whenever you use it.
Anonymizers
An anonymizer, also known as an anonymous proxy, is a tool that hides your IP address and
other identifying information when accessing the internet. This allows you to browse the web
without directly revealing your location or identity to the websites you visit.
An anonymizer refers to a proxy server designed to minimise the data a user discloses while
browsing the internet.
Uses of Anonymiser
1. Privacy and Security:
• Preventing Tracking:
Anonymizers hide a user's IP address, making it difficult for websites and third-party
trackers to follow their online activity.
• Protecting Personal Information:
By masking online activity, anonymizers can help prevent the collection and misuse of
personal information, such as search history or browsing patterns.
• Minimizing Risk of Identity Theft:
Anonymizers can reduce the risk of identity theft by making it harder for malicious actors
to link online activity to a user's identity.
Anonymizers can help users access websites and content that are blocked or restricted in
their region.
• Circumventing Censorship:
In some countries, anonymizers can be used to bypass internet censorship and access
otherwise restricted websites and information.
Anonymizers can make it harder for websites to track a user's browsing history and show
them personalized ads based on their location or preferences.
By avoiding targeted advertising and personalization, anonymizers can help users access a
more objective view of information.
4. Other Uses:
• Enhanced Security:
Anonymizers can help protect against certain types of cyber threats, such as hacking and
phishing, by making it harder for attackers to identify and target users.
Types of Anonymizers:
They can be broadly categorized into two main types: networked anonymizers and single-
point anonymizers.
Networked Anonymizers: These involve routing your internet traffic through a network of
servers, making it difficult to trace your origin back to your device. Examples include:
A free and open-source software that encrypts your internet traffic and routes it through a
distributed network of volunteer-operated servers, making it very difficult to track your
activities.
Create an encrypted tunnel between your device and a VPN server, masking your IP address
and location.
• Proxies:
These are servers that act as a middleman between your device and the internet, masking
your IP address and potentially hiding your origin from websites.
• Public Proxies:
These are freely available proxy servers that can be used by anyone.
• Residential Proxies:
These are proxy servers that appear to be originating from a home IP address, which can
be more difficult to identify as proxies.
These are specific computers within the Tor network that act as the final point of exit for
anonymized traffic, and they can be vulnerable.
PHISHING:
Phishing is a type of social engineering where attackers attempt to trick individuals into
revealing sensitive information like passwords, credit card details, or personal
information. This is typically done through fraudulent emails or messages that appear to
come from legitimate sources.
Types of Phishing:
Email phishing
In an email phishing scam, the attacker sends an email that looks legitimate, designed to
trick the recipient into entering information in reply or on a site that the hacker can use to
steal or sell their data.
Hackers used LinkedIn to grab contact information from employees at Sony and targeted
them with an email phishing campaign. They got away with over 100 terabytes of data.
Spear phishing
An attacker tried to target an employee of NTL World, which is a part of the Virgin Media
company, using spear phishing. The attacker claimed that the victim needed to sign a new
employee handbook. This was designed to lure them into clicking a link where they would
have been asked to submit private information.
Whaling
A whaling attack is a phishing attack that targets a senior executive. These individuals
often have deep access to sensitive areas of the network, so a successful attack can result
in access to valuable info.
Example of whaling
A founder of Levitas, an Australian hedge fund was the target of a whaling attack that led
the individual to a fake connection using a fraudulent Zoom link. After following the link,
they had malware installed on their system, and the company lost $800.000.
Smishing
Vishing, which is short for "voice phishing," is when someone uses the phone to try to steal
information. The attacker may pretend to be a trusted friend or relative or to represent them.
Example of vishing
In 2019, there was a vishing campaign that targeted members of the UK’s parliament and
their staffers. The attack was part of an assault that involved at least 21 million spam emails
targeting UK lawmakers.
Clone phishing
A clone phishing attack involves a hacker making an identical copy of a message the
recipient already received. They may include something like “resending this” and put a
malicious link in the email.
Impact of Phishing:
• Financial Loss:
Phishing scams can lead to unauthorized transactions, identity theft, and financial
exploitation says the OCC.
• Identity Theft:
Phishers can steal sensitive information like Social Security numbers and bank details,
leading to identity theft and its consequences.
• Malware Infections:
Phishing emails may contain malicious links or attachments that install malware, including
ransomware, on the victim's device states UT Southwestern Medical Center.
• Data Loss:
Compromised accounts and systems can lead to the loss of personal data, including photos,
documents, and financial records mentions Proofpoint.
PASSWORD CRACKING
A password cracker recovers passwords using various techniques. The process can involve
comparing a list of words to guess passwords or the use of an algorithm to repeatedly guess
the password.
KEYLOGGER
A keylogger or keystroke logger/keyboard capturing is a form of malware or hardware that
keeps track of and records your keystrokes as you type. It takes the information and sends it to
a hacker using a command-and-control (C&C) server. The hacker then analyzes the
keystrokes to locate usernames and passwords and uses them to hack into otherwise secure
systems.
Types Of Keyloggers
A software keylogger is a form of malware that infects your device and, if programmed to do
so, can spread to other devices the computer comes in contact with. While a hardware
keylogger cannot spread from one device to another, like a software keylogger, it transmits
information to the hacker or hacking organization, which they will then use to compromise
your computer, network, or anything else that requires authentication to access.
1. Software keyloggers
A software keylogger is put on a computer when the user downloads an infected application.
Once installed, the keylogger monitors the keystrokes on the operating system you are using,
checking the paths each keystroke goes through. In this way, a software keylogger can keep
track of your keystrokes and record each one.
After the keystrokes have been recorded, they are then automatically transferred to the hacker
that set up the keylogger. This is done using a remote server that both the keylogger software
and the hacker are connected to. The hacker retrieves the data gathered by the keylogger and
then uses it to figure out the unsuspecting user’s passwords.
The passwords stolen using the key logger may include email accounts, bank or investment
accounts, or those that the target uses to access websites where their personal information can
be seen. Therefore, the hacker's end goal may not be to get into the account for which the
password is used. Rather, gaining access to one or more accounts may pave the way for the
theft of other data.
2. Hardware keyloggers
A hardware keylogger works much like its software counterpart. The biggest difference is
hardware keyloggers have to be physically connected to the target computer to record the user's
keystrokes. For this reason, it is important for an organization to carefully monitor who has
access to the network and the devices connected to it.
If an unauthorized individual is allowed to use a device on the network, they could install a
hardware keylogger that may run undetected until it has already collected sensitive information.
After hardware keystroke loggers have finished keylogging, they store the data, which the
hacker has to download from the device.
The downloading has to be performed only after the keylogger has finished logging keystrokes.
This is because it is not possible for the hacker to get the data while the key logger is working.
In some cases, the hacker may make the keylogging device accessible via Wi-Fi. This way,
they do not have to physically walk up to the hacked computer to get the device and retrieve
the data.
SPYWARE
Spyware is a type of malicious software (malware) that is installed on a computing device
without the user's knowledge or consent. It gathers information about the user's activity,
including their online behavior, browsing habits, and even personal information, and then
transmits this data to third parties without their permission. This data can be used for various
malicious purposes, including data theft, advertising targeting, or even financial fraud.
Spyware is one of the most commonly used cyberattack methods that can be difficult for users
and businesses to identify and can do serious harm to networks. It also leaves businesses
vulnerable to data breaches and data misuse, often affects device and network performance,
and slows down user activity.
The term "spyware" first emerged in online discussions in the 1990s, but only in the early 2000s
did cybersecurity firms use it to describe unwanted software that spied on their user and
computer activity. The first anti-spyware software was released in June 2000, then four years
later, scans showed that around 80% of internet users had their systems affected by spyware,
according to research by America Online and the National Cyber Security Alliance.
However, 89% of users were unaware of the spyware’s existence and 95% had not granted
permission for it to be installed.
Types of spyware
1. Adware: This sits on a device and monitors users’ activity then sells their data to
advertisers and malicious actors or serves up malicious ads.
2. Infostealer: This is a type of spyware that collects information from devices. It scans
them for specific data and instant messaging conversations.
6. System monitors: These also track user activity on their computer, capturing
information like emails sent, social media and other sites visited, and keystrokes.
7. Tracking cookies: Tracking cookies are dropped onto a device by a website and then
used to follow the user’s online activity.
8. Trojan Horse Virus: This brand of spyware enters a device through Trojan malware,
which is responsible for delivering the spyware program.
VIRUS
A computer virus is a malicious software program (malware) that replicates itself by modifying
other programs and inserting its code. It's designed to infect, replicate, and damage computer
systems. Unlike a biological virus, a computer virus needs a host to attach itself to and spread,
often through infected files or programs.
2. Boot Sector Virus: Attacks the part of the computer that starts up when you turn it on. Boot
Sector Virus can also spread through devices like floppy disks. Often called a memory virus.
3. Macro Virus: Activates by running a program capable of executing macros, often found in
documents like spreadsheets.
4. Email Virus: Hides in email messages and activates by clicking a link, opening an
attachment, or interacting with the email.
5. Polymorphic Virus: Changes its form every time it installs to avoid detection by antivirus
software.
6. Multipartite Virus: Infects the computer’s boot sector, memory, and files, making it
difficult to detect and remove.
7. Encrypted Virus: Uses encryption to hide from antivirus software, includes a decryption
algorithm to run before executing.
8. Stealth Virus: Modifies detection code, making it very difficult to detect.
9. Resident Virus: Saves itself in the computer's memory and can infect other files even after
the original program stops.
10. Direct Action Virus: Tied to an executable file, it activates when the file is opened but
does not delete files or affect system speed; blocks file access.
11. Browser Hijacker Virus: Changes browser settings without permission, can redirect to
malicious sites.
1. Install Antivirus Software: Think of antivirus software as your computer's doctor. It works
around the clock to detect and block viruses before they can infect your system. Make sure to
keep it updated!
2. Update Regularly: Keep your operating system, software, and apps up to date. Updates
often include fixes for security vulnerabilities that viruses could exploit.
3. Be Cautious with Emails and Downloads: Don't open emails or download attachments
from unknown sources. If an email looks suspicious, even if you know the sender, it's best to
delete it.
4. Use Strong Passwords: Protect your accounts with strong, unique passwords. Consider
using a password manager to keep track of them all.
5. Backup Your Data: Regularly back up your data to an external drive or cloud storage. If
a virus does slip through, you won't lose everything.
By following these steps, you can help keep your computer virus-free and running smoothly.
WORM:
A worm is a type of malicious software (malware) that replicates itself and spreads across
networks without requiring any user interaction. Unlike a virus, which needs a host file to infect
a system, a worm can self-propagate and infect multiple computers independently. Worms
often exploit network vulnerabilities and can cause significant damage by consuming
bandwidth, disrupting services, and potentially stealing data.
Worms can copy themselves to other computers within a network without needing user
interaction.
• Standalone:
They don't need a host program to operate, unlike viruses, which need a file or application to
infect a system.
• Network-based:
Worms spread through network connections, like email, instant messaging, or shared network
drives.
• Exploit vulnerabilities:
They often target security weaknesses in software or operating systems to gain access and
spread.
• Resource consumption:
Worms can consume significant network bandwidth, leading to slowdowns, system crashes,
and even denial-of-service attacks.
• Potential for harm:
They can cause data loss, system damage, and even theft of sensitive information.
• Phishing emails: Worms can be attached to emails that look legitimate, tricking users
into opening them.
• Network-connected devices: Sharing files or devices (like USB drives) can spread
worms.
Types of Worms:
• Email worms: Spread through emails, often with malicious attachments.
• Internet worms: Infect websites and spread to visitors who browse those sites.
• Cryptoworms: Encrypt data on the victim's system, demanding ransom for its release.
TROJAN-HORSES
A Trojan horse is a type of malware that disguises itself as legitimate software to trick users
into installing it. Once installed, it can perform various malicious activities, such as data theft,
remote access, or system damage. Trojans don't self-replicate like viruses or worms; they rely
on user interaction for distribution.
Key Characteristics:
• Disguise: Trojans are designed to look like ordinary programs, files, or software.
• Delivery: They are often distributed through email attachments, fake software updates,
or by embedding themselves within legitimate software.
• Malicious Actions: Once installed, they can steal data, give attackers remote access, or
cause other harm to the system.
• Backdoor Trojans: Provide attackers with remote access to the infected system.
• Downloader Trojans: Install other malicious software on the device.
• Remote Access Trojans (RATs): Give attackers full control of the victim's computer.
• Be cautious about email attachments and suspicious links: Avoid clicking on links
or opening attachments from unknown senders.
• Update your antivirus software regularly: Ensure you have a strong antivirus or
security suite with up-to-date definitions.
• Use strong passwords and enable two-factor authentication: Protect your accounts
from unauthorized access.
BACKDOORS
A backdoor is a hidden entry point that bypasses a system's normal security measures, granting
unauthorized access. It's a way for malicious actors to gain access without triggering standard
security alerts, potentially leading to data theft, malware installation, and persistent control of
a system.
• Examples:
• Default passwords: Unchanged default credentials can act as backdoors,
allowing easy access for attackers.
• Security tools: Use security tools and strategies to detect and prevent backdoor
attacks.
STEGNOGRAPHY
Steganography, the art of concealing data within seemingly ordinary media, plays a significant
role in cybersecurity, particularly in both legitimate security practices and malicious
cyberattacks. It's used to hide secret messages, data, or even malware within images, audio,
video, or text files, making them difficult to detect by unauthorized parties.
• Legitimate Uses:
• Cyberattack Applications:
Malware developers and cybercriminals use steganography to hide malicious code within
seemingly harmless files, such as images or audio, to evade detection by antivirus
software. This "stegomalware" can be used in various attacks, including data exfiltration and
ransomware.
• Data Exfiltration:
Steganography can also be used in the data exfiltration stage of a cyberattack, allowing
malicious actors to extract stolen data from a compromised system without being detected.
By concealing data within ordinary files, steganography enables threat actors to bypass security
measures and maintain a low profile.
This technique involves modifying the least significant bit of each pixel or data unit to embed
the secret message.
Steganography in cybersecurity involves both legitimate uses for security professionals and
malicious applications by cybercriminals. It's a powerful tool for concealing data, and
understanding its techniques and applications is crucial for cybersecurity professionals to
effectively detect and prevent attacks.
DoS attacks aim to prevent users from accessing online services, websites, email, or other
resources.
Attackers flood the target with traffic, often using fake requests, to overload the system's
resources.
• No direct access:
Unlike some attacks that aim to steal data, DoS attacks primarily focus on disrupting
functionality, not gaining access to the system.
• Various methods:
DoS attacks can be launched from a single attacker's computer or distributed across multiple
computers (Distributed Denial of Service - DDoS).
• Impact on users:
DoS attacks can cause significant disruption to individuals and businesses, impacting their
ability to access online services and conduct business.
An attacker can flood a network with excessive traffic, causing it to become congested and
slow.
• Exploiting vulnerabilities:
Attackers may exploit vulnerabilities in a system's software or configuration to disrupt its
operation.
A DDoS attack uses multiple servers and Internet connections to flood the targeted resource. A
DDoS attack is one of the most powerful weapons on the cyber platform. When you come to
know about a website being brought down, it generally means it has become a victim of a DDoS
attack. This means that the hackers have attacked your website or PC by imposing heavy traffic.
Thus, crashing the website or computer due to overloading.
Example: In 2000, Michael Calce, a 15-year-old boy who used the online name “Mafiaboy”,
was behind one of the first DDoS attacks. He hacked into the computer networks of various
different universities. He used their servers to operate a DDoS attack that brought down several
websites such as eBay and Yahoo. In 2016, Dyn was hit with a massive DDoS attack that took
down major websites and services such as Netflix, PayPal, Amazon, and GitHub.
DoS DDoS
DoS Stands for Denial-of-service attack. DDoS Stands for Distributed Denial of
service attack.
In Dos attack single system targets the victim In DDoS multiple systems attack the victim's
system. system.
Victim's PC is loaded from the packet of data Victim PC is loaded from the packet of data
sent from a single location. sent from Multiple locations.
Dos attack is slower as compared to DDoS. A DDoS attack is faster than Dos Attack.
Can be blocked easily as only one system is It is difficult to block this attack as multiple
used. devices are sending packets and attacking
from multiple locations.
In DOS Attack only a single device is used In a DDoS attack, the volumeBots are used
with DOS Attack tools. to attack at the same time.
DOS Attacks are Easy to trace. DDOS Attacks are Difficult to trace.
Types of DOS Attacks are: Types of DDOS Attacks are:
1. Buffer overflow attacks 1. Volumetric Attacks
2. Ping of Death or ICMP flood 2. Fragmentation Attacks
3. Teardrop Attack 3. Application Layer Attacks
4. Flooding Attack 4. Protocol Attack.
3. Application Attacks: Application layer attacks (Layer 7 attacks) target the applications
of the victim in a slower fashion. Thus, they may initially appear as legitimate requests
from users and the victim becomes unable to respond. These attacks target the layer
where a server generates web pages and responds to HTTP requests. Application-level
attacks are combined with other kinds of DDoS attacks targeting applications, along
with the network and bandwidth. These attacks are threatening as it is more difficult for
companies to detect.
The logic of a DDoS attack is very simple, although attacks can be highly different from each
other. Network connections consist of various layers of the OSI model. Various types of DDoS
attacks focus on particular layers. Examples are illustrated below:
• Layer-3: Network layer - Attacks are known as Smurf Attacks, ICMP Floods, and
IP/ICMP Fragmentation.
• Layer-4: Transport layer - Attacks include SYN Floods, UDP Floods, and TCP
Connection Exhaustion.
1. Take quick action: Sooner the DDoS attack is identified, the quicker the harm can be
resisted. Companies should provide DDoS services or a certain kind of technology so
that the heavy traffic can be realized and worked upon as soon as possible.
2. Configure firewalls and routers: Firewalls and routers should be configured in such
a way that they reject bogus traffic and you should keep your routers as well as firewalls
updated with the latest security patches.
3. Consider artificial intelligence: While present defenses of advanced firewalls and
intrusion detection systems are very common, Artificial Intelligence is being used to
develop new systems.
4. Secure your Internet of Things devices: To keep your devices from becoming a part
of a botnet, it's smart to make sure your computers have trusted security software. It's
important to keep it updated with the latest security patches.
BUFFER OVERFLOW
A buffer is a temporary area for data storage. When more data (than was originally allocated
to be stored) gets placed by a program or system process, the extra data overflows. It causes
some of that data to leak out into other buffers, which can corrupt or overwrite whatever data
they were holding.
In a buffer-overflow attack, the extra data sometimes holds specific instructions for actions
intended by a hacker or malicious user; for example, the data could trigger a response that
damages files, changes data or unveils private information.
Attacker would use a buffer-overflow exploit to take advantage of a program that is waiting on
a user's input. There are two types of buffer overflows: stack-based and heap-based. Heap-
based, which are difficult to execute and the least common of the two, attack an application by
flooding the memory space reserved for a program. Stack-based buffer overflows, which are
more common among attackers, exploit applications and programs by using what is known as
a stack memory space used to store user input.
2. Access control loss: A buffer overflow attack will often involve the use of arbitrary
code, which is often outside the scope of programs’ security policies.
3. Further security issues: When a buffer overflow attack results in arbitrary code
execution, the attacker may use it to exploit other vulnerabilities and subvert other
security services.
1. Stack-based buffer overflows: This is the most common form of buffer overflow
attack. The stack-based approach occurs when an attacker sends data containing
malicious code to an application, which stores the data in a stack buffer. This overwrites
the data on the stack, including its return pointer, which hands control of transfers to
the attacker.
2. Heap-based buffer overflows: A heap-based attack is more difficult to carry out than
the stack-based approach. It involves the attack flooding a program’s memory space
beyond the memory it uses for current runtime operations.
3. Format string attack: A format string exploit takes place when an application
processes input data as a command or does not validate input data effectively. This
enables the attacker to execute code, read data in the stack, or cause segmentation faults
in the application. This could trigger new actions that threaten the security and stability
of the system.
WIRELESS ATTACKS:
A wireless attack involves identifying & examining the connections between all devices
connected to the business’s wifi. These devices include laptops, tablets, smartphones, and any
other internet of Things (IoT) devices. This attack refers to the unauthorized exploitation of
vulnerabilities in wireless networks or devices to gain unauthorized access, intercept data, or
disrupt network communication.
In these attacks, the attacker positions themselves between the wireless client and the legitimate
access point, intercepting and manipulating data transmissions. The attacker may then relay the
information back and forth, making it appear as if they are the legitimate access point. This
enables them to snoop on data or perform other malicious actions unnoticed.
Attackers set up unauthorized access points, mimicking legitimate ones, to deceive users into
connecting to them. Once connected, the attacker can eavesdrop, capture data, or launch further
attacks on the unsuspecting users.
5. Brute-Force Attacks
Attackers try various combinations of passwords or encryption keys in rapid succession until
they find the correct one to gain unauthorized access to the wireless network.
6. WEP/WPA Cracking
Attackers exploit vulnerabilities in older wireless security protocols like Wired Equivalent
Privacy (WEP) and Wi-Fi Protected Access (WPA) to gain unauthorized access to encrypted
wireless networks.
Attackers create fake access points with names similar to legitimate ones, tricking users into
connecting to the malicious network. Once connected, the attacker can intercept sensitive data
or execute further attacks.
8. Deauthentication/Disassociation Attacks
IDENTITY THEFT
Identity Theft also called Identity Fraud is a crime that is being committed by a huge number
nowadays. Identity theft happens when someone steals your personal information to commit
fraud. This theft is committed in many ways by gathering personal information such as
transactional information of another person to make transactions.
Example: Thieves use different mechanisms to extract information about customers' credit
cards from corporate databases, once they are aware of the information they can easily degrade
the rating of the victim's credit card. Having this information with the thieves can make you
cause huge harm if not notified early. With these false credentials, they can obtain a credit card
in the name of the victim which can be used for covering false debts.
There are various amount of threats but some common ones are :
• Criminal Identity Theft - This is a type of theft in which the victim is charged guilty
and has to bear the loss when the criminal or the thief backs up his position with the
false documents of the victim such as ID or other verification documents and his bluff
is successful.
• Senior Identity Theft - Seniors with age over 60 are often targets of identity thieves.
They are sent information that looks to be actual and then their personal information is
gathered for such use. Seniors must be aware of not being the victim.
• Driver's license ID Identity Theft - Driver's license identity theft is the most common
form of ID theft. All the information on one's driver's license provides the name,
address, and date of birth, as well as a State driver's identity number. The thieves use
this information to apply for loans or credit cards or try to open bank accounts to obtain
checking accounts or buy cars, houses, vehicles, electronic equipment, jewelry,
anything valuable and all are charged to the owner's name.
• Tax Identity Theft - In this type of attack attacker is interested in knowing your
Employer Identification Number to appeal to get a tax refund. This is noticeable when
you attempt to file your tax return or the Income Tax return department sends you a
notice for this.
• Social Security Identity Theft - In this type of attack the thief intends to know your
Social Security Number (SSN). With this number, they are also aware of all your
personal information which is the biggest threat to an individual.
• Synthetic Identity Theft - This theft is uncommon to the other thefts, thief combines
all the gathered information of people and they create a new identity. When this identity
is being used than all the victims are affected.
• Financial Identity Theft - This type of attack is the most common type of attack. In
this, the stolen credentials are used to attain a financial benefit. The victim is identified
only when he checks his balances carefully as this is practiced in a very slow manner.
Techniques of Identity Thefts: Identity thieves usually hack into corporate databases for
personal credentials which requires effort but with several social-engineering techniques, it is
considered easy. Some common identity theft techniques are:
• Mail Theft - This is a technique in which credit card information with transactional
data is extracted from the public mailbox.
• Phishing - This is a technique in which emails pertaining to be from banks are sent to
a victim with malware in it. When the victim responds to mail their information is
mapped by the thieves.
• Internet - Internet is widely used by the world as attackers are aware of many
techniques of making users get connected with public networks over Internet which is
controlled by them and they add spyware with downloads.
• Dumpster Diving - This is a technique that has made much information out of the
known institutions. As garbage collectors are aware of this they search for account
related documents that contain social security numbers with all the personal documents
if not shredded before disposing of.
• Card Verification Value (CVV) Code Requests - The Card Verification Value number
is located at the back of your debit cards. This number is used to enhance transaction
security but several attackers ask for this number while pretending as a bank official.
Following are some methods by which you can enhance your security for identity thefts:
1. Use Strong Passwords and do not share your PIN with anyone on or off the phone.
11. Never share your Aadhaar/PAN number (In India) with anyone whom you do not
know/trust.
12. Never share your SSN (In US) with anyone whom you do not know/trust.
13. Do not make all the personal information on your social media accounts public.
14. Please never share an Aadhaar OTP received on your phone with someone over a call.
15. Make sure that you do not receive unnecessary OTP SMS about Aadhaar (if you do,
your Aadhaar number is already in the wrong hands).
16. Do not fill personal data on the website that claims to offer benefits in return.