0% found this document useful (0 votes)
2 views47 pages

Module 4

The document discusses web browser security risks, including vulnerabilities to attacks such as hijacking and replay, and emphasizes the importance of user awareness in protecting personal information. It outlines how web browsers function, their core architecture, and popular examples while highlighting the need for safe browsing practices. Recommendations for improving browser security include keeping software updated, avoiding suspicious links, and using secure sites for sensitive transactions.

Uploaded by

fewehi8947
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views47 pages

Module 4

The document discusses web browser security risks, including vulnerabilities to attacks such as hijacking and replay, and emphasizes the importance of user awareness in protecting personal information. It outlines how web browsers function, their core architecture, and popular examples while highlighting the need for safe browsing practices. Recommendations for improving browser security include keeping software updated, avoiding suspicious links, and using secure sites for sensitive transactions.

Uploaded by

fewehi8947
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Module-4 (Web Security) Web Browser and Client risk- How a web browser works, Web

browser attacks, Operating safely, Web security- How HTTP works, Server and Client
contents, Attacking Web servers, Web Services.E-mail security- The e-mail risk, Protocols,
Authentication, Operating safely when using email, Domain Name System – DNS basics,
Purpose of DNS, Security Issues with DNS, DNS attacks. - WAP Gateway.

Web Browser and Client risk

In many ways, Web browsers are the ultimate in computer convenience. The Internet started
out as an academic information exchange enabler. Then Web browsers made the Internet easy
to use and allowed noncomputer-savvy companies and individuals to harness the power of
information exchange and remote processing. Ever since the inception of the easy-to-use and
pleasant-to-view Web browser, the Internet has taken off. In a few short years, it has landed in
nearly every business and most homes throughout the United States. The convenience,
productivity, and popularity of Web browsers make them a prime target for hackers and
would be attackers. As the convenience of a product increases, so does the security risk, so
Web browsers by their very nature should be expected to be risky. The productivity of the
Web browser also makes it a prime target for attacks because the hacker can get the biggest
bang for the effort put forth. Finally, the popularity of a product plays into the hacker’s hands
by increasing the scope of any attack or vulnerability discovered. The hacker who develops
an attack for a common Web browser is sure to find many susceptible targets.

More so than most applications on the typical user’s workstation, the Web browser highlights
the two related areas of concern—privacy and security. Security is concerned with the
confidentiality, integrity, and availability of data. Privacy is concerned with the inadvertent
disclosure of information. In some cases, this disclosure is to the result of a security
breakdown in confidentiality. But in many cases, the privacy violation occurs when users
unwittingly disclose personal information. The convenience and productivity of Web
browsers can lull users into providing information that they would not normally give to total
strangers.

Web browsers today provide a lot more features than simply rendering images and HTML
code. Their convenience is greatly enhanced by their capability to do the following:

✦ Run Common Gateway Interface (CGI) scripts on the Web server


✦ Run scripts written in JavaScript or Visual Basic Script (VBScript) on the Web browser

✦ Run executables such as Java and ActiveX on the Web browser host

✦ Launch various plugins such as an audio player or movie player

Convenience may introduce security risks into Web browsers, but it is the productivity and
popularity of the browser that makes us susceptible to these risks. It is a Web browser’s
productivity that keeps users coming back to this application.

The more an application is used for critical or sensitive work, the greater the potential
security risk to the user. Some of the most sensitive work users do on their work stations is
done through Web browsers. Often users will do banking, credit card purchases, shipping to a
home address, and hobby pursuits. The data involved in any of these activities would be of
interest to an attacker. But to be a prime target, an application must be more than just
convenient and productive—it must be popular, meaning widely distributed and used.
Hackers will focus their efforts on applications that will provide them with the largest source
of potential targets. Figure 6-1 illustrates the unique combination of convenience,
productivity, and popularity that makes a Web browser a favorite target for security attacks.

Web browsers, like most Internet applications, respond to emerging security threats. In the
early years, Web browsers were very vulnerable. They had features making them convenient
and productive but had no means for the user to make them more secure. Web browsers have
evolved (due to the security threat) to a customizable application. Users are now able to set
various configuration items to improve the security of their Web browsers. The problem with
highly customizable Web browsers, as a security measure, is that most users are not
sophisticated and savvy when it comes to securing a Web browser or even understanding the
threat. Often users will not change any of the browser’s security configuration items. The
customization, for security purposes, is then left to the system or network administrator.
However, as discussed earlier, browsing has become such an accepted norm for convenience
and productivity that few users will tolerate less than total functionality. As a result,
administrators that initially attempt to secure browsers are often beaten back by the onslaught
of complaints and requests for help. In the end, the administrator must relax the Web-
browsing security settings.

Web browser risks

The security risks associated with using a Web browser can be grouped into several
categories: ✦ The Web server may not be secure. All the data that users enter into their
browsers is ultimately processed on the Web server. In most cases, this information is stored
in a database of some sort. Most typical users assume that a professional organization that is
providing the service is security conscious. However, the opposite is probably true (as
discussed in detail in Chapter 10). The best defense a user can have against an insecure Web
server is to limit the sensitive data that is transmitted to the server.

✦ The browser runs malcode in the form of scripts or executables. The Web browser is a
convenient and powerful tool that makes the user’s life easier by running scripts and (in some
cases) executables for the user. However, this feature could be abused and malcode could be
run instead of useful routines.

✦ An attacker may eavesdrop on network traffic. Users should be aware that the security of
the data transmitted to and from the Web server is no more secure than the security of the
network on which it travels. This risk can be reduced when the Web server uses Secure
Sockets Layer (SSL) to encrypt the data transmitted and received.

✦An attacker may employ a man-in-the-middle attack. Sessionless Web-based applications,


such as a Web server are potentially susceptible to man-in-the middle attacks such as
hijacking and replay.

Session hijacking and replay occurs when traffic between the browser and server is observed
and captured by a network sniffer. In the case of hijacking, the attacker modifies the captured
traffic to allow the man in the middle to take the place of the client. All future traffic in the
session is now between the Web server and the attacker. For the replay attack, some aspect of
the session may be modified. Certain replays, such as transferring bank funds, may not
require modifications. The modified session is then fed back onto the network. As a result,
the Web server is fooled into believing that the replayed transaction is a legitimate action by
an authorized user, clearly a security problem.

Issues working against the attacker

Almost every browser and operating system combination is vulnerable, but a couple of
factors work in the browser’s favor. The following are some factors that slightly reduce the
risk to the user:

✦The attacker cannot choose the time and place. The nature of a Web browser and server
interaction requires the user to come to the server. In the vast majority of cases, the server
does not know who or when a user will connect with the server. This makes the planning of
an attack slightly more difficult. It is very difficult for an attacker to focus on one particular
individual. Because the attacker cannot specifically target their victim, they have to take a
victim of opportunity.

✦ The attacker probably does not know the victim. Because the attacker does not know who
the victim will be, they may attack a sophisticated user and get discovered very quickly.

✦ Browsers can vary. Although there are two major browsers (Netscape and Internet
Explorer), there is a fair amount of variety in the versions of each that are commonly
deployed. An attack for one particular browser version may not be a risk to users using a
different browser.

How a web browser works

Application software that allows users to access, search, and view information on the World
Wide Web by communicating with web servers is known as a web browser. It enables smooth
navigation of websites by retrieving and displaying online content in an interactive format.

 Displays web pages with text, images, videos, and links in a user-friendly manner

 Sends and receives data using HTTP/HTTPS protocols to load websites securely
 The user enters a website URL into the browser.

 The browser contacts a DNS (Domain Name System) server to convert the domain
name into an IP address.

 Using the IP address, the browser sends a request to the web server .

 The server responds with web content such as HTML, CSS, images and scripts.

 The browser processes and renders this content into a readable webpage.

Core Architecture of Web Browser

 The User Interface sends the user’s request to the Browser Engine , which manages
the browsing process.

 The Rendering Engine displays the webpage by interpreting HTML, CSS, and
executing JavaScript for interactivity.

 Networking and UI Backend work together to fetch data from the internet and render
visual elements on the screen.
Popular Web Browsers

1. Google Chrome :Developed by Google, Chrome is one of the most widely-used web
browsers in the world, known for its speed and simplicity.

2. Microsoft Edge : Developed by Microsoft, Edge is the default browser on Windows 10


and is known for its integration with other Microsoft products and services.

3. Apple Safari :Developed by Apple, Safari is the default browser on Mac and iOS devices
and is known for its speed and integration with other Apple products.

4. Comet Browser ( Perplexity) : A lightweight and fast web browser focused on simple,
distraction-free browsing with basic privacy and performance features.

5. ChatGPT Atlas : It is an AI-powered browser assistant that helps users search, understand,
and interact with web content more efficiently.

6. Brave :Developed by Brave Software, Brave is a web browser that is focused on privacy
and security and blocks third-party ads and trackers by default.

7. Opera:Developed by Opera Software, Opera is a web browser that is known for its speed
and built-in VPN feature.

Web browser attacks

Web browser attacks are pretty typical of Web-based applications in general. The attacks can
be summarized as follows:

✦ Hijacking—This is a man-in-the-middle attack in which the attacker takes over the


session.

✦ Replay—This is a man-in-the-middle attack in which sent data is repeated (replayed)


leading to various results.

✦ Spread of malcode (viruses, worms, and so on)—The scripting nature of Web browsers
makes them prime targets for the spread of malcode.

✦ Running dangerous executables on the host—In some cases, the browser may permit
executables to run on the host workstation. This can be very risky.
✦ Accessing host files—Certain attacks allow the browser to send files to an attacker. These
files may contain personal information, such as banking data, or system information, such as
passwords.

✦ Theft of private information—Browsers are at risk of disclosing sensitive information to


strangers on the Internet. This information may be used in identity theft or to conduct a social
engineering attack.

Hijacking attack

Session hijacking occurs when an HTTP session is observed and captured by a network
sniffer. The attacker modifies the captured traffic to allow the attacker to take the place of the
client. All future traffic in the session is now channelled between the Web server and the
attacker. The hijacking is usually done after the legitimate user has authenticated to the Web
server. Therefore, the attacker does not have to re-authenticate (usually for the remainder of
the session). In this way, the attacker bypasses one of the major security features of the Web-
based session, the initial authentication. The hijacking attack exploits a weak method of
maintaining state. If the attacker can understand how state is maintained, they may be able to
inject themselves into the middle of the session by presenting a valid state.

One typically weak method of maintaining state is using cookie data to maintain state. In this
method, the user is initially authenticated (usually with a user id and password). If the
authentication is successful, the Web server sends a session cookie to the user’s browser. Now
every time the browser hits that same web server (presumably during the same session), the
user does not need to enter the password, rather the cookie re-authenticates for the user.
Replay attack

Session replay occurs when an HTTP session is captured by a network sniffer. Some aspect of
the session is then modified (certain replays, such as transferring bank funds, may not require
modifications). The modified session is then fed back onto the network. If the replay is
successful, the Web server will believe the replayed traffic to be legitimate and respond
accordingly. This could produce a number of undesirable results.

The responsibility is on the Web server to prevent replay attacks. A good method for
maintaining the session will also prevent a replay attack. The Web server should be able to
recognize replayed traffic as no longer being valid.

Browser parasites

A browser parasite is a program that changes some settings in your browser. The parasite can
have many effects on the browser, such as the following:

✦ Browser plugin parasites may add a button or link add-on to the user’s browser. When the
user clicks the button or the link, information about the user is sent to the plugin’s owner.
This can be a privacy concern.

✦ Browser parasites may change a user’s start page or search page. The new page may be a
“pay-per-click site,” where the owner of the browser parasite earns money for every click.
✦ Browser parasites may transmit the names of the sites the user visits to the owner of the
parasites. This can be used to formulate a more directed attack on the user.

Operating safely

Learning to operate a Web browser safely is a tall order with all the attacks that are possible
today. Even if users manage to configure their browsers for the safest pos sible operation,
they are still at risk in how they navigate the Internet and how they respond to certain
circumstances. For example, the most secure browser settings won’t improve your security
unless you respond appropriately to any prompt dialog boxes that come up. If the prompt asks
if an ActiveX control should be run, the user must decide to completely trust the site and click
OK. If the user chooses poorly, a dangerous ActiveX application can bypass all the security
features and run on the user’s host workstation. If users do configure their browsers for strong
security, they will experience the brunt of the security versus convenience dilemma. The user
will be constantly bar raged with requests to accept cookies, scripts, and other features such
as ActiveX. Under this constant barrage, the typical user will give in and loosen the security
settings. Users can take a number of steps to increase the security of their web browser. Users
should evaluate the risks based on their own circumstances and decide which steps are
appropriate for them. These steps include the following:

✦ Keeping current with patches

✦Avoiding viruses

✦ Using secure sites for financial and sensitive transactions

✦ Using a secure proxy

✦ Securing the network environment

✦Avoiding using private information

✦Taking care when changing browser settings

The following are recommendations to improve the Web browser security or reduce the
security risk while browsing on the Internet.

✦ Be careful when changing browser configurations. Do not configure a command line shell,
interpreter, macro processor, or scripting language processor as the “viewer” for a document.
This shifts control to the creator of the file. The type of a document is determined by the Web
server, not the browser. Do not declare an external viewer for any file that contains
executable statements.

✦ Don’t configure to support scripts and macros. Do not configure an external view to be any
application that supports scripts and macros, such as Excel and Word.

✦ Never blindly execute any program you download from the Internet. When possible,
download scripts as text and examine the code before running the script.

✦ Browse to safe places. A user’s risk of getting malcode and parasites can be greatly
reduced by avoiding hacker and underground sites.

✦Be conscious of the home page configuration. Every time you bring up the browser, which
for most people is every time they start their machine, some Web sites will know it. The
tracking of users in this manner is low risk. Consider setting the home page to be blank.

✦ Don’t trust links. Be suspicious of everything. Get into the habit of reading where the link
is before you blindly click.

✦Don’t follow links in e-mail. E-mail is easily spoofed, meaning the mail may not be coming
from the person on the From: line. A legitimate business, such as your bank, will not send an
e-mail to its clients and ask them to click to log in.

✦Avoid browsing from systems with sensitive data. If possible, use a less risky workstation
to browse the Internet. This less risky workstation should not have sensitive and private data
on it.

✦ Guard your information. If possible, don’t use personal information on the Web.

✦ Use stronger encryption. Choose 128-bit encryption over 56 or 40 bit.

✦ Use a less common browser. Because most hackers are trying to exploit Netscape and
Internet Explorer, some security can be gained by using another browser.

✦Minimize use of plugins. JavaScript, Java, and ActiveX all have vulnerabilities and should
be avoided, if possible.

✦Minimize use of cookies. Private or sensitive data might be extracted from a Web browser
through cookies.
✦ Be conscious of where temporary files are stored and how they are handled. These
temporary files may hold private and sensitive information. Make sure the files are not on a
shared directory. If possible, set the browser to clear the history of saved files and locations
visited to zero or one day. Learning about a user’s Web-browsing habits can be a valuable aid
in conducting a social engineering attack.

Web Security

Web security refers to the practices and technologies used to protect websites, web
applications, and data from cyber threats and unauthorized access.

 Protects data during transmission over the Internet.

 Safeguards websites, servers, users, and applications.

 Prevents data breaches, malware attacks, and hacking.

 Essential due to the increasing number of cyberattacks.

Web security is about keeping websites, servers, users, and devices safe
from cyberattacks that come through the internet. These attacks can include things like
viruses, fake emails (phishing), and other harmful activities that can steal or leak important
information.

To stay protected, web security uses different tools and methods, such as firewalls, systems
that block suspicious activity, filters that block dangerous websites, and antivirus software. It
also covers the security of Web Apps, APIs, and cloud systems to keep everything running
safely online.

In today’s digital world, web security is becoming increasingly important as cyber threats
grow more advanced and frequent. Attacks like phishing, ransomware, and IoT-based threats
can cause serious financial, reputational, and legal damage. To stay secure, organizations and
individuals must adopt modern security practices and technologies to protect data and ensure
safe operations.

 Cyber threats are increasing in complexity and frequency

 Attacks can cause financial, reputational, and legal damage

 Advanced technologies are required for protection

 Strong access controls help prevent unauthorized access


 Secure development practices ensure safer applications

Key Trends in Web Security

1. AI and Machine Learning in Cybersecurity

Artificial Intelligence (AI) and Machine Learning (ML) are transforming cybersecurity by
enabling real-time threat detection and automated response. These technologies analyze large
volumes of data to identify unusual patterns and predict potential attacks before they occur.

2. Zero Trust Security Model

The Zero Trust model operates on the principle of “never trust, always verify.” Every user,
device, and application must be authenticated and authorized before access is granted,
reducing the risk of unauthorized access and insider threats.

3. Secure DevOps (DevSecOps)

DevSecOps integrates security into every stage of the software development lifecycle. By
embedding security early in the process, organizations can identify and fix vulnerabilities
faster, reducing the risk of exploitation after deployment.

4. IoT Security

With the rapid growth of Internet of Things (IoT) devices, securing connected systems has
become essential. Proper IoT security measures help prevent devices from becoming entry
points for cyberattacks and protect the overall network infrastructure.

How HTTP works

HTTPS stands for HyperText Transfer Protocol Secure. It is the most common protocol for
sending data between a web browser and a website. HTTPS is the secure variant of HTTP
and is used to communicate between the user's browser and the website, ensuring that data
transfer is encrypted for added security.
HTTPS establishes the communication between the browser and the web server. It uses the
Secure Socket Layer (SSL) and Transport Layer Security (TLS) protocol for establishing
communication. The new version of SSL is TLS(Transport Layer Security).

 HTTPS uses the conventional HTTP protocol and adds a layer of SSL/TLS over it.

 The workflow of HTTP and HTTPS remains the same, the browsers and servers still
communicate with each other using the HTTP protocol.

 However, this is done over a secure SSL connection. The SSL connection is
responsible for the encryption and decryption of the data that is being exchanged to
ensure data safety.

 HTTPS is important because it keeps the information on websites safe from being
easily viewed or stolen by anyone who might be spying on the network.
 When a website uses regular HTTP, data is sent in small chunks called packets that
can easily be intercepted using free software.

 This makes communication, especially over public Wi-Fi, very vulnerable to attacks.

 On the other hand, HTTPS encrypts the data, so even if someone manages to intercept
the packets, they will appear as random, unreadable characters.

Secure Socket Layer (SSL)

The main responsibility of SSL is to ensure that the data transfer between the
communicating systems is secure and reliable. It is the standard security technology that
is used for encryption and decryption of data during the transmission of requests.

 HTTPS is basically the same old HTTP but with SSL.

 For establishing a secure communication link between the communicating devices,


SSL uses a digital certificate called SSL certificate.

Roles of the SSL layer

 Ensuring that the browser communicates with the required server directly.

 Ensuring that only the communicating systems have access to the messages they
exchange.

Encryption in HTTPS

HTTP transfers data in a hypertext format between the browser and the web server,
whereas HTTPS transfers data in an encrypted format. As a result, HTTPS protects
websites from having their information broadcast in a way that anyone eavesdropping on
the network can easily see.

 During the transit between the browser and the web server, HTTPS protects the data
from being accessed and altered by hackers.

 Even if the transmission is intercepted, hackers will be unable to use it because the
message is encrypted.

 It uses an asymmetric public key infrastructure for securing a communication link.


Keys for Encryption:

 Private Key: It is used for the decryption of the data that has been encrypted by the
public key. It resides on the server-side and is controlled by the owner of the website.
It is private in nature.

 Public Key: It is public in nature and is accessible to all the users who communicate
with the server. The private key is used for the decryption of the data that has been
encrypted by the public key.

Server and Client contents

In a web browser, the Client (the browser) renders and displays the website, while the Server
(the remote computer) stores and processes the data. The browser requests website files, and
the server responds by delivering the necessary code and assets to be interpreted and shown
on your screen.

The web experience relies on a clear division of labor between what executes locally and
what happens remotely.

Client-Side (Inside the Browser)

The client is your device running a web browser (e.g., Chrome, Safari). It acts as a receiver,
translator, and interactive engine for the user.

 HTML: The skeleton of the page. It dictates the structure and content (text, images,
links).

 CSS: The styling. It handles the colors, layouts, fonts, and responsiveness of the page.

 JavaScript: The interactivity. It runs directly in the browser to handle animations,


form validations, and dynamic updates without needing to reload the page.

 Browser Storage: Manages client-specific data such as local storage, session storage,
and cookies (used for maintaining login sessions or user preferences).

💻 Server-Side (Behind the Scenes)

The server is a remote computer (or network of computers) hosting the website's files
and databases. It waits for client requests, processes them, and sends back the correct
information.
 Databases: Stores persistent information (e.g., user accounts, product catalogs,
posts).

 Backend Code: Processes user input on the server, interacts with databases, and
dynamically builds HTML pages before sending them to the client (using languages
like [Link], Python, or PHP).

 APIs (Application Programming Interfaces): Bridges the client and server. The
client browser can request specific data from the server API, which returns just the
data (often in JSON format) without reloading the full page.

🔄 The Interaction Cycle

1. Request: You enter a URL or click a link. The browser sends an HTTP/HTTPS
request over the internet to the server.

2. Process: The server receives the request, runs any required logic, and retrieves the
necessary files or database records.

3. Response: The server sends an HTTP response back to the client, usually containing
the HTML, CSS, JavaScript, and media files.

4. Render: The browser's rendering engine interprets the code and displays the visual
webpage for you to use.

Let’s walk through exactly what happens when you interact with a web application, using the
example of posting a comment on a blog.

Step 1: User Action (Client)

You type your comment into a text box and click the “Post Comment” button. This triggers a
JavaScript event handler that captures your action.

Step 2: Client Preparation

JavaScript code on your browser validates your comment locally (checking it’s not empty,
perhaps ensuring it’s under a character limit), retrieves your authentication token from
browser storage (proving you’re logged in), constructs a data payload containing your
comment text, post ID, and timestamp, and prepares an HTTP POST request to send to the
server.

Step 3: HTTP Request Transmission


Your browser sends the request over the internet using the HTTP (HyperText Transfer
Protocol) or HTTPS (HTTP Secure) protocol. The request includes several components:

 Request Method – POST (indicating you’re creating new data)

 URL – The server endpoint like [Link]

 Headers – Metadata including content type (JSON), authentication tokens, and


accepted response formats

 Body – Your actual comment data in JSON format

Step 4: Network Journey

The request travels through multiple routers and networks across the internet. If using
HTTPS, the data is encrypted end-to-end, protecting it from eavesdropping. DNS (Domain
Name System) servers translate the human-readable domain name into an IP address so the
request reaches the correct server.

Step 5: Server Reception

The web server (like Nginx or Apache) receives your request, checks if it’s properly
formatted, routes it to the appropriate application server based on the URL path, and passes
along all request data.

Step 6: Server-Side Processing

The application server springs into action by authenticating your request using the provided
token, authorizing you to post comments (checking you’re not banned), validating your
comment content (checking for spam, profanity, proper length), sanitizing input to prevent
malicious code injection, inserting the new comment into the database, and preparing a
response confirming success.

Step 7: Database Interaction

The server communicates with the database to insert your new comment record including
your user ID, the comment text, timestamp, and post ID. The database confirms the operation
succeeded and returns the newly created comment with its unique ID.
Step 8: Response Preparation

The server formats a response, typically as JSON data containing the newly created comment
with its ID, timestamp, your username, and a success status code. It sets appropriate HTTP
headers for caching, content type, and security policies.

Step 9: Response Transmission

The server sends the HTTP response back through the internet to your browser. The response
includes a status code (200 for success, 201 for created, 400 for bad request, 401 for
unauthorized, 500 for server error) along with headers and the response body containing your
data.

Step 10: Client Processing

Your browser receives the response and JavaScript code parses the JSON data, updates the
page to display your new comment without refreshing, shows a success message, and may
make additional requests to load your user avatar or update comment counts.

This entire request-response cycle typically completes in 100-500 milliseconds, creating the
illusion of instantaneous interaction. The beauty of client-server communication is that it
happens seamlessly thousands of times during a typical browsing session without you ever
noticing.

Attacking Web servers

An attack on a web server refers to any malicious attempt to compromise the security,
integrity, or availability of a web-based host or its application infrastructure. Cybercriminals
target web servers to steal sensitive data, gain unauthorized remote control, or disrupt digital
operations.

Phase 1: Information Gathering & Reconnaissance

Attackers rarely strike blindly; they first systematically map the target.

 Scanning: Attackers map active hosts, open ports, and running services using tools
like Nmap.

 Banner Grabbing: Interrogating the server headers using curl or Netcat reveals the
exact server software and version (e.g., Apache, Nginx).
 Directory Enumeration: Automated tools search for hidden or poorly secured
directories, unlinked backup files, and exposed .git repositories.

Phase 2: Common Web Server Attack Vectors

Once a footprint is established, attackers exploit specific vulnerabilities within the operating
system, server software, or backend database.

[Attacker]

├──► Injection (SQLi, Command) ──► Database/OS Takeover

├──► Denial of Service (DDoS) ──► Server Resource Exhaustion

├──► Web Shell Upload ──────────► Persistent Remote Backdoor

└──► Directory Traversal ───────► Restricted System File Access

1. Injection & Malicious Scripting

 SQL Injection (SQLi): Attackers inject malicious SQL commands into vulnerable
user input fields. This tricks the backend database into bypassing authentication or
dumping credential records.

 Command Injection: If a server unsafely passes input directly to the operating


system, attackers execute commands to read, write, or delete arbitrary files.

 Web Shell Attacks: Threat actors exploit file upload vulnerabilities to plant a
malicious script (web shell) inside the directory. It functions as a permanent backdoor
for remote control.

2. Resource & Service Disruption

 DoS/DDoS Attacks: Attackers overwhelm the web server with high-volume traffic or
malicious request spikes to render the services completely slow or unresponsive.

 HTTP/2 Bomb: A highly efficient Denial-of-Service exploit discovered by Calif that


chains a variation of a compression bomb with a low-and-slow hold. It can take down
unpatched servers using minimal bandwidth.
3. Access Control & File Manipulation

 Directory Traversal: Attackers append sequences like ../ into URLs to break out of
the server's root directory and access configuration or system files.

 SSH / Port Brute Forcing: Attackers automate millions of credential combinations


on listening management ports to hijack administrative accounts.

Phase 3: Defensive & Mitigation Strategies

Securing a web server requires a multi-layered approach to reduce the attack surface.

 Input Validation: Rigorously sanitize all incoming parameters and enforce strict
allow-lists to stop injection flaws.

 Web Application Firewall (WAF): Deploy a WAF to filter out malicious payloads,
cross-site scripting (XSS), and automated bots.

 Patch Management: Frequently update operating systems, language frameworks


([Link], Python), and server applications to eliminate unpatched zero-day
vulnerabilities.

 Access Hardening: Move away from simple password authentication to SSH keys
and mandate multi-factor authentication (MFA) across infrastructure controls

Web Services

The Internet is the worldwide connectivity of hundreds of thousands of computers of various


types that belong to multiple networks. On the World Wide Web, a web service is a
standardized method for propagating messages between client and server applications. A web
service is a software module that is intended to carry out a specific set of functions. Web
services in cloud computing can be found and invoked over the network.
The web service would be able to deliver functionality to the client that invoked the web
service.

A web service is a set of open protocols and standards that allow data to be exchanged
between different applications or systems. Web services can be used by software programs
written in a variety of programming languages and running on a variety of platforms to
exchange data via computer networks such as the Internet in a similar way to inter-process
communication on a single computer.
Any software, application, or cloud technology that uses standardized web protocols (HTTP
or HTTPS) to connect, interoperate, and exchange data messages – commonly XML
(Extensible Markup Language) – across the internet is considered a web service.
Web services have the advantage of allowing programs developed in different languages to
connect with one another by exchanging data over a web service between clients and servers.
A client invokes a web service by submitting an XML request, which the service responds
with an XML response.

Functions of Web Services

 It's possible to access it via the internet or intranet networks.

 XML messaging protocol that is standardized.

 Operating system or programming language independent.

 Using the XML standard, it is self-describing.

 A simple location approach can be used to locate it.

Components of Web Service

XML and HTTP is the most fundamental web services platform. The following components
are used by all typical web services:

SOAP (Simple Object Access Protocol)

SOAP stands for "Simple Object Access Protocol." It is a transport-independent messaging


protocol. SOAP is built on sending XML data in the form of SOAP Messages. A document
known as an XML document is attached to each message. Only the structure of the XML
document, not the content, follows a pattern. The best thing about Web services and SOAP is
that everything is sent through HTTP, the standard web protocol.

A root element known as the element is required in every SOAP document. In an XML
document, the root element is the first element. The "envelope" is separated into two halves.
The header comes first, followed by the body. The routing data, or information that directs
the XML document to which client it should be sent to, is contained in the header. The real
message will be in the body.
UDDI (Universal Description, Discovery, and Integration)

UDDI is a standard for specifying, publishing and discovering a service provider's online
services. It provides a specification that aids in the hosting of data via web services. UDDI
provides a repository where WSDL files can be hosted so that a client application can
discover a WSDL file to learn about the various actions that a web service offers. As a result,
the client application will have full access to the UDDI, which serves as a database for all
WSDL files.
The UDDI registry will hold the required information for the online service, just like a
telephone directory has the name, address, and phone number of a certain individual. So that
a client application may figure out where it is.

WSDL (Web Services Description Language)

If a web service can't be found, it can't be used. The client invoking the web service should be
aware of the location of the web service. Second, the client application must understand what
the web service does in order to invoke the correct web service. The WSDL, or Web services
description language, is used to accomplish this. The WSDL file is another XML-based file
that explains what the web service does to the client application. The client application will
be able to understand where the web service is located and how to use it by using the WSDL
document.

The client would use requests to send a sequence of web service calls to a server that would
host the actual web service.
Remote procedure calls are what are used to make these requests. Calls to methods hosted by
the relevant web service are known as Remote Procedure Calls (RPC). Example: Flipkart
offers a web service that displays prices for items offered on [Link]. The front end or
presentation layer can be written in .Net or Java, but the web service can be communicated
using either programming language.
The data that is exchanged between the client and the server, which is XML, is the most
important part of a web service design. XML (Extensible markup language) is a simple
intermediate language that is understood by various programming languages. It is a
counterpart to HTML. As a result, when programs communicate with one another, they do so
using XML. This creates a common platform for applications written in different
programming languages to communicate with one another.
For transmitting XML data between applications, web services employ SOAP (Simple Object
Access Protocol). The data is sent using standard HTTP. A SOAP message is data that is sent
from the web service to the application. An XML document is all that is contained in a SOAP
message. The client application that calls the web service can be created in any programming
language because the content is written in XML.

Features/Characteristics Of Web Service

Web services have the following features:

(a) XML Based: The information representation and record transportation layers of a web
service employ XML. There is no need for networking, operating system, or platform binding
when using XML. At the middle level, web offering-based applications are highly
interoperable.

(b) Loosely Coupled: A customer of an internet service provider isn't necessarily directly
linked to that service provider. The user interface for a web service provider can change over
time without impacting the user's ability to interact with the service provider. A strongly
coupled system means that the patron's and server's decisions are inextricably linked,
indicating that if one interface changes, the other should be updated as well.
A loosely connected architecture makes software systems more manageable and allows for
easier integration between different structures.

(c) Capability to be Synchronous or Asynchronous: Synchronicity refers to the client's


connection to the function's execution. The client is blocked and the client has to wait for the
service to complete its operation, before continuing in synchronous invocations.
Asynchronous operations allow a client to invoke a task and then continue with other tasks.
Asynchronous clients get their results later, but synchronous clients get their effect
immediately when the service is completed. The ability to enable loosely linked systems
requires asynchronous capabilities.

(d) Coarse-Grained: Object-oriented systems, such as Java, make their services available
through individual methods. At the corporate level, a character technique is far too fine an
operation to be useful. Building a Java application from the ground, necessitates the
development of several fine-grained strategies, which are then combined into a rough-grained
provider that is consumed by either a buyer or a service.
Corporations should be coarse-grained, as should the interfaces they expose. Web services
generation is an easy approach to define coarse-grained services that have access to enough
commercial enterprise logic.

(e) Supports Remote Procedural Call: Consumers can use an XML-based protocol to call
procedures, functions, and methods on remote objects utilizing web services. A web service
must support the input and output framework exposed by remote systems.
Enterprise-wide component development Over the last few years, JavaBeans (EJBs) [Link]
Components have become more prevalent in architectural and enterprise deployments. A
number of RPC techniques are used to allocate and access both technologies.
A web function can support RPC by offering its own services, similar to those of a traditional
role, or by translating incoming invocations into an EJB [Link] component invocation.

(f) Supports Document Exchanges: One of XML's most appealing features is its simple
approach to communicating with data and complex entities. These records can be as simple as
talking to a current address or as complex as talking to an entire book or a Request for
Quotation. Web administrations facilitate the simple exchange of archives, which aids
incorporate reconciliation.
The web benefit design can be seen in two ways: (i) The first step is to examine each web
benefit on-screen character in detail. (ii) The second is to take a look at the rapidly growing
web benefit convention stack.

Advantages Of Web Service

Using web services has the following advantages:


(a) Business Functions can be exposed over the Internet: A web service is a controlled
code component that delivers functionality to client applications or end-users. This capability
can be accessed over the HTTP protocol, which means it can be accessed from anywhere on
the internet. Because all apps are now accessible via the internet, Web services have become
increasingly valuable. Because all apps are now accessible via the internet, Web services have
become increasingly valuable. That is to say, the web service can be located anywhere on the
internet and provide the required functionality.

(b) Interoperability: Web administrations allow diverse apps to communicate with one
another and exchange information and services. Different apps can also make use of web
services. A .NET application, for example, can communicate with Java web administrations
and vice versa. To make the application stage and innovation self-contained, web
administrations are used.

(c) Communication with Low Cost: Because web services employ the SOAP over HTTP
protocol, you can use your existing low-cost internet connection to implement them. Web
services can be developed using additional dependable transport protocols, such as FTP, in
addition to SOAP over HTTP.

(d) A Standard Protocol that Everyone Understands: Web services communicate via a
defined industry protocol. In the web services protocol stack, all four layers (Service
Transport, XML Messaging, Service Description, and Service Discovery) use well-defined
protocols.

(e) Reusability: A single web service can be used simultaneously by several client
applications.

E-mail security

Email is one of the most widely used communication tools in the world. We use it for work,
banking, online shopping, social media accounts and sharing important documents. But
cybercriminals also use email as their favorite target to spread malware, steal passwords,
launch phishing attacks and scam users.

 Technical stuff: Using tools like encryption (think of it as a secret code) to hide your
email’s content or filters to block junk emails.
 Smart habits: Learning to spot fake emails or creating super-strong passwords so no
one can sneak into your account.

Importance Of Email Security

Emails are like a playground for hackers. Here’s why you need to protect your inbox:

 Protection Against Phishing Attacks: Hackers create fake emails that appear to
come from trusted brands, banks or coworkers to steal credentials and sensitive data.

 Prevents Malware Infections: Malicious attachments and infected links can install
ransomware, spyware or trojans on your device.

 Safeguards Sensitive Information: Businesses and individuals send confidential


information through email every day. Without protection, this data can be intercepted.

 Protects Business Reputation: A compromised email account can send spam or


scams to customers and employees, damaging trust and credibility.

 Supports Compliance Requirements: Organizations must comply with privacy laws


and regulations like: GDPR, HIPAA, PCI-DSS ,Global Privacy Standards. Failure to
secure emails may lead to legal penalties and data breaches.

 Reduces Spam and Productivity Loss: Strong email filtering keeps inboxes clean
and helps users focus on legitimate communication.

Benefits of Email Security

 Blocks Phishing Emails: Advanced filtering systems detect suspicious emails before
they reach the inbox.

 Prevents Unauthorized Access: Strong authentication and encryption protect


accounts from hackers.

 Secures Sensitive Data: Encryption ensures private information stays confidential


during transmission.

 Detects Malware Early: Security systems scan attachments and links for malicious
content.

 Reduces Spam: Smart filters automatically identify and block junk emails.
 Protects Business Communication: Secure email systems prevent impersonation
and business email compromise (BEC) attacks.

 Enhances Privacy: Only authorized recipients can access protected messages and
attachments

E-mail Risks

Email risks include malicious software delivery, identity deception, and data exposure.
Cybercriminals exploit inboxes to distribute malware, steal credentials, and manipulate users
into financial transfers. Because email is a primary communication tool, it remains the most
common vector for targeted cyberattacks. [1, 2, 3, 4]

Top Email Security Threats

 Phishing & Spear Phishing: Deceptive emails mimicking trusted entities (e.g.,
banks, colleagues) designed to steal passwords or sensitive information. [1, 2]

 Business Email Compromise (BEC): Cybercriminals impersonate executives or


vendors to trick employees into authorizing fraudulent wire transfers or sending
confidential data. [1, 2]

 Malware & Ransomware: Emails containing malicious attachments or links that,


when clicked, install software to encrypt files or monitor keystrokes. [1, 2]

 Spoofing & Domain Impersonation: Attackers forge the sender's address to make
messages appear legitimate, increasing the likelihood of user compliance. [1, 2]

 Account Takeover (ATO): Unauthorized access to a legitimate email account,


allowing attackers to hijack existing threads or send spam to trusted contacts. [1, 2, 3]

 Data Exfiltration & Leaks: Sensitive company or personal data being intercepted in
transit or accidentally leaked by users sending it to unsecured external parties. [1, 2]

Best Practices for Protection

 Enable Multi-Factor Authentication (MFA): Adds a critical layer of defense against


account takeovers.

 Verify Sender Authenticity: Carefully check the actual sender address and look for
signs of social engineering before opening attachments or clicking links.
 Keep Software Updated: Ensure your operating system, browser, and antivirus
software are up to date to block known malware.

 Use Secure Connections: Use encryption to protect emails that contain highly
sensitive personal or financial information.

E-mail Protocols

Email protocols are standardized rules that control how emails are sent, received, and
accessed between mail clients and mail servers over the Internet.

 Enable communication between sender and receiver.

 Define how mail servers and email clients interact.

 Ensure reliable email delivery and access.

 Commonly used in services like Gmail and Outlook.

Three basic types of email protocols involved for sending and receiving mails are:

1. SMTP (Simple Mail Transfer Protocol)

Simple Mail Transfer Protocol is used to send mails over the internet. SMTP is an application
layer and connection-oriented protocol. SMTP is efficient and reliable for sending emails.
SMTP uses TCP as the transport layer protocol. It handles the sending and receiving of
messages between email servers over a TCP/IP network.

 Sends emails from sender to receiver using mail servers.

 Uses commands like HELO, MAIL FROM, RCPT TO, DATA to transfer messages.

 Identifies sender and receiver email addresses during communication.

 Notifies sender if email delivery fails.

 Considered reliable due to error reporting.

2. POP3 (Post Office Protocol)

Post Office Protocol is used to retrieve email for a single client. POP3 version is the current
version of POP used. It is an application layer protocol. It allows to access mail offline and
thus, needs less internet time. To access the message it has to be downloaded.
 POP allows only a single mailbox to be created on the mail server.

 POP does not allow search facilities

 Some of the POP commands are LOG IN, STAT, LIST, RETR, DELE, RSET, and
QUIT.

3. IMAP (Internet Message Access Protocol)

Internet Message Access Protocol is used to retrieve mails for multiple clients. There are
several IMAP versions: IMAP, IMAP2, IMAP3, IMAP4, etc. IMAP is an application layer
protocol. IMAP allows to access email without downloading them and also supports email
download.

 The emails are maintained by the remote server. It enables all email operations such
as creating, manipulating, delete the email without reading it.

 IMAP allows you to search emails. It allows multiple mailboxes to be created on


multiple mail servers and allows concurrent access.

 Some of the IMAP commands are: IMAP_LOGIN, CREATE, DELETE, RENAME,


SELECT, EXAMINE, and LOGOUT.

E-mail Authentication

Many email marketers may believe their email program is optimized and bulletproof,
especially if their performance is satisfactory. However, there could be danger lurking. There
are thousands of malicious agents hijacking domains daily. Spammers are growing more
sophisticated in their tactics, enabling them to mimic your domain to look more legitimate.
As a result, email experts created email authentication and validation standards. Without
sufficient email authentication, your brand is at much greater risk of damage.

Phishing scams and spam reaching your customers could be catastrophic, ranging from
reputation erosion to financial impact for your business or your customers. Email
authentication vulnerability is something many email marketers have little to no experience
with until it is actively causing harm.

Custom domain authentication

If you are using a domain outside of Gmail, AOL, and others, you need to ensure your
domain is protected to continue building and retaining your audience. Without the benefit of
authentication on your own domain, all your signals sent to mailbox providers (MBPs)
indicate the mail transfer agent (MTA) rather than the original sender.

Benefits of custom domain authentication

Domain authentication allows you to control your own email authentication destiny. You
don’t leave the authentication to your ESP or MTA. Instead, you can ensure the brand domain
itself is protected.

At the most basic level, properly authenticating your domain makes it more difficult for
malicious spoofing or hijacking of your brand’s identity. Using authentication in conjunction
with a custom domain requires bad actors to create a vanity URL to match and mimic your
domain. They don’t have the ease of simply mimicking a general domain like Gmail, which
requires little to no effort.

Do I need custom domain authentication?

The short answer is absolutely, yes. Without domain authentication, you’re risking brand
integrity because you’re leaving your brand vulnerable to spoofing and malicious attacks. By
actively protecting your property, you allow users to trust your brand and have a seamless,
safe experience across all activities, from log-in to email engagement. It’s a user experience
must, assuring your customers or visitors they’re safe providing log-in details or personal
information to a protected entity. If the domain changes when you click a link from an email,
it can lead to distrust and suspicions of spam.

The following email authentication information assumes the use of a custom domain.

How does email authentication work?


Email authentication is a collection of activities created to confirm and verify the identity of
an email sender. These techniques include Sender Policy Framework (SPF), DomainKeys
Identified Mail (DKIM), and Domain-based Message Authentication, Reporting &
Conformance (DMARC). By confirming the sender is who they claim to be, email
authentication is a key component of protecting both the brand and email recipients from
spoofing and phishing.

Email authentication provides several benefits. As a sender, you are no longer an easy target
for bad actors to hijack. This means you lower your chances of being spoofed or other
undesired uses of your brand name.

This protection extends to your mail recipients as well. You’re blocking as much spam and
dangerous mail to their inbox as you can. While you can’t fully inoculate subscribers from
phishing attempts, with email sender authentication you can be more confident your email
isn’t contributing to the problem.

Finally, you’re providing overall brand protection beyond email. Many high-profile
companies fell victim to email scams over the last few years. When email is successfully used
to extract customer information, your business could be responsible for monetary damages.
Beyond the financial impact, brand reputation, trust, and loyalty quickly erode without
consumer confidence.

Three primary email authentication methods

There are three core methods of email authentication methods: SPF, DKIM, and DMARC.
These are foundational and can be built upon with newer, more nuanced technologies.
Without employing DKIM and SPF, you cannot add the benefits of DMARC. This tiered and
layered approach multiplies the security of your domains and, consequently, your brand.

1. SPF

Sender Policy Framework, or SPF, is a basic email authentication technology. It’s simpler to
configure than several of the other steps you can take to authenticate email messages. Plus,
you’ll need a properly configured SPF record to allow implementation of other, more
complex technologies.

At its most basic level, SPF is used to prohibit email forgery. It involves code called an SPF
record, which is placed in the sender’s Domain Name Server (DNS). Your DNS record is
public, but only relevant to players in the email space. The record allows mail servers
receiving the mail to verify the content is truly from the sender.

If the server does not confirm the records match or detect there was manipulation in
transmission, the server can reject the message.

That being said, SPF is a relatively simple trust indicator and works better in tandem with
other, more secure email authentication methods. Put frankly, it’s a can’t-skip step in building
an effective email program.

2. DKIM / DomainKeys

Where SPF is a straightforward step toward security, DomainKeys Identified Messaging


(DKIM) is just as crucial but significantly more complex. DKIM requires a series of setup
steps and, later, several checks during message transmission.

A major differentiator from SPF, DKIM uses encryption. This involves building encryption
tokens for both the sent email and the receiving server. First, as a sender, you’ll need to
identify which components of your emails you want to use for verification. This could be the
entire message or just an element of the header. Once you determine this, you can encrypt
those portions. This is what will be checked to ensure there was nothing manipulated in
transmission from sender to receiver.

DKIM uses several “keys.” These keys include a pair of keys for encryption itself, a public
key living on your DNS, and a private key residing on your mail servers.

The receiver sees the DKIM signature, then does a DNS lookup to find the public key. It then
decrypts the key and creates its own hash of the information it sees. Finally, as the message
arrives at the MBP, it will verify both keys match. If it does, nothing was changed in
transmission as determined by the keypair match. At this point, the email message is
considered valid and is an additional data point for MBPs to consider when choosing to
deliver.

3. DMARC

Domain-based Message Authentication, Reporting & Conformance (DMARC) is the


finishing touch on a well-authenticated email program. This validation system detects and
prevents domain spoofing and phishing. Because DMARC leverages both SPF and DKIM, it
directs MBPs what exactly to do when both email authentication steps fail.
 p=none: Take no action at all.

 p=quarantine: Filter messages into a quarantine folder and do not deliver to the inbox.

 p=reject: Do not accept the mail to any box.

Beyond setting up the standard for full protection, it’s imperative to analyze and understand
the DMARC reports generated at each policy level. Additionally, you’ll need to have an
implemented DMARC policy to qualify to use BIMI, a new authentication standard being
adopted by some of the largest mailbox providers.

BIMI

The newest entry into the email authentication space is Brand Indicators for Message
Identification (BIMI). Although BIMI itself is not a means of email authentication, it aims to
drive adoption of strong sender authentication for the entire email ecosystem by requiring the
use of DMARC.

When set up, BIMI places a small graphic next to a sender’s From name, which is a vanity
name rather than the sender’s email address. Most companies select a version of their
recognizable logo to use as the graphic image. This visually reinforces your brand identity,
and provides reassurance for the recipient to trust the email message.

But BIMI isn’t readily available to any sender. Instead, the sender must implement the
recommended email authentication protocols. This is how it’s closely related to email
authentication but doesn’t necessarily provide any technical protection. Instead, it is a sign to
the recipient the mail is truly from the company rather than a spammer.

BIMI requires the use of a strict DMARC policy, which in turn requires SPF and DKIM.
While BIMI is more marketing-oriented for brand impressions, it’s a nice perk of being
thorough in your email authentication.

Other email authentication methods

While SPF, DKIM, and DMARC are the most commonly known and used email
authentication methods, there are a few other components available for use. These standards
are either deprecated or have not yet gained widespread support, but sometimes still surface
in discussions of email authentication. Familiarity with these email authentication methods
can help you determine their appropriateness for your program.
Sender ID

This email authentication tool operates similarly to SPF in which it is designed to identify
mismatched signals. By using Sender ID, the receiving server can detect if the incoming mail
is unauthorized. If the sending domain is not authorized to send the message, using the SPF
record published in the public DNS, Sender ID will catch it. ISPs do this check before
allowing an email to reach the intended recipient.

While Sender ID seems almost identical to SPF, they differ in how they detect fraud. How?
They each check different headers to perform different functions. Yet, because Sender ID
requires a published SPF record to operate successfully, it enhances the protection afforded
by SPF.

Sender ID codes are nuanced to indicate the type of issue detected, if there is any.

 Pass: Everything matches and the mail is clear for delivery.

 Neutral: The findings are inconclusive, so it doesn’t necessarily indicate fraud, but is
not clear enough to pass.

 Soft fail: The purported responsible address (PRA)’s signals don’t match, but there’s
only evidence the IP might not exist.

 Fail: The IP address is definitively not permitted. Either there is no PRA incoming at
all or the sender domain isn’t real.

 None: There’s simply no SPF data published in the sender’s DNS.

 TempError: The DNS failed but it’s temporary, due to an unavailable DNS server or
similar.

 PermError: There is an error not related to a temporary problem, and instead the DNS
record has something truly wrong, such as a record format error.

ADSP

Author Domain Signing Practices (ADSP) can be used as an extension to DKIMto


authenticate emails. This allows relaying domains to publish the signing practices it uses on
behalf of senders. This isn’t much to worry about from the sender side of email, but you
should be familiar with how your ESP is handling your mail.

VBR
Independent or third-party certification providers can use Vouch by Reference (VBR) to
verify sender reputations. These signals can be added by an MTA, email client or third
parties. VBR provides a marker the email is trustworthy.

iprev

An IP reverse lookup simply confirms an IP’s DNS is properly configured. It doesn’t


necessarily indicate trustworthiness, so it shouldn’t be used as a means of email sender
authentication but it does note whether or not the record is valid.

DNSWL

Safe lists are sometimes used to automatically flag a sender as safe. Historically, they’ve been
called “whitelists.” A DNSWL is an “allow-list” with a lookup to identify a sender’s
trustworthiness. Your domain’s inclusion on a list makes it simpler to check the veracity of
your messages.

Operating safely when using email

Operating safely when using email requires protecting your account with strong
authentication, actively verifying the sender’s identity to avoid phishing scams, and never
clicking unknown links or downloading unexpected attachments. Always avoid sending
sensitive information like passwords or financial details via email.

Essential practices to keep your email secure include:

Account Security

 Enable Two-Factor Authentication (2FA): Also known as 2-Step Verification, this


adds an extra layer of defense so even if your password is stolen, hackers cannot
access your account.

 Use Unique Passwords: Never reuse your email password for other websites. Use a
trusted password manager like Google's Password Manager to create and store
complex combinations securely.

Phishing and Scam Awareness

 Verify the Sender: Always double-check the sender's email address, not just the
display name. Scammers often use look-alike domains with subtle misspellings.
 Hover Before Clicking: Hover your mouse over any web link to preview the actual
destination URL before clicking it.

 Avoid Unsolicited Attachments: Never open attachments or enable macros in files


from unknown senders or unexpected emails, as they often contain malware.

Privacy and Data Handling

 Beware of Public Wi-Fi: Avoid accessing or sending emails containing sensitive data
while connected to unprotected public Wi-Fi networks.

 Never Email Confidential Data: Avoid sending social security numbers, bank
details, or passwords through email. Legitimate organizations will never ask you to
provide this information via email.

 Log Out: Always lock your device or log out of your email account when leaving
your computer unattended.

If you're interested, I can share actionable steps on:

 Setting up Two-Factor Authentication (2FA) for your specific email provider.

 Recognizing specific red flags in phishing emails.

 Generating strong, memorable password

Domain Name System

Translation of human-readable domain names into IP addresses enables computers to


communicate over the internet, a function performed by the Domain Name System (DNS),
which operates in a hierarchical and distributed manner while improving performance
through caching.

 Provides name-to-address resolution using a hierarchical system (Root, TLD,


Authoritative servers) to locate domain information.

 Improves performance by using caching mechanisms, reducing lookup time for


repeated requests.

DNS process can be broken down into several steps, ensuring that users can access websites
by simply typing a domain name into their browser.
 User Input: The user enters a domain name (e.g., [Link]) in the
browser.

 Local Cache Check: The browser or OS checks its cache for a stored IP address.

 DNS Resolver Query: If not found, the request is sent to a DNS resolver (usually by
ISP).

 Root Server Query: The resolver queries a root server, which points to the correct
TLD server.

 TLD Server Response: The TLD server directs the resolver to the domain’s
authoritative server.

 Authoritative Server Response: The authoritative server returns the actual IP


address.

 Final Response: The resolver sends the IP back to the user, and the browser connects
to the server.

Structure of DNS

The structure of DNS is hierarchical in nature, enabling scalable and organized domain name
resolution across the global Internet.

1. Root

The topmost level of the DNS hierarchy.

 Represented by a dot (.) at the end of a domain name

 Acts as the starting point of domain resolution

2. Top-Level Domains (TLDs)

The level directly below the root that defines domain extensions.

 Includes extensions like .com, .org, .net, .edu

 Helps categorize domains by purpose or region

3. Second-Level Domains

The main domain name registered by an organization.


 Appears before the TLD (e.g., "example" in [Link])

 Uniquely identifies a domain under a TLD

4. Subdomains

Extensions of the main domain used for organization.

 Examples: www, mail, blog

 Helps structure different parts of a website

5. Hostnames

Identifies specific servers or devices within a domain.

 Examples: web1, mailserver, ftp

 Maps to actual IP addresses using DNS records

Types of Domains

DNS categorizes domain names into different types to organize the global naming system and
support both forward and reverse resolution.

1. Generic Domains (gTLDs)

These domains are used for general purposes and are not tied to any country.

 Include extensions like .com, .org, .net.


 Not restricted to any specific country

 Used for commercial, organizational, and educational purposes

2. Country Code Domains (ccTLDs)

These domains represent specific countries or geographic regions.

 Examples: .in (India), .us (USA), .uk (UK), .jp (Japan)

 Managed by respective national authorities

3. Reverse DNS

These domains are used to map IP addresses back to domain names.

 Used for reverse lookup (IP address -> domain name)

 IPv4 uses [Link]

 IPv6 uses [Link]

 Uses PTR (Pointer) records

Domain Name Server

Responsible for storing DNS records and answering queries to resolve domain names into IP
addresses, this function is performed by a Domain Name Server.

 Stores DNS records such as A, AAAA, MX, CNAME, NS, and PTR.

 Responds to queries from clients or other DNS servers.

 Operates within the hierarchical DNS structure.

 Can perform either recursive or authoritative functions.

 Enables communication between users and web servers by supplying necessary DNS
data.

DNS Lookup

Also known as DNS Resolution, is the process of converting a domain name into its
corresponding IP address so that a device can establish communication with the target server.

Key Components
The key components of DNS work together to resolve domain names into IP addresses
efficiently.

1. DNS Resolver: Starts the DNS lookup process and acts as an intermediary between client
and DNS servers.

 Initiates the DNS query from the client side.

 Forwards requests to appropriate DNS servers to get the IP address.

2. Recursive Query: A query where the resolver fetches the complete answer on behalf of the
client.

 Resolver performs full lookup across multiple DNS servers if needed.

 Returns the final IP address or an error to the client.

3. Iterative Query: A query where the server provides the best information it has or a
referral.

 Returns partial response or points to another DNS server.

 Helps the resolver move step-by-step toward the final answer.

4. Non-Recursive Query: A query where the answer is already available in cache or


authoritative server.

 Response is returned immediately without further lookup.

 No additional DNS server communication is required.

DNS Caching

Technique that temporarily stores DNS records to reduce repeated queries and improve
resolution efficiency.

 Stores previously resolved domain records locally.

 Reduces response time for future requests.

 Minimizes load on external DNS servers.

 Improves overall network performance.

TTL (Time-to-Live)
TTL defines the duration for which a DNS record is considered valid in cache.

 Specifies how long a DNS record remains stored in cache.

 Defined by the authoritative DNS server.

 Measured in seconds.

 After expiration, a new DNS lookup is required.

Example: If the TTL value is 3600 seconds, the record remains cached for one hour before it
must be refreshed.

Reverse DNS Lookup

Reverse DNS Lookup is the process of resolving an IP address to its associated domain name,
performing the opposite function of standard DNS resolution.

 Converts an IP address into a domain name.

 Uses special domains such as [Link] (IPv4) and [Link] (IPv6).

 Relies on PTR (Pointer) records for mapping.

Reverse DNS is commonly used for:

1. Network Diagnostics

Helps in analyzing and troubleshooting network issues.

 Helps administrators identify the domain linked to a specific IP address.

 Assists in traffic analysis and troubleshooting.


2. Email Security

Ensures emails are sent from legitimate sources.

 Used by mail servers to verify sender authenticity.

 Helps reduce spam and fraudulent email activity.

DNS Record Types

Different DNS record types are used to store specific information about a domain.

 A Record: Maps a domain name to its corresponding IPv4 address.

 CNAME Record: Creates an alias that points one domain name to another domain
name.

 MX Record: Specifies the mail server responsible for receiving emails for a domain.

 TXT Record: Stores text information used for verification and email authentication
purposes.

Security Issues with DNS

The Domain Name System (DNS) is often called the "phonebook of the internet," but
because it was built without security in mind, it is highly vulnerable to interception,
manipulation, and denial-of-service attacks. Understanding these risks is vital for protecting
networks and sensitive user data.

1. DNS Spoofing & Cache Poisoning

 What it is: Attackers inject fake IP addresses into a DNS resolver’s cache.

 The impact: Users typing legitimate URLs are silently redirected to fraudulent
websites (e.g., fake banking pages) designed to steal credentials.

2. DNS Hijacking

 What it is: Malicious actors physically alter the DNS settings on a user's local router
or take control of the authoritative DNS servers for a domain.

 The impact: Traffic is permanently diverted to attacker-controlled servers, enabling


widespread phishing campaigns or state-level censorship.

3. DDoS & Amplification Attacks


 What it is: Attackers flood a DNS server with a massive volume of requests or abuse
open resolvers using spoofed IP addresses.

 The impact: The DNS server crashes or becomes overwhelmed, making the websites
relying on it completely inaccessible to legitimate users.

4. DNS Tunneling

 What it is: Attackers encode malicious data (such as stolen passwords) or command-
and-control instructions directly into standard DNS queries.

 The impact: Because many firewalls do not inspect DNS traffic closely, attackers can
covertly exfiltrate sensitive information.

5. Eavesdropping

 What it is: Unencrypted DNS queries are broadcast in clear text, meaning ISPs,
network admins, or hackers can easily see every website you try to visit.

 The impact: Severe loss of user privacy and susceptibility to targeted network
surveillance.

How to Mitigate DNS Security Issues

 DNSSEC: Adds cryptographic digital signatures to DNS records so that resolvers


can verify the data is authentic and not tampered with.

 DoH / DoT: Utilizes DNS over HTTPS (DoH) or DNS over TLS (DoT) to encrypt
DNS queries, preventing eavesdropping and tampering.

 Secure DNS Resolvers: Switch to reliable, security-focused public DNS services like
Cloudflare ([Link]) or OpenDNS ([Link]).

DNS Attacks

1. Denial of service (DoS): An attack where the attacker renders a computer useless
(inaccessible) to the user by making a resource unavailable or by flooding the system
with traffic.

2. Distributed denial of service (DDoS): The attacker controls an overwhelming


amount of computers (hundreds or thousands) in order to spread malware and flood
the victim's computer with unnecessary and overloading traffic. Eventually, unable to
harness the power necessary to handle the intensive processing, the systems will
overload and crash.

3. DNS spoofing (also known as DNS cache poisoning): An attacker will drive the
traffic away from real DNS servers and redirect them to a "pirate" server,
unbeknownst to the users. This may cause the corruption/theft of a user's personal
data.

4. Fast flux: An attacker will typically spoof his IP address while performing an attack.
Fast flux is a technique to constantly change location-based data in order to hide
where exactly the attack is coming from. This will mask the attacker's real location,
giving him the time needed to exploit the attack. Flux can be single or double or of
any other variant. A single flux changes the address of the webserver while double
flux changes both the address of the web server and the names of DNS serves.

5. Reflected attacks: Attackers will send thousands of queries while spoofing their own
IP address and using the victim's source address. When these queries are answered,
they will all be redirected to the victim himself.

6. Reflective amplification DoS: When the size of the answer is considerably larger
than the query itself, a flux is triggered, causing an amplification effect. This
generally uses the same method as a reflected attack, but this attack will overwhelm
the user's system's infrastructure further.

Measures against DNS attacks:

1. Use digital signatures and certificates to authenticate sessions in order to protect


private data.

2. Update regularly and use the latest software versions, such as BIND. BIND is open-
source software that resolves DNS queries for users. It is widely used by a good
majority of the DNS servers on the Internet.

3. Install appropriate patches and fix faulty bugs regularly.

4. Replicate data in a few other servers, so that if data is corrupted/lost in one server, it
can be recovered from the others. This could also prevent single-point failure.

5. Block redundant queries in order to prevent spoofing.


6. Limit the number of possible queries.

WAP Gateway

The term WAP Gateway in DNS refers to how cellular networks route legacy mobile internet
traffic (Wireless Application Protocol) to the open web. Mobile carriers use specialized DNS
configurations to automatically direct subscriber requests to a carrier-hosted WAP
proxy/gateway.

How the Process Works

1. The Request: When a legacy mobile device attempts to load a website, the request is
packaged into compact, encoded WAP protocols.

2. DNS Resolution: The mobile network's DNS server intercepts the URL and points it
toward the carrier's specific WAP Gateway IP address, rather than directly to the web
server.

3. Translation: The WAP Gateway acts as a proxy. It translates the encoded wireless
protocols into standard HTTP/HTTPS and sends the request to the target web server.

4. Response: The gateway receives the web page data, compresses/compiles it into a
mobile-friendly format (like WML), and sends it back to the phone.

WAP DNS Architecture (Wireless Profiled DNS)

To optimize DNS lookups for bandwidth-constrained devices, the Open Mobile Alliance
(OMA) designed a specific extension called Wireless Profiled DNS (WP-DNS).

 Header Compression: It optimizes domain name strings to consume less airtime.

 Caching: It defines rules for how WAP gateways and mobile terminals cache DNS IP
addresses to reduce radio traffic.

You might also like