15.01.2024 Views

CompTIA A+ Certification All-in-One Exam Guide

  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

this gambit, the attacker first learns the account name of a legitimate person

in the organization, usually using the infiltration method. The attacker then

calls someone in the organization, usually the help desk, in an attempt to

gather information, in this case a password.

Hacker: “Hi, this is John Anderson in accounting. I forgot my

password. Can you reset it, please?”

Help Desk: “Sure, what’s your user name?”

Hacker: “j_w_anderson.”

Help Desk: “OK, I reset it to e34rd3.”

Telephone scams certainly aren’t limited to attempts to get network

access. There are documented telephone scams against organizations aimed at

getting cash, blackmail material, or other valuables.

Phishing

Phishing is the act of trying to get people to give their user names,

passwords, or other security information by pretending to be someone else

electronically. A classic example is when a bad guy sends you an e-mail

that’s supposed to be from your local credit card company asking you to send

them your user name and password. Phishing is by far the most common

form of social engineering done today.

Phishing refers to a fairly random act of badness. The attacker targets

anyone silly enough to take the bait. Spear phishing is the term used for

targeted attacks, like when a bad guy goes after a specific celebrity. The

dangerous thing about spear phishing is that the bait can be carefully tailored

using details from the target’s life.

Denial of Service

A denial of service (DoS) attack uses various methods to overwhelm a

system, such as a Web server, to make it essentially nonfunctional. DoS

attacks were relatively common in the early days of the Web. These days

you’ll see distributed denial of service (DDoS) attacks that use many

machines simultaneously to assault a system.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!