Cyber Security
🔒 Log in to trackCyber attacks and social engineering
🔒 Log in to trackAttacks are methods used to cheat people or to break services. Some target people, such as phishing, vishing and smishing. Some target services, such as DoS, DDoS and man-in-the-middle. Other named attacks include salami, data diddling, logic bomb, SQL injection and brute force.
Two groups of attacks
Group every attack by its target. Some attacks target people. Others target services.
Attacks on people
- Phishing: a fake mail or site that looks like your bank. It asks for passwords, OTPs or card details. Think of fishing with bait.
- Spear phishing: phishing aimed at one person or one office, using personal details.
- Vishing: phishing by voice, a phone call.
- Smishing: phishing by SMS.
- Pharming: you type the correct address, yet a fake site opens. The attacker has tampered with the DNS or the server.
- Social engineering: tricking people through fear, urgency or authority. It attacks the person, not the code.
Tip: Phishing needs the user to be fooled. Pharming does not.
Attacks on services
- DoS (Denial of Service): a flood of useless requests so real users cannot get in.
- DDoS (Distributed DoS): the flood comes from many machines at once, often a botnet.
- Man-in-the-Middle (MITM): the attacker sits between two parties and reads or changes what they send. Open Wi-Fi is a common setting.
- Eavesdropping: passive listening to data as it travels.
- Sniffing: capturing network packets to read them.
- Spoofing: pretending to be someone else, such as a fake sender address.
Named attacks
| Attack | Idea |
|---|---|
| Salami attack | Steals tiny amounts from very many accounts. Hard to notice |
| Data diddling | Changes data before or while it is entered |
| Logic bomb | Code that waits for a trigger, then acts |
| SQL injection | Types database commands into a web form to read the database |
| Brute force | Tries every possible password until one works |
Telling the look-alikes apart
- Phishing asks the user to hand over data. Pharming hijacks the address itself.
- DoS drowns the server. MITM listens in the middle of a real conversation.
- Salami steals small amounts often. Data diddling alters records.
- A logic bomb waits for a trigger.
Rule: The word "distributed" means many sources. DDoS is the flood from many machines.
Example: A bank clerk shaves a few paise off thousands of accounts. That is a salami attack.
Question types you will see
Each type: how to recognise it, the method step by step, and one question to try.
Phishing family
The scenario describes a fake mail, call, SMS or site that asks for private data.
Check the delivery: mail, voice, SMS or site.
Mail is phishing, voice is vishing, SMS is smishing.
A fake site despite a correct address is pharming.
The family shares one aim, and only the channel differs.
Which attack sends a fake SMS to trick a user into giving bank details?
Show solutionHide solution
The channel is SMS.
Phishing by SMS is smishing.
Smishing
DoS and DDoS floods
A server is overwhelmed and real users cannot get in.
Spot the words flood, overload or unavailable.
One source is DoS.
Many machines, often a botnet, is DDoS.
The flood denies the service to real users.
An attack that floods a server from thousands of infected machines is a:
Show solutionHide solution
The flood comes from many machines.
That is the distributed form.
DDoS attack
Man-in-the-Middle and eavesdropping
Someone secretly reads or changes messages between two parties.
Spot the words between, intercept or open Wi-Fi.
Reading and changing is MITM.
Only listening is eavesdropping.
The attacker sits in the middle of a real chat.
An attacker secretly sits between a user and a website and reads the traffic. This is:
Show solutionHide solution
The attacker is between two parties.
That is MITM.
Man-in-the-Middle attack
Classic named attacks
The question gives a special detail such as tiny amounts, a trigger, or a web form.
Tiny amounts from many accounts is salami.
Data changed during entry is data diddling.
A trigger date is a logic bomb.
Commands in a form is SQL injection.
Each named attack has one memorable trick.
A program deletes files on 1 January of a given year, and stays silent until then. It is a:
Show solutionHide solution
It waits for a date.
A date trigger means a logic bomb.
Logic bomb
Brute force and password guessing
An attacker tries many passwords until one works.
Spot the words every combination or many guesses.
Name it brute force.
Long and mixed passwords slow it down.
A longer password has far more combinations to try.
Trying every possible password until the right one is found is called:
Show solutionHide solution
Every option is tried.
The method uses force, not trickery.
Brute force attack
Shortcuts that save time
Vishing uses voice calls. Smishing uses SMS. Both are phishing with a different bait.
A fraudster phones you pretending to be from your bank and asks for your OTP. This is:
Show solutionHide solution
The bait is a phone call.
Phishing by voice is vishing.
Vishing
In pharming you type the right address and still reach a fake site. The address system was tampered with.
Mistakes to avoid
Where most students lose marks on this subtopic.
Calling a DoS attack a virus.
DoS is a flood of requests. It is an attack, not malware.
Saying pharming needs the user to click a bad link.
Pharming sends you to a fake site even if you type the right address.
Confusing DoS and DDoS.
DDoS comes from many machines at once.
Thinking MITM floods the server.
MITM sits between two parties and listens or changes messages.
Mixing salami with data diddling.
Salami steals tiny amounts. Data diddling changes data during entry.
Quick revision
Read this the night before the exam.
Phishing is mail bait. Vishing is voice. Smishing is SMS. Pharming is a fake site despite a correct address.
Spear phishing targets one person or office.
DoS floods a server. DDoS floods from many machines, usually a botnet.
MITM listens between two parties. Eavesdropping is passive listening.
Salami takes tiny sums from many accounts. Logic bomb waits for a trigger.
SQL injection puts commands in a web form. Brute force tries every password.
Social engineering attacks the person, not the machine.
Practice: 20 questions
Sets of 10, mixed across the question types above. Every answer has a step-by-step explanation.
Topic test · 10 questions
Suggested time 5 min · wrong answers go to your mistake notebook automatically.