Font size
Worksheets2.3 Server Exploits Review
Total questions: 55
Worksheet time: 29mins
When programming a webpage, JavaScript is used to
Make sure the graphics are laid out well
Add forms to pages (like when you place an order)
Speed up the transmission of data
add logic to a web page & make it interactive
When programming a web page, HTML is used for
to provide the highest level of security
organize the content on the page
determine who can access each page
create a log of the users activity on the page
Which tags in this code are JavaScript
<html> </html>
<script> </script>
<body> </body>
<p> </p>
XSS stands for
Extra Security System
Cross-site scripting
Extra Social Security
Cross-system Surveilance
Which of the following is NOT something hackers use Cross-site scripting for.
steal data
instigate a ping attack
take control over a computer
run malicious
How do hackers get the cross-site script onto another machine
Hidden in a photo of a webpage
Part of a downloadable file
Executed when a button is pressed on webpage
inserted into the web pages input fields
When working in Cybersecurity Training Site (CTS), what were the levels of security available to test. Check all that apply.
sub par
low
medium
high
Which of the SQL lines of code, provide a low level of security for an input field?
Which section of SQL, preforms a data cleanse on the input the user typed into a form on a web page?
Sec 1
Sec 2
Sec 3
What is the purpose of data cleansing?
Make sure all data in a data base is correct and up to date
Cleaning up data that is about to be displayed on a web page
Removing scripting tags entered onto a web page by a user
Removing incorrect data a user enters into a form on a web page
How does a cross-site scripting exploit change a web page?
By executing JavaSript that runs in the browser.
By making the HTML look different.
By changing data in the database.
By executing JavaScript that runs on the server.
How does a hacker exploit a website using SQL injection?
By using SQL code to modify data.
By using SQL code to view unauthorized data.
By using SQL code to delete data.
All of the above.
When we played the Routing Game, what were we re-enacting?
The paths internet traffic will flow when the internet is busy
The simulation of packets of data getting lost on the internet
The path a ping attack forces web pages to follow to get displayed
The simulation of network traffic, sending packets of data between hosts and routers
What is WireShark used for?
Monitoring the migration path of sharks
Monitoring and analyzing network traffic
Analyzing the amount of valid and invalid traffic on a network
Trolling the internet looking for malicious activities
What is a ping in Cybersecurity
A radar tone from submarine to measure the distance to another object
A notification sent to a cybersecurity expert to alert them of to activities that are suspicious
A method of checking the status of a host server
A game played with a tiny white ball.
Which of the following are actual panes in WireShark? Choose all that are correct.
Packet Detail
Packet Bytes
Packet Translation
Packet List
What pane if the pane highlighted in purple
Packet List
Packet Detail
Packet Bytes
A piece of software or a sequence of commands that takes advantage of a vulnerability in a computer system to cause unexpected behavior to occur.
Passive Analysis
Security Balance
Inetpub
exploit
Refers to the action of watching and analyzing network traffic
Back-end
Packet Sniffer
DDos
Exploit
The buying and selling of goods or services over the internet
HTML
Passive Analysis
E-commerce
SQL Injection
Confidentiality, Integrity and Availability
TLS
CIA Triad
IEEE
NIC
The first half of the MAC address, designating the manufacturer of the network device.
OUI
TLS
DDOS
SQL
Access systems without permission—but then share their findings and report problems they find
Inetpub
Protocol
Gray-hat Hacker
SQL
Used for retrieving and manipulating data in a database.
SQL
SQL Injection
HTML
Router
Used to organize the content on a web page
Exploit
TLS
OUI
HTML
Analyze something without interfering or affecting it
Protocol
Gray-hat Attacker
Passive Analysis
Exploit
The buying and selling of goods or services over the internet.
Bank-end
Passive Analysis
CIA Triad
ecommerce
contains all the web pages and content that will be published on the web.
Inetpub
HTML
SQL
Protocol
A network device that controls and filters data between networks, either wired or wireless.
Packet_Sniffer
Router
Server
Security Baselin
A three-way communication method using SYN (synchronize), SYN-ACK (synchronize=acknowledge), and ACK (acknowledge) to establishing a connection between hosts.
MAC Address
TCP Handshake
SMTP
DDoS
Data that is stored in a specialized table format. It contains addresses of known networks (other routers), ones that have already been discovered and used. When a new, unknown network destination is discovered, the router will update its routing table.
IP Address Table
MAC Address Table
Routing Table
Master Router
Helps you organize and manage data packets so you can monitor and analyze network traffic
Packet Tracer
Wireshark
ICMP
Packet Filtering
A way for a computer to communicate with all hosts on a network using one message - often used when a computer needs to find a host
TCIP
Broadcasting
Routing
A Wireshark data capture file that contains packet information of network traffic.
Pcap File
Text file
Ping file
Broadcast file
Used to check the status of a host
ipconfig
netstat
ping
websearch
An addresses that is a unique numeric code that is assigned to networking hardware components (typically a network interface card or NIC) that is built into computers and mobile devices. The code is assigned by the manufacturer, includes their unique identification number, and never changes.
MAC Address
IP Address
Ping Address
127.0.0.0
Added security measures that recognize any scripting tags entered by a user, treated as plain text or deletes them completely from the user input, removing any of their functionality
Packet Sniffer
CRUD
Java
Data cleansing
Used to add logic to a web page and make it interactive
Java
Python
HTML
JavaScript
a type of exploit in which the attacker takes advantage of an interactive web page to insert malicious client-side code into it
Ping Attack
Malware
Forced Browsing
Cross-site scripting (XSS)
The software that experts identify suspicious network traffic such as invalid data requests, packets from suspicious sources, and suspicious content.
Powershell
Wireshark
FTP
Server Manager
What is the destination IP Address of each ping request?
323/16897
172.30.0.6
1.01619
172.30.0.13
What is the source IP Address of each ping reply?
323/16897
172.30.0.6
1.01619
172.30.0.13
When working in Wireshark, what can the timestamp of a packet tell you?
When a hacker performed an SQL Injection
When a packet is sent through a router.
When the web server is to shut down.
When a log file was created.
In the address: 0a:61:89:59:4d:0c
what is the MAC address of the destination host?
0a:61:89
59:4d:0c
0a:61:89:59
89:59:4d
In the following Linux command what does the -f stand for:
ping -f -i 0 -s 4000 172.30.0.6
factory
flood
flash
firewall
In the following Linux command what does the -i stand for:
ping -f -i 0 -s 4000 172.30.0.6
ifcong
IP address
interval
interrupt
A part of a process or system that is seen by the user and typically provides functionality to the user.
Back end
Front Page
Front End
Workspace
A part of a process or system that is not seen by the user. It provides a supporting function on behalf of the main process.
Back end
Front Page
Front End
Workspace
What do we use MAC addresses for?
Find the manufacturer of a device
Find the IP address of a server
Know what time a attack took place
Know what type of computer the attack is coming from.
Finding the MAC address had a legitimate OUI indicates that the address is valid and is proof that this is malicious activity.
True
False
Why would a server use the broadcast feature?
To announce it is available
To find the best route to another server
To send error messages
To communicate to all hosts on a network.
For packet 1 what is the MAC address for the source of this packet.
(a)
Who is the client in a network?
A device that is requesting information or services from a server
A device that provides information and services over a network
A router that sends requests for information or services
A devices that directs traffic on a network.
What type of number system is represented by MAC address: 00:22:fa:1c:eb:e6
Binary
Hexadecimal
Decimal
The first three pairs of the MAC address are called the ___?
NIC
OUI
CIA
HEX
