Security
  Home arrow Security arrow Page 4 - What’s behind the curtain? Part II
Dev Shed Forums 
Administration  
Apache  
BrainDump  
DHTML  
Flash  
Java  
JavaScript  
Multimedia  
MySQL  
Oracle  
Perl  
PHP  
Practices  
Python  
Reviews  
Security  
Style-Sheets  
Web Services  
XML  
Zend  
Zope  
Forums Sitemap 
IBM® developerWorks 
Dedicated Servers 
E-Commerce Hosting 
Linux Web Hosting 
Managed Hosting 
Small Business Hosting 
Download TestComplete 
VPS Hosting 
Weekly Newsletter

 
Developer Updates  
Free Website Content 
IBM Developerworks
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
SECURITY

What’s behind the curtain? Part II
By: Eliana Stavrou
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 4 stars4 stars4 stars4 stars4 stars / 7
    2005-02-28

    Table of Contents:
  • What’s behind the curtain? Part II
  • Denial of service (DoS) attack
  • Password cracking attack
  • Social engineering attack
  • Conclusion

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
     
    ADVERTISEMENT

    TestComplete™ automates software testing for a fraction of what the big guys charge. Easy functional and load testing for all Windows, .NET, Java and Web apps. Download a free trial now.

    What’s behind the curtain? Part II - Social engineering attack
    (Page 4 of 5 )

    Social engineering is used by hackers to break the trust users place in other people and reveal sensitive information, such as their password. Usually, the cracker tries to gain the confidence of a user in an attempt to compromise the network’s and systems’ security. The cracker can accomplish his purpose by sending email to legitimate users, claiming to be the administrator and asking the users to send him their password to perform an urgent administration work.

    The cracker relies on the ignorance of the user to provide him this kind of information; many times people do not think about the value of the information they possess and are careless about protecting it. Another technology through which crackers use social engineering is the phone, as they call the victims to try to find out what they want.

    Another social engineering method is called “shoulder surfing.” The “shoulder surfing” method can be used by anyone, even your co-worker. The main characteristic of this method is that someone looks over your shoulder while you type in your password. So be careful when providing your password with people around.

    Packet Sniffing attack

    Crackers usually use tools such as a packet sniffer to grab information traveling on a network running protocols such as Ethernet and TCP/IP. Sniffing is a passive attack that only reads the data on the network link without altering anything. Sniffing programs are used to steal passwords, read emails and other sensitive information.

    When using a packet sniffer to listen to the communication link, the cracker's NIC card is set to promiscuous mode to watch over any packet that travels on the link you are already using. When there is activity on the link, the sniffer reports it in real time as soon as it detects it.

    Usually, the cracker doesn’t need to put a big effort into using these tools. All he needs to focus on is the interpretation of the data provided by the tool, which usually requires only a good knowledge of networking issues and TCP/IP.

    These tools are also used by the good guys, i.e. the administrator, to monitor the network and report problems and vulnerabilities in order to fix them before someone takes advantage of them.

    Keep in mind that firewalls don’t prevent sniffing, so don’t rely on them to avoid packet sniffing on your network.

    More Security Articles
    More By Eliana Stavrou


     

       

    SECURITY ARTICLES

    - An Epilogue to Cryptography
    - A Sequel to Cryptography
    - An Introduction to Cryptography
    - Security Overview
    - Network Security Assessment
    - Firewalls
    - What’s behind the curtain? Part II
    - What’s behind the curtain? Part I
    - Vectors
    - PKI: Looking at the Risks
    - A Quick Look at Cross Site Scripting
    - PKI Architectures: How to Choose One
    - Trust, Access Control, and Rights for Web Se...
    - Basic Concepts of Web Services Security
    - Safeguarding the Identity and Integrity of X...




    © 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway