Posts

Showing posts with the label information security officer training

Everything You Need To Know About Sniffing – Part 1

Image
What is a sniffer in hacking? This section describes network sniffing and threats, how a sniffer works, active and passive sniffing, how an attacker hacks a network using sniffers, protocols susceptible to sniffing, sniffing within the data link layer of the OSI model, hardware protocol analyzers, SPAN ports, wiretapping, and lawful interception. Network Sniffing Packet sniffing may be a process of monitoring and capturing all data packets passing through a given  network sniffer   by using a software application or a hardware device, Sniffing is simple in hub-based networks, because the traffic on a segment passes through all the hosts related to that segment. However, most networks today work on switches.  A switch is a complicated computer networking device. the main difference between a hub and a switch is that a hub transmits line data to every port on the machine and has no line mapping, whereas a switch looks at the Media Access Control (MAC) address...

Anti-Forensics Techniques

Image
• Data hiding in file system Structures Data hiding is one in all the anti-forensic techniques utilized by attackers to form knowledge inaccessible. NTFS-based exhausting disks contain unhealthy clusters during a data file as $BadClus and also the MFT entry eight represents these bad clusters. $BadClus could be a sparse file, that permits attackers to cover unlimited information further as portion a lot of clusters to $BadClus to cover a lot of information. • Trail Obfuscation Trail Obfuscation is one in every of the anti-forensic techniques that attackers use to mislead, complicate, disorient, sidetrack, and/or distract the rhetorical examination method. the method involves totally different techniques and tools, such as: Log cleaners Spoofing Misinformation Backbone hopping Zombie accounts Trojan commands  In this method, the attackers delete or modify information of some vital files so as to confuse the incident res-ponders. They modify header data and file ...