Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Power Lifting Lever Belt
SkullVamp
Updated:
Saturday at 10:32 PM
Ad icon
port.lk Domain for sale
Lankan-Tech
Updated:
Saturday at 3:55 PM
Colombo
Kaduwela - Two Storey House for Sale
dilrasan
Updated:
Jun 11, 2026
Ad icon
Wechat qr verification
Pawan2005
Updated:
Jun 11, 2026
🚀 GOOGLE AI PRO 18 MONTHS ACTIVATION 🚀
sayuru bandara
Updated:
Jun 10, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
Learn Ethical Hacking - Part 1
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="Jolly_Roger" data-source="post: 8584674" data-attributes="member: 197784"><p><span style="font-size: 18px"><span style="color: Red"><strong>Assets, Threats, and Vulnerabilities</strong></span></span></p><p></p><p> </p><p></p><p><strong>Objectives:</strong> </p><p></p><p><span style="font-size: 15px">Recall essential terminology </span></p><p><span style="font-size: 15px">List the elements of security </span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">As with any new technology topic, terminology is used that must be learned to better understand the field. To be a security professional, you need to understand the relationship between threats, assets, and vulnerabilities. </span> <span style="font-size: 15px"></span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">Risk is the probability or likelihood of the occurrence or realization of a threat. There are three basic elements of risk: assets, threats, and vulnerabilities. Let’s discuss each of these. </span> <span style="font-size: 15px"></span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">An asset is any item of economic value owned by an individual or corporation. Assets can be real — such as routers, servers, hard drives, and laptops — or assets can be virtual, such as formulas, databases, spreadsheets, trade secrets, and processing time. Regardless of the type of asset discussed, if the asset is lost, damaged, or compromised, there can be an economic cost to the organization. </span> <span style="font-size: 15px"></span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">A threat is any agent, condition, or circumstance that could potentially cause harm, loss, damage, or compromise to an IT asset or data asset. From a security professional’s perspective, threats can be categorized as events that can affect the confidentiality, integrity, or availability of the organization’s assets. These threats can result in destruction, disclosure, modification, corruption of data, or denial of service. Some examples of the types of threats an organization can face include the following: </span> <span style="font-size: 15px"></span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">Unauthorized Access</span> <p style="margin-left: 20px"><span style="font-size: 15px">If userids and passwords to the organization’s infrastructure are obtained and confidential information is compromised and unauthorized, access is granted to the unauthorized user who obtained the userids and passwords.</span></p><p><span style="font-size: 15px">Stolen/Lost/Damaged/Modified Data</span><p style="margin-left: 20px"><span style="font-size: 15px">A critical threat can occur if the information is lost, damaged, or unavailable to legitimate users.</span></p><p><span style="font-size: 15px">Disclosure of Confidential Information</span><p style="margin-left: 20px"><span style="font-size: 15px">Anytimethere is a disclosure of confidential information, it can be a critical threat to an organization if that disclosure causes loss of revenue, causes potential liabilities, or provides a competitive advantage to an adversary.</span></p><p><span style="font-size: 15px">Hacker Attacks</span><p style="margin-left: 20px"><span style="font-size: 15px">An insider or outsider who is unauthorized and purposely attacks an organization’s components, systems, or data. </span></p><p><span style="font-size: 15px">Cyber Terrorism</span><p style="margin-left: 20px"><span style="font-size: 15px">Attackers whotarget critical, national infrastructures such as water plants, electric plants, gas plants, oil refineries, gasoline refineries, nuclear power plants, waste management plants, and so on.</span></p><p><span style="font-size: 15px">Viruses and Malware</span><p style="margin-left: 20px"><span style="font-size: 15px">An entirecategory of software tools that are malicious and are designed to damage or destroy a system or data.</span></p><p><span style="font-size: 15px">Denial of Service (DoS) or Distributed Denial of Service Attacks</span><p style="margin-left: 20px"><span style="font-size: 15px">An attack against availability that isdesigned to bring the network and/or access to a particular TCP/IP host/server to its knees by flooding it with useless traffic. Many DoSattacks, such as the Ping of Death and Teardrop, exploit limitations in the TCP/IP protocols. Like malware, hackers constantly develop new DoS attacks, so they form a continuous threat.</span></p><p><span style="font-size: 15px">Natural Disasters, Weather, or Catastrophic Damage</span><p style="margin-left: 20px"><span style="font-size: 15px">Hurricanes, such as Katrina that hit New Orleans in 2005, storms, weather outages, fire, flood, earthquakes, and other natural events compose an ongoing threat.</span></p><p><span style="font-size: 15px">If the organization is vulnerable to any of these threats, there is an increased risk of successful attack. </span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">A vulnerability is a weakness in the system design, implementation, software or code, or the lack of a mechanism. A specific vulnerability might manifest as anything from a weakness in system design to the implementation of an operational procedure. Vulnerabilities might be eliminated or reduced by the correct implementation of safeguards and security countermeasures. </span> <span style="font-size: 15px"></span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">Vulnerabilities and weaknesses are common with software mainly because there isn’t any perfect software or code in existence. Vulnerabilities in software can be found in each of the following:</span> <span style="font-size: 15px"></span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">Firmware</span> <p style="margin-left: 20px"><span style="font-size: 15px">This software is usually stored in ROM and loaded during system power up.</span></p><p><span style="font-size: 15px">Operating System</span><p style="margin-left: 20px"><span style="font-size: 15px">This operating system software is loaded in workstations and servers.</span></p><p><span style="font-size: 15px">Configuration Files</span><p style="margin-left: 20px"><span style="font-size: 15px">The configuration file and configuration setup for the device.</span></p><p><span style="font-size: 15px">Application Software</span><p style="margin-left: 20px"><span style="font-size: 15px">The application or executable file that is run on a workstation or server.</span></p><p><span style="font-size: 15px">Software Patch</span><p style="margin-left: 20px"><span style="font-size: 15px">This is a small piece of software or code snippet that the vendor or developer of the software typically releases as software updates, software maintenance, and known software vulnerabilities or weaknesses.</span></p><p><span style="font-size: 15px">Vulnerabilities are not the only concern the ethical hacker will have. Exploits are a big concern, as they are a common mechanism used to gain access. That’s discussed next.</span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">Defining an Exploit </span> <span style="font-size: 15px"></span></p><p><span style="font-size: 15px"></span></p><p><span style="font-size: 15px">An exploit refers to a piece of software, tool, or technique that takes advantage of a vulnerability that leads to privilege escalation, loss of integrity, or denial of service on a computer system. Exploits are dangerous because all software has vulnerabilities; hackers and perpetrators know that there are vulnerabilities and seek to take advantage of them. Although most organizations attempt to find and fix vulnerabilities, some organizations lack sufficient funds for securing their networks. Even those that do are burdened with the fact that there is a window between when a vulnerability is discovered and when a patch is available to prevent the exploit. The more critical the server, the slower it is typically patched. Management might be afraid of interrupting the server or afraid that the patch might affect stability or performance. Finally, the time required to deploy and install the software patch on production servers and workstations exposes an organization’s IT infrastructure to an additional period of risk.</span></p></blockquote><p></p>
[QUOTE="Jolly_Roger, post: 8584674, member: 197784"] [SIZE=5][COLOR=Red][B]Assets, Threats, and Vulnerabilities[/B][/COLOR][/SIZE] [B]Objectives:[/B] [SIZE=4]Recall essential terminology List the elements of security As with any new technology topic, terminology is used that must be learned to better understand the field. To be a security professional, you need to understand the relationship between threats, assets, and vulnerabilities. [/SIZE] [SIZE=4] Risk is the probability or likelihood of the occurrence or realization of a threat. There are three basic elements of risk: assets, threats, and vulnerabilities. Let’s discuss each of these. [/SIZE] [SIZE=4] An asset is any item of economic value owned by an individual or corporation. Assets can be real — such as routers, servers, hard drives, and laptops — or assets can be virtual, such as formulas, databases, spreadsheets, trade secrets, and processing time. Regardless of the type of asset discussed, if the asset is lost, damaged, or compromised, there can be an economic cost to the organization. [/SIZE] [SIZE=4] A threat is any agent, condition, or circumstance that could potentially cause harm, loss, damage, or compromise to an IT asset or data asset. From a security professional’s perspective, threats can be categorized as events that can affect the confidentiality, integrity, or availability of the organization’s assets. These threats can result in destruction, disclosure, modification, corruption of data, or denial of service. Some examples of the types of threats an organization can face include the following: [/SIZE] [SIZE=4] Unauthorized Access[/SIZE] [INDENT][SIZE=4]If userids and passwords to the organization’s infrastructure are obtained and confidential information is compromised and unauthorized, access is granted to the unauthorized user who obtained the userids and passwords.[/SIZE][/INDENT][SIZE=4]Stolen/Lost/Damaged/Modified Data[/SIZE][INDENT][SIZE=4]A critical threat can occur if the information is lost, damaged, or unavailable to legitimate users.[/SIZE][/INDENT][SIZE=4]Disclosure of Confidential Information[/SIZE][INDENT][SIZE=4]Anytimethere is a disclosure of confidential information, it can be a critical threat to an organization if that disclosure causes loss of revenue, causes potential liabilities, or provides a competitive advantage to an adversary.[/SIZE][/INDENT][SIZE=4]Hacker Attacks[/SIZE][INDENT][SIZE=4]An insider or outsider who is unauthorized and purposely attacks an organization’s components, systems, or data. [/SIZE][/INDENT][SIZE=4]Cyber Terrorism[/SIZE][INDENT][SIZE=4]Attackers whotarget critical, national infrastructures such as water plants, electric plants, gas plants, oil refineries, gasoline refineries, nuclear power plants, waste management plants, and so on.[/SIZE][/INDENT][SIZE=4]Viruses and Malware[/SIZE][INDENT][SIZE=4]An entirecategory of software tools that are malicious and are designed to damage or destroy a system or data.[/SIZE][/INDENT][SIZE=4]Denial of Service (DoS) or Distributed Denial of Service Attacks[/SIZE][INDENT][SIZE=4]An attack against availability that isdesigned to bring the network and/or access to a particular TCP/IP host/server to its knees by flooding it with useless traffic. Many DoSattacks, such as the Ping of Death and Teardrop, exploit limitations in the TCP/IP protocols. Like malware, hackers constantly develop new DoS attacks, so they form a continuous threat.[/SIZE][/INDENT][SIZE=4]Natural Disasters, Weather, or Catastrophic Damage[/SIZE][INDENT][SIZE=4]Hurricanes, such as Katrina that hit New Orleans in 2005, storms, weather outages, fire, flood, earthquakes, and other natural events compose an ongoing threat.[/SIZE][/INDENT][SIZE=4]If the organization is vulnerable to any of these threats, there is an increased risk of successful attack. A vulnerability is a weakness in the system design, implementation, software or code, or the lack of a mechanism. A specific vulnerability might manifest as anything from a weakness in system design to the implementation of an operational procedure. Vulnerabilities might be eliminated or reduced by the correct implementation of safeguards and security countermeasures. [/SIZE] [SIZE=4] Vulnerabilities and weaknesses are common with software mainly because there isn’t any perfect software or code in existence. Vulnerabilities in software can be found in each of the following:[/SIZE] [SIZE=4] Firmware[/SIZE] [INDENT][SIZE=4]This software is usually stored in ROM and loaded during system power up.[/SIZE][/INDENT][SIZE=4]Operating System[/SIZE][INDENT][SIZE=4]This operating system software is loaded in workstations and servers.[/SIZE][/INDENT][SIZE=4]Configuration Files[/SIZE][INDENT][SIZE=4]The configuration file and configuration setup for the device.[/SIZE][/INDENT][SIZE=4]Application Software[/SIZE][INDENT][SIZE=4]The application or executable file that is run on a workstation or server.[/SIZE][/INDENT][SIZE=4]Software Patch[/SIZE][INDENT][SIZE=4]This is a small piece of software or code snippet that the vendor or developer of the software typically releases as software updates, software maintenance, and known software vulnerabilities or weaknesses.[/SIZE][/INDENT][SIZE=4]Vulnerabilities are not the only concern the ethical hacker will have. Exploits are a big concern, as they are a common mechanism used to gain access. That’s discussed next. Defining an Exploit [/SIZE] [SIZE=4] An exploit refers to a piece of software, tool, or technique that takes advantage of a vulnerability that leads to privilege escalation, loss of integrity, or denial of service on a computer system. Exploits are dangerous because all software has vulnerabilities; hackers and perpetrators know that there are vulnerabilities and seek to take advantage of them. Although most organizations attempt to find and fix vulnerabilities, some organizations lack sufficient funds for securing their networks. Even those that do are burdened with the fact that there is a window between when a vulnerability is discovered and when a patch is available to prevent the exploit. The more critical the server, the slower it is typically patched. Management might be afraid of interrupting the server or afraid that the patch might affect stability or performance. Finally, the time required to deploy and install the software patch on production servers and workstations exposes an organization’s IT infrastructure to an additional period of risk.[/SIZE] [/QUOTE]
Insert quotes…
Verification
Dahaya deken beduwama keeyada?
Post reply
Top
Bottom