Authentic attacks Flashcards

(12 cards)

1
Q

What is a Pass-the Ticket attack?

A

aim to steal kerberos tickets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Kerberoasting?

A

Post compromise attack used for cracking Microsoft AD service account passwords

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Credential Stuffing uses

A

reuses known passwords

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SPN stands for?

A

Service Principle Name and is used in Kerberos systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

LOLBins stand for?

A

Living of te Land attack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Prowler is used for?

A

Security audits on AWS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Is Prowler python based?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is Scout Suit open scource?

A

yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Scout Suit is used for?

A

performing security assessments on cloud environments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Can Scout Suit be Agentless?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Reflected XSS is

A

attacker input (usually from a URL, form or header) is reflected by the server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

DOM XSS lives

A

entirely in client-side JavaScript

How well did you know this?
1
Not at all
2
3
4
5
Perfectly