โ† All Certified Ethical Hacker Flashcard Decks

Session Hijacking and Evading IDS Firewalls Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Session Hijacking and Evading IDS Firewalls flashcards as text
  1. Which type of session hijacking intercepts a session between two parties without requiring prediction of a sequence number?

    Answer: Passive Hijacking

    Passive hijacking involves monitoring a session to capture sensitive data without actively injecting packets, avoiding detection by not disrupting the session.

  2. What is the primary goal of TCP session hijacking?

    Answer: To take over an established TCP connection

    TCP session hijacking aims to take control of an active TCP session by predicting or stealing sequence numbers to inject malicious packets.

  3. Which tool is commonly used for session hijacking and man-in-the-middle attacks on a LAN?

    Answer: Ettercap

    Ettercap is a comprehensive suite for man-in-the-middle attacks, capable of sniffing, session hijacking, and filtering live connections on a LAN.

  4. What countermeasure best prevents session hijacking caused by predictable session tokens?

    Answer: Using long, randomly generated session IDs

    Long, cryptographically random session IDs are computationally infeasible to predict, preventing attackers from guessing valid session tokens.

  5. Which attack technique do attackers use to steal session cookies by injecting a script into a vulnerable web application?

    Answer: Cross-Site Scripting (XSS)

    XSS can be used to inject malicious scripts that read and exfiltrate the victim's session cookies to the attacker's server.

  6. What is 'IP spoofing' used for in the context of session hijacking?

    Answer: Masquerading as a trusted host to hijack a TCP session

    In session hijacking, IP spoofing allows the attacker to forge packets with a trusted source IP to impersonate a legitimate party in the TCP session.