02.03.2018 Views

Sybex CEH Certified Ethical Hacker Version 8 Study Guide

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

unsafe site warnings – webservers and web applications 461<br />

unsafe site warnings, 248<br />

UPDATE statement in SQL injection, 340<br />

updates in social networking, 248<br />

upload bombing, 319<br />

URG flag, 385<br />

URIs (uniform resource identifiers), 312<br />

URLs<br />

companies, 89<br />

directory traversal attacks, 321<br />

web apps, 288<br />

U.S. Army, attack on, 331<br />

U.S. Code of Fair Information Practices, 19<br />

U.S. Communications Assistance for Law<br />

Enforcement Act, 19<br />

U.S. Computer Fraud and Abuse Act, 19<br />

U.S. Department of Energy, attack on, 331<br />

U.S. Electronic Communications Privacy<br />

Act, 19<br />

U.S. Kennedy-Kassebaum Health Insurance<br />

and Portability Accountability Act, 19<br />

U.S. Medical Computer Crime Act, 19<br />

U.S. Missile Defense Agency, attack on, 331<br />

U.S. National Information Infrastructure<br />

Protection Act, 19<br />

U.S. Privacy Act, 19<br />

USB drives, 164, 398<br />

USB wireless cards, 365<br />

user groups, 130<br />

usernames<br />

importance, 154<br />

stealing, 5<br />

users in Windows, 130–131<br />

V<br />

validation<br />

certificates, 66<br />

input, 317<br />

vandalizing web servers, 316<br />

version information in SQL injection, 338<br />

vertical privilege escalation, 168–169<br />

viruses, 184<br />

creating, 189<br />

description, 183<br />

detecting, 196–198, 198<br />

kinds, 186–188<br />

life and times, 184–186<br />

researching, 189<br />

Windows protection software, 47<br />

voice recognition, 407<br />

VRFY command, 143–144<br />

vulnerabilities, 45<br />

pen testing, 10<br />

research and tools, 18<br />

scanning for, 106, 119<br />

web servers and applications, 312–316<br />

vulnerable software in web applications, 321<br />

W<br />

Wabbit virus, 185<br />

WAITFOR command, 341<br />

WAITFOR DELAY command, 341<br />

walls, 407<br />

warballooning, 361<br />

warchalking, 361<br />

warded locks, 404<br />

wardialing, 106–108<br />

wardriving, 108, 360–361<br />

warflying, 361<br />

warning banners, 396–397<br />

warwalking, 361<br />

WaveStumbler tool, 361<br />

Wayback Machine, 89<br />

weak ciphers in web applications, 320<br />

web browsers<br />

proxies, 121–122<br />

social networking, 247<br />

spyware infection, 192<br />

Web Server component in web<br />

applications, 313<br />

webcams, 91<br />

webservers and web applications, 309–310<br />

client-server relationships, 310–316<br />

components, 311–313<br />

cross-site scripting, 317–318<br />

directory traversal attacks, 321–322<br />

DoS targets, 262<br />

encryption weaknesses, 320–321<br />

exam essentials, 323

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!