【正文】
程在向一個文件寫入,另一個線程同時在對同一個文件進行讀出,程序的執(zhí)行結(jié)果不是確定的,與這兩個線程的競爭結(jié)果有關(guān)。 心理類方法包括通過電話或者在線通訊,如致電 Helpdesk假冒成內(nèi)部員工尋求管理員 Reset口令。 ? DRDoS(Distributed Refletor Denial of Service):attacker uses a fake source IP (Target ‘s) and send connection to several legilimate servers,when these servers respond they send the ACK packets to the attacker’s target. 四類攻擊之四:拒絕服務(wù) DDoS圖 攻擊過程 Step 1: Reconnaissance 偵探 The most mon method is social engineering, or tricking an employee into revealing sensitive information, Other methods include dumpster diving(搜索廢物箱) Step 2: Scanning 掃描(通過各種軟件工具) by scanning an anization’s puter software and work configuration to find possible entry points. 攻擊過程:信息收集 挖掘漏洞 Step 3: Gaining access 竊取訪問權(quán) take over a system and work by using a stolen password to create a phony account, or by exploiting a vulnerability that allows them to install a malicious Trojan horse, or automatic “bot” that will await further mands sent through the Inter. 攻擊過程:實施攻擊 Step 4: Maintaining access 維護訪問(安裝惡意軟件,修改配置,獲取Root權(quán)完全控制該主機或網(wǎng)絡(luò)設(shè)備,并為了防范其它黑客而答補?。? Once an attacker has gained unauthorized access, he or she may secretly install extra malicious programs that allow them to return as often as they wish. These programs, known as root kits or back door” run unnoticed and can allow an attacker to secretly access a work at will. If the attacker can gain all the special privileges of a system administrator, then the puter or work has been pletely taken over, and is owned by the attacker. Sometimes the attacker will reconfigure a puter system, or install software patches to close the previous security vulnerabilities just to keep other hackers out. 攻擊過程:安裝后門 Step 5: Covering tracks 掩蓋痕跡(通過清除日志) Sophisticated attackers desire quiet, unimpeded access to the puter systems and data they take over. They must stay hidden to maintain control。 社會工程攻擊又分為兩類:物理的和心理的。如果有人不停的鍵入 ESC鍵,就有可能阻止從特權(quán)態(tài)切換到普通用戶狀態(tài),從而獲得了特權(quán)。 實現(xiàn)特權(quán)提升的方法 實現(xiàn)特權(quán)提升的方法 ? Misconfiguaration Attacks 各種系統(tǒng)不適當?shù)呐渲每赡鼙还粽哂脕肀荛_安全屏障, 不適當?shù)呐渲煤蜎]有對系統(tǒng)及時打補丁會使系統(tǒng)至于某種安全暴露狀態(tài),大多數(shù)安全所面臨的問題。 ISS NE