Cybersecurity Full Course 2026 | Cyber Security Tutorial for Beginners | Cybersecurity | Edureka
Skills:
Security Basics80%
Key Takeaways
Covers the fundamentals of Cybersecurity, including common attacks, security tools, and practical techniques for safeguarding information
Full Transcript
Hello everyone and welcome to the cyber security full course. Your step-by-step guide to protecting systems, networks, and data in today's digital world. In a time where cyber threats are growing every day, cyber security has become one of the most in demand skills. From fishing attacks to ransomware, hackers are constantly looking for weaknesses. This course will help you understand how these threats work and how to defend against them. We will start with the fundamentals of cyber security, explore common attacks, dive into security tools, and learn practical techniques for safeguarding information. Along the way, you will gain hands-on knowledge in areas like ethical hacking, network security, cryptography, cloud security, and incident response. And by the end of this course, you will not only understand the principles of cyber security, but also be ready to apply them in real world situations, whether to protect your personal data, secure an organization, or build a career in this fast growing fit. So before we begin, please like, share and subscribe to Edureka's YouTube channel and hit the bell icon to stay updated on the latest tech content from Edureka. Also check out Edureka's CV V13 ethical hacking course with AI tools in collaboration with EC Council. It offers you the opportunity to earn the globally recognized C13 certification. This comprehensive training program dives deep into AI powered hacking techniques and cutting edge GP based tools covering 20 in demand modules and over 500 advanced attack methods. It is designed to equip you with the skills to identify and mitigate security vulnerabilities and the course emphasizes real world application through two 21 hands-on labs. Your enrollment includes official EC council, ECOSER and an exam watcher helping you prepare confidently for the CH V13 exam. So check out the course link given in the description box below. Now let us get started with our first topic that is what is cyber security. Before we get into what cyber security is, let's first look at why it's so important today. Imagine you wake up and hear that a company has lost millions just because of cyber attack. Talking about such an attack, a few years back on May 7, 2021, Colonial Pipeline, which is a major American oil pipeline system, became the victim of a ransomware attack. Colonial Pipeline is an oil pipeline that was established in 1962. It spans over 5,500 m from Texas to New Jersey, transporting gasoline, jet fuel, and heating oil. This pipeline is essential in transporting oil products from the Gulf of Mexico to the east coast of the United States. This attack involved multi-stages against Colonial Pipeline IT systems. The pipelines operational technology systems which actually move oil were not directly compromised during the attack. The attack began when a hacker group identified as dark side assessed the Colonial Pipeline network. Within a 2-hour window, the attackers stole 100 GB of data. Following the data theft, the attackers affected the Colonial Pipeline IT network with ransomware that affected many computer systems, including billing and accounting. Colonial Pipeline shut down the pipeline to prevent the ransomware from spreading. Security investigation firm Mandant was then bought in to investigate the attack. The attacker group demanded a ransom of 75 bitcoins, which is worth $4.4 million USD. Colonial Pipeline paid a Dark Side hackers to get the decryption key, enabling the company's IT staff to regain control of its systems. Although the ransom was paid within hours, but the tool provided to restore their systems was slow and ineffective, which caused further delay and economic loss. The reputational damage was even worse. Now, let's see the root cause of the attack. Attackers got into the Colonial Pipeline network through an exposed password for a VPN account. A colonial pipeline employee likely used the same password for the VPN in another location. The password was somehow compromised as a part of a different data breach. Password reuse has become a common problem as many users often use the same password more than once. Here is an attack summary to understand the attack clearly. The date was May 7, 2021. The attack type was a ransomware attack. The attacking group was dark side and the loss was of 75 bitcoins which was around $4.4 4 million USD. And this wasn't the only major attack. About a decade ago, there was another big attack known as a Sony PlayStation Network outage. Before diving into the attack, let's take a quick look at what Sony PlayStation Network was before 2011. Launched in November 2006, PSN was an online gaming service for PlayStation consoles, offering features like online multiplayer gaming, digital game purchases, and streaming services. By 2011, PSN had grown into a major platform with millions of users worldwide, becoming a central hub for PlayStation gamers to connect, play, and access a wide range of digital content. It was a crucial part of Sony's gaming ecosystem with a rapidly expanding user base. The BSN was not just a gaming platform. It was also a social network where players could interact with friends, join gaming communities, and share achievements. The network's popularity soared with the success of the PlayStation 3, attracting a diverse and loyal customer base. By early 2011, millions of PlayStation users were regularly logging into the PSN, making it one of the largest online gaming platforms at the time. But then in April 2011, everything changed. The activist group Anonymous targeted Sony's PlayStation Network and bought it down with a distributed denial of service attack. The attack was in retaliation for Sony's legal actions against two individuals, George Hort, known as Giohart and Alexander Igoran, known known as Graphic Colo. These hackers had previously exposed vulnerabilities in Sony's PlayStation 3, enabling users to bypass the console security features. Anonymous warned Sony, stating, "You have victimized your customers merily for possessing and sharing information. Now you will experience the wrath of Anonymous." On April 19th, 2011, Sony detected an external intrusion on their system, affecting both PlayStation Network and Curiosity Services. By April 20, Sony had taken the PSN servers offline to protect its users, leaving millions without access to online gaming for several weeks. However, the most alarming part of this breach was the exposure of sensitive user data. the personal information of 77 million users including names, addresses, emails, PlayStation networks, passwords and login and even PSN online ids was compromised. In some cases, users profile data including purchase history and billing addresses may have also been accessed, rising serious concerns about identity theft. The financial damage was immense, costing Sony an estimated $171 million. However, the repetitional damage was even worse as Sony faced significant backlash from its users and multiple lawsuits. Now, let's see the root cause of the attack. The attack was fueled by Sony's decision to remove the other OS feature from the PlayStation 3, which allowed users to install Linux. Hackers motivated by this removal sought to expose vulnerabilities in Sony's system. Anonymous angered by Sony's legal actions against those hackers took matters into their own hands and that led to the attack that crippled Sony's network and expose the personal data of millions. Here is an attack summary to understand the attack clearly. The date was April 17 to 19, 2011. The attack type was an external intrusion. The attacking group was anonymous and the loss was of $171 million USD. As we have seen from these real world examples, cyber attacks can have devastating impacts. Now, while these two attacks were significant in their own right, they are just a few examples of many cyber instance that happen every year. To give you a clearer picture of how cyber security vulnerabilities have been increasing over the years, let's take a look at some data. As you can see from this graph, the number of reported vulnerabilities has been rising year after year from small breaches to massive cyber attacks like the ones we just discussed. The scale of problem is growing. In fact, by 2024, we have seen vulnerabilities reach unprecedented levels, making cyber security more critical than ever before. Here is another graph that breaks down the vulnerabilities by type including some of the most common ones like XSS, CSRF, SSRF, XSSE, and denial of service attacks. These vulnerabilities are exploited every day by malicious actors to gain access to sensitive information, disrupt services, or cause financial and reputational damage to companies. Whether it's through exploiting weak spots in systems or using social engineering techniques, these threats are becoming more sophisticated and it's crucial that we understand them so we can protect against them. Now that we have seen the impact cyber attacks can have and how vulnerabilities continue to rise year after year, it's clear that we need strong defenses in place. So what exactly is cyber security and how does it protect us from such threats? Let's dive in. According to CISA, cyber security is the art of safeguarding our networks, devices, and data from criminal use while ensuring confidentiality, integrity, and availability. Let's break that down into three key pillars. First is the confidentiality. It is all about protecting sensitive information from unauthorized access. For instance, only those with the right permissions can access specific data. Then comes the integrity which ensures that the data remains accurate and unaltered by unauthorized parties. Last is the availability that makes sure that the information or the service is accessible when needed by authorized users. Now that we have a clear understanding of what cyber security is, let's dive deeper into how it's implemented. Think of them as a fundamental rules and guidelines that form the foundation of a strong cyber security posture. They act as our trusty guide through the digital wilderness. Moving on to our first principle that is confidentiality. It is about keeping information private. For example, when you send a message through WhatsApp, it's encrypted, which means only you and the person you're messaging can read it. This keeps the conversation private and no one else can access it even if they manage to intercept the data. Next comes the integrity which ensures the information is not changed without permission. Imagine you download a file from the internet and the website provides a unique code to verify the file. Before using the file, you can use this unique code to verify that it hasn't been tampered with and is safe to use. Next is the availability is about keeping sure information and systems are always accessible when needed. For example, if you're using Google Drive, Google makes sure your files are available even if one of their servers goes down. They do this by storing your data on multiple servers so you can always access your files. Next is the authorization controls what you can do after you login. For instance, in a company system, employees might log in with their credentials, but what they can access depends on their role. A regular employee might only see their own files, while a manager can access departmentwide data. This ensures that people only access what they're supposed to. Then comes the authentication. This is how you prove who you are when you log into a system. A simple example is when you enter your password to log into your email. To make it more secure, some systems use two-actor authentication where after entering your password, you might also have to enter a code sent to your phone. This makes sure it's really you logging in. Next is a non-repudiation means ensuring that someone cannot deny they did something. A good example is digital signatures. When you sign an online document with a digital signature, it creates a record that proves you signed it. Later, you can't say you didn't sign it because the digital signature is unique to you. Moving on to accountability means tracking who does what in a system. For example, in a company's network, all activities like who accessed which files and when are logged. These logs help the companies track actions, making sure that everyone is responsible for what they do. Last is the auditability is about keeping records so actions can be reviewed later. Imagine a company uses software to track all changes made to important documents. If something goes wrong, they can review the history to see who made changes and when helping them figure out what happened. With these principles in mind, you now have a solid understanding of how cyber security works at its core. But to truly grasp cyber security, we need to also understand the networks we protect. Up next, we'll dive into networking basics, covering everything from network types and components to firewalls and IP addressing. Imagine you are in a large office building. There are hundreds of computers, printers, and other devices all needing to communicate with each other to share information, resources, and access the internet. This communication is made possible through what we call a computer network. A computer network is essentially a collection of interconnected devices like computers, servers, and routers that communicate with each other to share resources and information. This connectivity is crucial for everything from sending an email to accessing cloud services. Without networks, our digital world would be fragmented and isolated. Now that we know what a computer network is, let's explore the different types of networks that exist and how they fit into various scenarios. First, we have LANs or local area networks. These are networks that cover a small geographic area like a single building or a campus. For example, the network in your home or office is a LAN connecting your computers, printers, and other devices. Next is a WAN or wide area network. Vans cover larger geographic areas such as cities, countries, and even continents. The internet itself is the largest van, connecting millions of land across the world. Vans are essential for businesses with multiple locations, enabling them to share resources and communicate effectively. Then we have MANs or metropolitan area networks. These networks cover a larger area than the land, but are still limited to a specific city or large campus. They're often used by universities or city governments to connect multiple buildings within a specific area. Lastly, we have PANS or personal area networks. These are the smallest networks, typically covering just a few meters. Think of the Bluetooth connection between your smartphone and your wireless earbuds. That's a PAN. Now that we have seen the different types of networks, let's take a closer look at the key components that make these networks work smoothly. First is a modem. A modem is a device that converts digital data from a computer into a format suitable for a transmission medium like telephone lines and vice versa. Next comes a network interface card. It is a hardware component inside a computer that enables it to connect to a network. It can be wired or wireless too. Next is a repeater. A repeater is a network device that receives a signal, amplifies it and retransmits it to extend the range of communication over long distances. Moving on to hub. A hub is a basic network device that connects multiple computers in a local network. It broadcasts the data to all devices connected regardless to which device the data is meant for. Next comes switch. A switch is a more advanced version of a hub that can direct the data it receives only to the device it is meant for making it more efficient. Next is a router. A router connects different networks together and routes data between them. It can connect devices within a local area network to the internet. Moving on to bridge. A bridge connects two separate networks allowing them to function as a single network. It works at the data link layer and helps divide networks into segments to reduce traffic. Last is a gateway. A gateway is a device that connects two different networks that use different protocols allowing them to communicate with each other. Having covered the essential components that help networks function, let's move on to one of the most crucial defenses in cyber security that is firewall. A firewall is defined as a cyber security tool that monitors incoming and outgoing network traffic and permits or blocks data packets based on a set of security rules. Think of a firewall as a gatekeeper for your network. It ensures that unauthorized or harmful data doesn't get into your network and that sensitive data doesn't leak out. Imagine you're sending a request to visit a website. Your request first goes through the firewall which checks if it's safe. If it is, the request is sent to the internet. Where the website server process it and sends a response back. The firewall checks this response allowing only legitimate data to reach your device. If the hacker tries to send malicious data, the firewall blocks it keeping the network safe. Now we understand the basic concept of a firewall and its role in protecting networks. Let's explore the different types of firewalls and how will they offer various levels of security. First we have the packet firewall. It controls network traffic by inspecting source and destination IP addresses, protocols and ports without analyzing the state of connection. Next is the stateful inspection firewall. Monitors the full state of active connections and allow traffic only if valid sessions is established. Blocking unauthorized packets. Next is the application layer firewall. Inspects traffic at the application layer blocking malicious or suspicious application level requests like HTTP that could harm the network. Moving on to next generation firewall. It provides advanced security by combining traditional firewall capabilities with additional features like intrusion prevention, application control and cloud threat intelligence. Next is a circuit level gateway. It secures TCP UDP connections by managing sessions at the OSI models session layer. Ensures packet exchange is valid between trusted endpoints. Moving on to the software firewall. It protects an individual computer by running as software, notifying users of potential threats from unauthorized access or malicious websites. Then comes a hardware firewall, a physical device that monitors and filters traffic at the network boundary, enforcing access controls and security policies on inbound and outbound traffic. Last is the cloud firewall. A cloud deployed firewall that filters traffic at the cloud level, offering protection against unauthorized access to private networks without the need for physical infrastructure. Now that we understand the role of firewalls, let's explore how devices in a network communicate with each other using IP addresses. Just like every house on a street needs a postal address, every device on a network needs an address. This is where IP addresses comes in. An IP address or internet protocol address is a unique identifier assigned to each device on a network. It allows devices to find and communicate with each other. There are two types of IP addresses. The first is the IPv4. Then comes the IPv6. IPv4 is a older version and uses 32-bit address like 192.168.1.1. However, with the explosion of devices needing IP addresses, the available IPv4 addresses are running out. This is where IPv6 comes in. IPv6 uses a 128 bit address providing a much larger pool of addresses. This ensures that we won't run out of the addresses anytime soon. IP addresses are like postal addresses in the digital world, ensuring the devices can locate and communicate with each other. Now that we understand how devices are identified and connected, let's dive into how web servers communicate using HTTP status codes. Now let's have a small quiz in what we have studied earlier. Moving on to our first question. Which firewall monitors and keeps track of the state of active connections? And the options are A next generation firewall, B software firewall, C stateful inspection firewall and D packet firewall. If you know the correct answer, please comment below. Now that we have discussed IP addressing, let's go ahead and perform a simple demo on how we can find IP addresses of our machines. But before that we have to install some prerequisites. So let me show you how to install VMware on your personal computer and run a virtual environment like Kali Linux on it. But before that let's break down what exactly is virtual machine. First we have the infrastructure. This is your physical computer or the host machine which provides the hardware resources like CPU, memory and storage that the virtual machine will use. Examples are cloud servers, databases and your personal computer. Then we have is a hypervisor which is a software that lets you run virtual machines on your computer and manages how resources are shared between them. Examples are Oracle virtual box and VMware Workstation. Then we have the guest operating system. Now this is operating system that runs on your hypervisor. For us it's going to be Kali Linux but other examples are Windows and Ubuntu. With that said, let's get started with the installation. All right, let's start by getting WMware. First, open up your favorite web browser. Could be Chrome, Firefox, Edge, whatever you like. Now, in search bar, just type in VMware Workstation Pro and hit enter. You'll want to click on the very first link that pops up. It should take you directly to the official WM web page. Once you're on the site, you'll see two main options. The first is Workstation Pro and Fusion Pro. Now, we interested in Workstation Pro because that's a one for Windows. Scroll down a bit and you'll find a download button that says VMware Workstation Pro download. Go ahead and click that. Now, this will take you to the Broadcom website. They handle VMware downloads. It used to be much easier before this change. Back then, we could download it directly from VM web without having to login or create an account, but now Broadcom requires a login to proceed. It's just an extra step, but it doesn't take long. If you already have an account, just sign in. And if you don't, no worries. Registering is quick and simple. While registering, it's not important to register with your company's email. You can also use your personal email as well. Once you're logged in, you'll land on the VMware Workstation download page. Now, make sure you're downloading the right version. We need the VMware Workstation Pro 17.0 for personal use, that is Windows. Personal use is a key here because we don't want the commercial version. Go to 17.6.1 and click on that. Now agree to the terms and conditions and on the right hand side you will see the little download icon. Click on that and your download should start immediately. Easy, right? Now that we have got VMware, let's move to downloading Kali Linux. Before that, let's talk about Kali Linux. It's a Debian based operating system that is specially designed for ethical hacking and penetration testing. It comes pre-installed with hundreds of security tools that professionals use for their own day-to-day tasks like network scanning, vulnerability testing, and password cracking. With that said, let's start with the installation. Head over to your browser again, and this time Kali Linux into the address bar. Hit enter and just like before, click on the first link that pops up. This will take you straight to the official Kali Linux page. Once you're there, you'll see a big download button. Go ahead and click that and you'll be asked to choose your platform. Since we are setting up this on the virtual machine, you're going to select the option for virtual machines. Now, scroll down a bit and you'll see several download options. Since we are using VMware, make sure to pick the one specifically for VMware. You'll find the download icon right next to it. Click on that and your download should start right away. Wait patiently until the download is complete. Now that we have both these files ready and downloaded on our desktop, let's start with installation process. So first up, we'll install VMware Workstation Pro. Head to the folder where we downloaded the VMware installer file. You should see the file name something like VMware Workstation full.exe. Let's double click on that to start the installation. A prompt will appear asking for permissions to continue. Click yes. After that, the VMware installer window will pop up. Click next to get started. And then you'll be shown the license agreement. You know the drill here. Just click on the box that say I accept the terms in the license agreement and hit next. Now you'll see an option asking if you want to add VMware Workstation Console tools to your system path. Make sure this box is checked. It's really useful, trust me. Next, you'll see two options related to the user experience. You can uncheck these if you don't want to send usage data to VMware. Totally up to you. If you prefer not to have a desktop shortcut like me, go ahead and uncheck the desktop shortcut option. Once all that's done, hit install and let the magic happen. VMware will install itself on your system. And when it's finished, click finish. If you have a license key, you can enter it now. But if you don't, no worries. Just click on finish again and we have done with the installation of VMware Workstation. Now that VMware is installed, let's move on to setting up Kali Linux. Go to the folder where we downloaded the Kali Linux zip file. Right click on it and choose extract all. You can extract it wherever you prefer on your system. Once the extraction is done, open the folder and you will see a bunch of files. What we're interested in is the one with the VMX extension. That's a virtual machine configuration file. Now just double click on that VMX file. This will automatically open VMware Workstation and start the import process for Kali Linux. Once imported, Kali Linux should appear inside VMware Workstation as a new virtual machine. And there you go. Your Kali Linux VM is all set up and ready to run. All right. Now that Kali Linux is imported into VMware, we need to make a few changes before booting it up for the first time. First, click on edit virtual machine settings. Then we'll open up the setting window. Under the hardware tab, you'll see an option for memory. Now, for smoother operation, I recommend assigning at least 4 GB of RAM to your virtual machine. But if your computer has less available RAM, you can leave it to 2GB and it should still work fine. Once that's done, click okay to save your settings. Now you're ready to boot up the Kali machine. Click on power on this virtual machine. This will start up your Kali Linux VM. Once the machine boots up, you'll arrive at the login screen. Here you'll need to enter the default credentials. The username is Kali and the password is also Kali. Simple enough. You're now inside your Kali Linux virtual machine. Here you go. We have successfully installed the Kali Linux virtual machine. Now let's go ahead and see how we can see the IPv4 and IPv6 address of our Windows host machine and as well as Kali virtual machine. Starting with Windows, open your terminal and type IP config. Hit enter. And now you can see the IP Windows configuration on the screen. Now if you scroll down you will see something like wireless LAN adapter Wi-Fi address. Under that you can see link local IPv6 address. So this is our IPv6 address and we also have the IPv4 address that is 192.168.0.96. This is how we check the IPv address for the Windows machine. Now let's see how to do the same for a Kali machine. Same as we did before. Go to your terminal and type if config and hit enter. You can see something like inet 192.168.112.128. This is our IPv4 address. And we can see inet 6 that is the IPv6 address. So this is how we check the IP addresses for Windows and Linux machine. When you interact with the website, the web servers respond with specific status codes that tell you what's happening behind the scenes. First, we have theformational status code starting with one indicates that the request was received and is still being processed. Then we have the success status code starting with two confirms the request was successful like a 200 okay status. Then we have is a redirection status code which starts with three. Tells the client that further actions is needed to complete the request. Moving on to the client errors status code which starts with four indicates an issue with the client's request. Last we have the server error status code which starts with five. Shows there is a problem on the server side. Now that we have covered the status codes, let's talk about some of the most common HTTP errors you may encounter and what they mean. First we have is the 401 unauthorized. That means the client is not authorized to access the requested resource. Next is the 400 bad request. The server cannot understand the request due to bad syntax. Moving on to 404 not found. The server cannot find the requested resource. Next we have is a 403 forbidden. The client does not have permission to access the resource. Then comes a 500 internal server error. A generic error message indicating the server encountered an unexpected issue. Last the 503 service unavailable. The server is currently unable to handle the request due to being overloaded or under maintenance. After exploring how web traffic functions and how errors are communicated, it's time to look at the larger picture. How data flows across networks using different models. Let's first break down the OSI model, then the TCP IP model, and finally we'll compare both to see how they align. The OSI model is a conceptual framework developed by the international organization for standardization that is used to understand and implement networking protocols in seven distinct layers. Each layer serves a specific function and interacts with the layers directly above and below it. The first layer is the physical layer. This is the lowest layer of the OSI model. It deals with the physical connection between devices including the transmission and reception of raw data bytes over a physical medium such as cables, switches and hubs. The physical layer is responsible for defining the hardware specifications, transmission rates and encoding methods. The next layer is the data link layer. This layer establishes, maintains and decides how data is transferred between directly connected nodes in a network. It ensures that the data reaches its destination without errors. This layer is further divided into two sub layers. First is a media access control which controls how devices on the network gain access to the data and also gives permission to transmit it. Next is the logical link control which controls frame synchronization, flow control and error checking. The third layer is the network layer. The network layer is responsible for the logical addressing and routing of data. It decides the path that data should take across the network often using routers to forward packets to their destination. This layer handles packet forwarding including routing through different routers. The fourth layer is a transport layer. The transport layer ensures the reliable transmission of data between systems. It controls flow, handles error correction and ensures that the data is delivered in the correct sequence. It also manages data segmentation and reassembly. This layer supports both TCP which is connection oriented and UDAP which is connectionless. The fifth layer is a session layer. This layer manages sessions or connections between applications. It establishes, manages and terminates the communication sessions between two systems. It also controls dialogue control and synchronization. The sixth layer is a presentation layer. The presentation layer translates data between the application layer and the network. It is responsible for the data format translation, encryption and compression. This layer ensures that the data sent from the application layer of the one device can be read by the application layer of another device even if they use different data formats. The last we have is the application layer. The application layer is the closest layer to the end user and is responsible for network services to applications. It directly interacts with a software application that implement a communication component. It provides services like email file transfer and network resource sharing. The TCP IP model also known as the internet protocol suit is a simple and more practical framework used to explain how data moves across networks. It has four layers which combines some of the functions found in OSI models seven layer. The first layer is a network access layer. This layer combines the functionality of both the physical and data link layers from the OSI model. It handles the hardware components and transmission medium as well as defining how data is physically transmitted across the network. The second layer is the internet layer. Equivalent to the network layer of the OSI model, the internet layer is responsible for logical addressing and routing data to its destination. It defines protocols for data packet addressing and forwarding through the network. The third layer is a transport layer. Similar to the OSI transport layer, this layer manages data flow control, error checking and ensures that the data is delivered reliably from one system to another. The primary protocols used are TCP for reliable data transmission and UDP for fast connectionless communication. The fourth layer is application layer. This layer combines the functionality of the session, presentation and application layers of the OSI model. It deals with high level protocols and services that allow users to interact with the networks. It supports processes like file transfer, email and web browsing. While the OSI model is more of the theoretical framework, it provides a great foundation for understanding networking and data transmission. The TCP IP model on the other hand is used for real world networking, especially on the internet. Understanding the basics of networking sets the stage for appreciating how data is transmitted and protected across the internet. Now let's take up a quiz in what we have learned earlier. And the second question is in the TCP IP model which layer corresponds to the OSI models network layer and the options are Athernet layer B transport layer C application layer and D link layer. If you know the correct answer comment below. Now let's delve into a crucial aspect of cyber security that is cryptography. This practice ensures that our data remains confidential and secure by transforming it into a format that is unreadable without the correct decryption key. Cryptography is a practice of securing information by transforming it into an unreadable format. This process involves two key operations. First is encryption and decryption. Encryption is a process of converting plain text into cipher text using an algorithm and a key. Decryption is a reverse process converting cipher text back into plain text using a key. The purpose of cryptography is to ensure the confidentiality, integrity, and authenticity of data. Now let's explore the different methods of encryption that cryptographers employ to safeguard data. First we have the symmetric cryptography. Use the same key for both encryption and decryption. It's fast and efficient but requires secure key distribution. Example AES that is the advanced encryption standard. Next we have the asymmetric cryptography uses a pair of keys a public key and a private key. The public key encrypts data and the private key decrypts it. This method is slower but provides a way to securely share keys. Example the RSA. Having established the two main types of encryption, let's dive deeper into specific cryptographic algorithms that implement these methods. First we have is the advanced encryption standard. It uses the same key for encryption and decryption. It is a symmetric block cipher algorithm with block size of 128 bits, 192 bits or 256 bits. Second we have the data encryption standard. It is used to convert 64-bit plain text data into 48 bit encrypted cipher text. It uses symmetric keys. Third we have is the RSA. It is a asymmetric cryptographic algorithm which uses two different keys for encryption. This algorithm works on a block cipher concept that converts plain text into cipher text and vice versa. The last type we have is the secure hash algorithm. It is used to generate unique fixed length digital fingerprints of input data known as the hashes. Its variations such as SHA 2 and SH 3 are commonly used to ensure data integrity and authenticity. Now let's take up a quiz in which we have learned earlier. Question number three. Which of the following is a type of symmetric encryption? And the options are A RSA, B AES, option C we have dey helman, option d we have lgaml. If you know the correct answer, please comment below. Now that we have covered the basics of cryptography and the different types of encryption, let's dive into a practical demonstration. In this demo, we'll encrypt a sample text file, decrypt the encrypted file back to its original form, verify the integrity of the original and decrypted files. This hands-on example will help you see how these cryptographic techniques are applied in real world scenarios to protect and verify data. Let's get started. We'll focus on symmetric encryption using the AES algorithm and verify data integrity with the SHA 256 hash function. Now, let's create a sample text file. In this step, we create a simple text file that contains a message, hello world. This file is named as sample.txt. This step sets up the file we'll work with. Now, we will be using open SSL to encrypt the sample.txt file using the AES algorithm along with the 256-bit key in cipher blockchaining mode. This command invokes the open SSL encryption tool. Here we are specifying the AES algorithm with the 256-bit key and CBC mode. Then we have added a random salt to strengthen the encryption by preventing attacks on reused passwords. After that we have specified the input file that is the file that we have encrypting. And here we have the output file where the encrypted content will be stored. And also we have specified a password for our encrypted file which is edurea. By running this, we encrypt the sample.txt file and store the result in encrypted.bin. Now let's go ahead and see what we have in our encrypted file. Here we can see that we are presented with a garbage value that's not human readable. So we'll be using the decryption method to make it readable again. This step decrypts the encrypted file back to its original form using the same password that is edurata. Each part of this command is similar to the encryption command with the addition of the D flag which specifies decryption mode and D stands for decrypt and we have the input file that is the encrypted.bin and the output is stored in the decrypted .txt. After running this, it decrypts the file named decryptor.txt that matches the original sample.txt file. Now let's see the content in the decrypted.txt file. This confirms that the decryption worked correctly and restored the file to its original state. In the next step, we will be generating a SH 256 hash of the original file. In this step, we generate a SHA 256 hash for the original file to create a unique digital fingerprint. The SH 256 sum command computes the SH 256 hash and the output is redirected to the original hash.txt. In the next step, we are going to calculate the SHA 256 hash of the decrypted file. This step calculates the SHA 256 hash of the decrypted file and stores it in decrypted hash.txt. This allows us to compare it with the original hash to check if both files are identical after encryption and decryption. Now let's compare the hashes of both these files. If both hashes match, it means the original and decrypted files are identical, proving that no data was altered during the encryption and decryption process. Now that we have explored how cryptography protects our data through encryption and decryption, it's time to dive into the other side of the equation. The threats and vulnerabilities that cryptography aims to defend against. While encryption can secure information, understanding the types of cyber attacks that can bypass or challenge these defenses is crucial. Let's move on to the various types of attack that pose a risk to our digital world. First we have is a malware. It is a program or code created to harm a computer, network or server. Now let's see the types of malware. First we have the ransomware. Imagine you're working on an important project and suddenly your computer locks you out. A message pops up demanding money to unlock it. That's ransomware. It encrypts your file and demands payment to restore access. Next is a spyware. This sneaky software hides your computer watching everything you do like a spy. For example, it could record your keystrokes to steal your passwords. Moving on to adwear. Have you ever seen those annoying pop-up ads? That's adear. It bombards you with ads sometimes even redirecting your browser to malicious websites. Next, we have the Trojan. Like the Trojan horse from history. This malware disguises itself as something harmless. For instance, you might download a game, but it secretly installs a Trojan that lets hackers control your computer. Then we have the worms. Unlike virus, worms don't need to attach to files. They spread by themselves often through networks. Imagine someone sends an infected email to everyone in your company and the worm spreads to every computer. Next comes the rootkits. These are tools hackers use to hide their presence. For example, a hacker might install a rootkit to gain administrative control of your system without you knowing. Next comes a key logger. A key logger records every keystroke you make. It's like someone looking over your shoulder while you type your passwords or messages. Last is a botnet. A botnet is a network of infected computers controlled by a hacker. These computers are often used to launch large scale attacks like sending out massive amount of spam. The next type of attack we have is a denial of service attack. A doors attack is like flooding a shop with so many customers that real buyers can't get it. In cyber terms, hackers overwhelm a website with traffic, making it unavailable to users. For example, if a DOSS attack hits an online store during a big sale, customers might not be able to make purchases. Next type of attack we have is fishing. Fishing is a scam email pretending to be from your bank or asking for your password. Hackers use this technique to trick you into revealing personal information. For instance, you might receive an email that looks like it's from PayPal, but it's actually a fake site designed to steal your login details. Next, we have a spoofing. Spoofing is when a hacker pretends to be someone else. Imagine receiving a call from a number that looks like your bank, but it's actually a hacker trying to get your information. In email, they might spoof the sender's address to make it look legitimate. The next type of attack we have is the code injection based which involves inserting malicious code into a system or application to manipulate its behavior. Now let's see the different types of code injection based attacks. First we have the SQL injection. Imagine a website with a search bar. A hacker enters malicious code instead of search term tricking the website into revealing confidential data. This is SQL injection. Then we have the cross-ite scripting that is excess which occurs when a hacker inject malicious scripts into a website. For example, they might post a malicious link on a forum that when clicked runs harmful code on your browser. The next type of attack we have is a social engineering attacks. Social engineering is all about manipulating people rather than breaking into systems. For example, a hacker might call an employee pretending to be from IT support asking for their password to fix an issue. The next attack is an insider threat. Sometimes the threat comes from within. An insider threat that could be an employee who misuses their access to steal data or cause harm. For example, an employee with access to sensitive files might leak them to the public. The last type of attack we have is the AI powered attack. This is like using artificial intelligence to create deceptive content such as deep fake videos to mislead or deceive. Under AI powered attacks, we have deep fake. Deep wakes use AI to create realistic but fake videos or audio. For example, a hacker might create a deep fake video of a company CEO making a false announcement causing panic. Then we have is the AI generated social engineering. Hackers use AI to craft convincing fishing emails or messages making them more likely to deceive people. For example, AI could generate a personalized fishing emails that look exactly like a message from your boss. Now that we have discussed the types of cyber attacks that can compromise our digital security, it's essential to understand who is behind these attacks. Not all hackers are same. Some work to protect our systems while others seek to exploit them. Let's explore the different types of hackers and their motivations. First, we have the black hat hackers. Blackhat hackers are the bad guys in the hacking world. They break into systems illegally, often to steal data, install malware, or cause harm. Imagine someone breaking into your house to steal valuables. That's what these hackers do to the computer systems. Next, we have is the white hat hackers. These are good guys. They use their hacking skills to find and fix security flaws before the bad guys can exploit them. Think of them as security experts who test locks and doors to make sure your house is safe. Moving on to gray hat hackers. Gray hat hackers are somewhere in between. They might break into systems without permission but do it to point out flaws, not cause harm. It's like someone breaking into your house to show that your lock is weak but without asking you first. Next we have is the activists. Activists use hacking as a form of protest or to promote a political agenda. They target organization or governments they disagree with, often to expose information or disrupt operations. It's like someone spray painting a message on a public building to make a statement. Moving on to state nation sponsored hackers. These hackers work for governments and are often involved in cyber instance, stealing sensitive information from other countries or disrupting their operations. Imagine a spy gathering secrets from another country. Last we have the scripkadies. Stupkadies are amateurs in hacking world. They don't have deep knowledge but use existing tools and scripts to carry out attacks. It's like someone with no technical skills using a lockpicking kit they bought online to break into a house. Now that we have identified the different types of hackers and their motivations, it's important to understand how organizations can defend against these threats. One of the most effective ways to do this is through penetration testing. a proactive approach that simulates cyber attacks to uncover vulnerabilities before malicious hackers can exploit them. Let's take up a quiz in what we have learned before. Question number four. Which type of hacker is known for their malicious intent and seeks to steal sensitive information? And the options are A. Grayhat hacker, B black hat hacker, option C script kitty, and option D ethical hacker. If you know the correct answer, please comment below. Now let's talk about penetration testing. Penetration testing is a security exercise in which security experts attempt to find and exploit vulnerabilities in a computer system. The purpose of this simulated attack is to identify any weak spots in a systems defenses that attackers could exploit. Penetration testing helps an organization discover vulnerabilities and flaws in their systems that they might not have otherwise be able to find. This can help stop attackers before they start. as organization can fix these vulnerabilities once they have been identified. Now let's talk about the different types of penetration testing. First we have the open box penetration testing. It is also known as the white box testing. In this type the tester has full knowledge of the system being tested. This includes access to architecture documents, source code and network information. The purpose of open box penetration testing is used to simulate an insider threat or a highly knowledgeable attacker who has deep knowledge of the system. The goal is to identify vulnerabilities that may be difficult to spot without inside information. Next, we have the closed box penetration testing which is also known as the blackbox testing. Here the tester has no prior knowledge of the system. The only information they have is what a real external attacker would. This means no internal details or documentation. The purpose of closedbox penetration testing is to simulate an external attacker's approach starting from scratch and attempting to gather information and exploit vulnerabilities. Next we have is the covert penetration testing. In this scenario, a penetration test is carried out without the knowledge of the IT or security teams except of the few key individuals. This is sometimes called as double blind testing. This type of attack aims to test how well the security team responds to a real attack without a prior notice. Next we have the external penetration testing. External penetration testing focuses on external facing assets such as web application servers and firewalls which are exposed to the public internet. The tester tries to exploit these from the outside mimicking an attack from an external threat actor. It accesses how vulnerable an organization's public facing infrastructure is to attack. Next we have the internal penetration testing. In internal testing, the tester assumed the role of someone inside the network such as a rogue employee or the attacker who has already breached the parimeter. It evaluates the security from the inside, identifying what an attacker could access if they gain entry to your internal network. Now that we understand what penetration testing is, let's break down the key phases involved in this process. The first phase is pre-engagement. This is where the scope and goals of the testers defined. The tester and the organization agree on what systems will be tested and under what condition. Next, we have the information gathering. In this step, the tester collects as much data as possible about the target system, including IP addresses, network details, and other valuable information that could help in identifying vulnerabilities. Following that, there is threat modeling. This is where the collected information is used to map potential threats and the areas most likely to be targeted by attackers. Then comes vulnerability analysis. Here the tester identify weaknesses in the system that could be exploited such as outdated software or poor security configurations. Once vulnerabilities are found, it's time for exploitation. The tester will attempt to exploit those weaknesses to gain unauthorized access just like a real attacker would. After that is post exploitation. This phase involves assessing the impact of the breach. The tester analyzes the extent of access gained and what sensitive data could be exposed or compromised. Finally, there's reporting. In the last phase, the tester documents the findings including vulnerabilities and recommendations for improving security. But before that, we have a quiz in what we have learned before. Question number five, in which phase does the penetration tester attempt to exploit vulnerabilities found during the scanning phase? And the options are A reporting, B exploitation, C post exploitation, and D reconnaissance. If you know the correct answer, please comment below. [Music] Ethical hacking is like having a good guy test your computer or network to find and fix any weak points before bad guy can use them. It's a bit like inviting a friendly detective to check if your digital doors and windows are secure. So instead of causing harm, this ethical hackers help strengthen your online defense, making sure your information stays safe from cyber threats. This way, businesses can stay ahead of potential problems and keep their digital spaces secure and trustworthy. Having an ethical hacker ensures that your computer is safe and secure. So what exactly is ethical hacking? Ethical hacking is a practice where expert intentionally test computer system to find and fix security vulnerabilities. The objective is to improve cyber security and stop unwanted access, data breaches and other cyber threats as compared to malicious hacking. Ethical hacking is a proactive strategy used by organizations to protect their digital assets. Maintaining a safe and powerful digital environment, safeguarding important data and staying one step ahead of hackers all depend on ethical hacking. Now let's explore several reasons why ethical hacking is important. And the first reason is it prevent attacks. It identifies and fixes security weaknesses before a hacker can take advantage of them. Next, strengthens security. Improving overall cyber security helps organizations stay ahead of constantly changing cyber threats. The next reason is ensures compliance with industry standards and regularizations related to cyber security. And the next reason is protects information. It protects private information while gaining and maintaining the trust of stakeholders and clients. Then manage risk proactively. It facilitates the early identification and reductions of possible cyber threats and encourages a proactive strategy for cyber security. Let us now discuss on the different types of ethical hackers. Basically there are three types of hackers and they are white hat hacker, black hat hacker and gray hat hacker. So let's explore a bit deeper into these different types of ethical hackers. So the whitehead hackers also known as ethical hacker are cyber security experts who conduct authorized assessments of systems, networks and applications. Their primary goal is to identify vulnerabilities and improve security defenses. Whitehead hackers use their expertise to conduct penetration test, vulnerability assessments and security audits. They collaborate closely with organizations to identify and address vulnerabilities before malicious hackers can exploit them. Example, a whitehead hacker hired by a financial institution conduct routine security assessments on online backing systems. They identify potential vulnerabilities such as flaws in the website code or configurations and work with the bank's IT team to implement security measures to safeguard customer financial information. The whitehead hackers play an important role in the proactive defense against cyber threats, assisting organizations in maintaining the integrity and security of their digital assets. The next type of hacker is blackhat hacker. Black hat hackers are people who engage in malicious behavior using vulnerabilities for personal gain, financial gain or malicious intent. They operate outside the bonds of law and ethical standards. Blackhead hackers may steal sensitive data, gain unauthorized access to systems, and launch cyber attacks for financial gain, or use ransomware attacks to extort money from victims. For example, an advanced hacker penetrates a company's network, steals customer data, and sells it on the dark web for a profit. In addition, a blackhead hacker could launch a distributed denial of service attack on a competitor's website, disrupting their online services. It is important to note that blackhead hacking is both illegal and unethical. Blackhead hackers activities represent serious threats to individuals, organizations, and society as a whole. Ethical hacking as practiced by white hat hackers seeks to reduce these threats by identifying and addressing vulnerabilities before they are used by malicious actors. The next type of hacker is gray hat hackers. Grey hat hacker falls somewhere between ethical and potentially questionable behavior. They may discover and disclose vulnerabilities without explicit permission raising ethical concern about responsible disclosure. Greyhound hackers may discover security faults in system, network or applications without authorization. While their intentions are good, their actions may not always be consistent with legal and ethical standards. Greyhand hackers discover a software weakness in a widely used application. Instead of immediately informing the company, they publicly disclose the vulnerabilities in order to draw attention to the problem and potentially put pressure on the company to address it. It's important to note that grey hat hacker can be uncertain and isn't always viewed as a responsible or ethical approach to cyber security. Responsible disclosure and collaboration with organizations are fundamental principles of ethical hacking practices. Next, let's have a look at the roles and responsibilities of an ethical hacker. First, permission and authorization. Prior to conducting any security testing, obtain proper authorization. Ethical hackers must obtain explicit permission from the organizations or individual in charge of the system they are testing. Next, vulnerability assessment. Determine and evaluate potential security risk in computer systems, networks, and applications. This involves looking into the systems architecture, configurations, and code to identify faults. Next, penetration testing. Penetration testing involves simulating real world cyber attacks in order to find vulnerabilities and evaluate the effectiveness of existing security measures. This could include attempting to gain unauthorized access, increasing privileges or manipulating the systems to find weaknesses. Next, network security testing. It evaluate the security of networks including routers, firewalls and other network devices to ensure they are properly configured and resistant to potential attacks. Next, application security testing evaluates the security of software applications by reviewing source code, analyzing application behavior, and identifying vulnerabilities that attacks could exploit. Next, wireless network testing. Test the security of wireless network to identify weaknesses in encryption, authentication and access control. Next, social engineering test. Use social engineering test to evaluate the human component of security. This may include fishing simulations in which ethical hackers attempt to trick employees into disclosing sensitive information. Moving on, let's discuss the key concepts of ethical hacking. Ethical hacking involves a set of key concepts and principles that guide the practice of security testing within ethical and legal boundaries. And here are some of the key concepts of ethical hacking. First, authorization. Before conducting any security testing, ethical hackers must obtain explicit and legal permission from the organizations or individual owning the system. Unauthorized hacking activities are illegal and can have serious consequences. Next, legal and ethical boundaries. Ethical hackers must adhere to the legal and ethical boundaries set by local laws and professional codes of conduct. They should avoid any activities that violate privacy, confidentiality, or the law. Next, informed consent. Obtain informed consent from stakeholders before conducting any security assessments. This ensures that the organizations or individual being tested is aware of and agrees to the testing activities. Next, purpose of testing. The primary goal of ethical hacking is to identify and address security vulnerabilities, weaknesses, and potential risk within a system. The goal is to improve security, not cause harm or damage. Then we have confidentiality. Ethical hackers must keep all information obtained during security testing strictly confidential. This include information about vulnerabilities, sensitive data and anything else relevant to the organization security posture. Next, what skills and certifications should an ethical hacker obtain? So the skills are networking knowledge, understanding of networking protocols, architectures and services. This include TCP IP, routting, switching, firewalls and VPNs. Next, operating system proficiency. Familiarity with various operating systems including Windows, Linux, and Unix is important. Knowledge of system administration task is crucial. Next, programming and scripting. Proficiency in programming languages such as Python, C, C++, or scripting languages like Bash. This is important for writing custom scripts and understanding code vulnerabilities. Then web application knowledge, understanding of web technologies, web application architecture and common vulnerabilities such as SQL injection, cross-sight scripting and cross-sight request forgery. Next, wireless technologies. Knowledge of wireless networking protocols and security measures. Having familiarity with tools used for wireless network penetration testing is very important. Then we have cryptography. Understanding of cryptographic concepts and protocols as well as the ability to identify and assess cryptographic vulnerabilities. Then security tools proficiency experience with a variety of security tools including vulnerability scanners, network sneepers and penetration testing frameworks. Now that we have covered the skills required to be an ethical hacker, let's look at the top cyber security certifications that can help you become a certified ethical hacker. About the certified ethical hacker, start your career with the most popular ethical hacking certification in the world that is the certified ethical hacker CE. This top-notch program offers structured training for aspiring cyber professionals, globally acknowledged and enabling work flexibility. Master the five phases of ethical hacking through a comprehensive curriculum including hands-on experience in cyber Q labs. Also, you can choose between live online or hybrid learning options for a flexible educational journey. Check out the C V12 certified ethical hacking course by Adurika in collaboration with EC Council and offers the chance to obtain the CV V12 certification. This training which focuses on fundamental cyber security skills certifies knowledge of network security, cryptography and other areas transforming participants into certified ethical hackers prepared to tackle cyber security issues. The next certification is certified information system security professional. The CISSP certification is a globally recognized credential for cyber security professionals. It validates expertise across various security domains and require passing an exam showcasing a high level of competencies in cyber security. Check out the highly regarded CISSP certification training course in information security as well to achieve leadership roles upskill and obtain this certification. Edure offers the best training available. The CISSP certification points to a high level of managerial and technical proficiency for effectively overseeing security frameworks in businesses. The next certification is CompTIA Security Plus. The CompTIA Security Plus certification is recognized worldwide and confirms fundamental skills needed for essential security task and for starting a career in IT security. CompTIA Security Plus is your gateway to a cyber security career, equipping you with a foundational skills, assessing practical abilities for real world challenges and keeping you updated on the latest trends in cyber security technology and techniques. Edureka's collaboration with CompTIA Security Plus provides an opportunity to obtain the globally recognized CompTIA security plus certification training course. The training which focuses on critical cyber security skills for administrators validates knowledge of risk management, thread handling and intrusion detection. This certification enables you to manage security incidents effectively. Now let's talk about how much an ethical hacker typically earns. In India, the average base pay varies from 24,000 rupees to 1 lakh per month. Meanwhile, the average annual salary for an ethical hacker in the United States is $134,000. Salaries for highly skilled professionals with advanced certifications and years of experience may be higher than this range. [Music] Let's get started with the phases. So the first phase is reconnaissance and also I'll be explaining each phase of ethical hacking with the help of an analogy so that it's easy for beginners to understand. Suppose you're a beginner, it's the first video you're watching on ethical hacking or maybe you've watched a little videos and you know you don't have a lot of understanding of what ethical hacking is then it'll be easy for you to understand. So let's start with the first phase. Firstly I'll tell you what this analogy is. So the analogy goes something like this. Suppose there's an enemy layer at a location and this enemy layer has got a lot of destructive weapons and you are the army chief who's assigned to you know attack the enemy layer and take control of this. So my question to you is if you were actually an army officer you know who's assigned to make a surgical strike you've got a lot of forces you've got the army you've got tanks you've got air force all at your command so would you just take all your forces and go attack? I don't think so. Yeah, because first you'll have to create a plan and before that you'll have to understand the enemy layer. So you'll collect basic information such as the location of the layer, how to get to that location from the army base. You'll collect more information about the building, the number of floors and the surroundings of the building. So similarly, when it comes to ethical hacking, you cannot just, you know, use tools or type something in your computer and just hack the target. So to hack the target the first thing you have to do is understand the target. So this phase where you understand your target is reconnaissance. So reconnaissance is basically the phase where the ethical hacker collects information about the target so that it's easy for him to understand how to actually hack the target. So some of the basic information you would want to collect are the first one would be the IP address of the target. Suppose you're trying to hack a particular system in a network then you would want to know the IP address of the target because you know the IP address uniquely identifies the system in the network. The next thing you would want to know is the IP address range. Suppose there's an organization with you know hundreds of computers and you want to hack the whole network. You don't know which computer or which system has got the lowest security. So to check that you would need the IP address range of the whole organization or the network. The next thing you would want to know is the network. You would want to know the architecture of the network. And finally, you would want to know about the DNS record. So these are very basic things, very basic information to collect about your target. And depending on what your target is, this information might vary. So now I'll be talking about some of the most popular tools used for reconnaissance. The first tool I'm going to talk about is search engine. So I'm sure you're familiar with Google, Yahoo, and you know, Bing. So I'll give you an example. Okay, imagine yourself in this situation where you are an ethical hacker. You're the best in the city. There's no one else who can compete your skills of ethical hacking. And one day you're at your office and this guy, a CEO of a big organization comes to you and he hands out the name of a website and he wants you to test for security loopholes or weaknesses on his website. and he just walks away. He doesn't speak a word. He's an introvert, you know. So, at this point, you only know the name of the website. You have, you know, no idea of what this application is or what your target is. You only know the name of your website. So, what would be the first thing you do? So, the first thing you would want to do is use the name of the website into a search engine. So, maybe Google the name of the website. There are different search engines you can use. There's Google, there's duck.go, go. There's Yahoo, there's Shodden and a lot of search engines. So, you just Google search or use whatever search engine you want to and then find information about your target. So, the first thing you'd get is the URL of the target, the URL of the website using which you can find out other information such as the IP address, the IP address range and whatever information I told about in the previous slide. So, this is the first thing you would do. The next tool you would use which is one of the most popular tool for reconnaissance is NS lookup. So NS lookup is a DNS quering tool and it's mainly used to get the domain name and the IP address map of your target. So suppose there's an organization like maybe you want to you know collect information about the same website. Then you would run a nsookup search on that and you'd collect information such as the domain name, the IP address map, the range, the IP address range and such information. The next tool you can use is who is lookup. Who is lookup is a browser based query and response tool and it's mainly used to get the registration and delegation details of your target. So suppose your target application requires a login. So maybe the username is the email ID and using who is lookup you can find out who the website is registered to the contact information and many other information. So these information will play a vital role when you're actually trying to hack the application. So these are the most popular tools for reconnaissance. Moving forward to the next phase of ethical hacking. So the next phase is scanning. Now let's come back to the surgical strike example. You found out the location of the enemy layer. You know you found out the way how you can go from the army base to the enemy layer. And you also found out about the surroundings. But is this information enough? You found the enemy layer. You found the building. But can you just go attack now? No. You need a strategy. You need a plan. And for this, the main thing you would require to know is which point of the building you can enter from. So basically, you scan the whole building to see which points you can enter from and whether these points are blocked or are they open because obviously there are enemies. They have got destructive weapons. So maybe a door is you know set up with a bomb with an explosive. So you have to scan the building so that you can find a safe way to you know enter the building and attack. Similarly when it comes to scanning in ethical hacking you found out the IP address the IP address range and many information but it's not enough. Now it's time to find out those points on your target which has got a weak security and where you can try to hack the target from. So this phase where you find the weak points on the target is scanning. The scanning is basically the phase where you find out points on the target system or the network from where the hacker can try to hack the target. So these are the weak points on your target that you can start the hack from. Some of the information you would want to collect during your scanning are there's active ports and active hosts. So these are basically the ports and the hosts that are live and running on the system. So there's no point if there's an organization and there's a network of 100 computers and 10 computers out of the 100 computers are turned off. There's no point in finding out information about the 10 shutdown computers. If you want to hack the network, you would want to hack one of the target that's live and up and running. And that's why you would want to know about the active ports and the active hosts. Then you would want to know about the services being run on your target. So these services could be security services like firewall intrusion detection because obviously you wouldn't want your target to know that it's being hacked. So you would want to be a little careful. So you'd find out services that are being run and then you would want to collect information about the application and the operating system. So when I say vulnerable application and operating system, it means the application or the operating system that is being used by the target which is unpatched or outdated. So most of the time when you are you know scanning your target you find out application or operating system that are unpatched which have got security loopholes and you can use these weaknesses to hack your target. Now let's see which are the most popular tools used for scanning. The first one is openvas. Open is an open-source framework with several services and tools for vulnerability scanning and management. The next tool is Nikto. Nikto is a command line vulnerability scanner and this tool uh scans web servers for dangerous files, CGIs and outdated services. So like I previously told while finding out information about the vulnerable application or operating system that if you find outdated services or unpatched services, there's a high chance that you can find out weaknesses on your target. So Nikto is a one such tool that will give you information about these outdated services. The next tool I'm going to talk about is wires. Wires is a tool especially used for wireless networks. Suppose there's a Wi-Fi network and you want to you know scan this network then you can use wires and this is an open-source packet analyzer and gives a lot of information about the wireless network. The next tool and my most favorite tool is Nessus. Nessus is a very powerful tool that provides high performance data capture. And the reason I like Nessus is it provides various types of scans. So depending on what information you want about the target or what type of target is you know your system or the network, you can select different scans. So each scan will give you different results using which you can hack the target. So these are some of the most popular tools used for scanning. So moving on to the next phase that is exploitation. So now you've collected enough information about your target. Your plan's ready. You know where to enter the building from. You know how to attack. It's time to attack. So now you call your force, your tanks, your army and then lead the attack and then gain control of the enemy layer. Similarly, when it comes to ethical hacking, you use different exploitation tools because your tools are like your force, like your army. and you use these exploitation tools to hack the target. So this is the phase where the hack actually happens. So exploitation is a phase where the hacker takes advantage of the weakness and loopholes found on the target system or the network and then runs appropriate tools to hack the target. So there are different steps for you know using exploitation. The first thing is selecting the right attack. So not every attack is applicable to every target. So depending on how your target is, depending on what weaknesses you found on the target, you'll have to select the right the appropriate attack. Then you will have to launch the attack on your target and finally you will gain access of your target. So some of the most popular tools used for exploitation are the first one is beef. Beef is a tool mainly used for penetration testing and it's a tool that leverages you know browser vulnerabilities. The next tool is one of my most favorite and uh this is the tool that I mostly use. It's metas-ploit. It's one of the most popular exploitation tools and uh this tool has got hundreds of scripts to hack. The next tool I'm going to talk about is SQL map. SQL map is a tool that automates detection and exploitation of SQL injection flaws. So I'm sure if you're a beginner, you don't know what SQL injection is, but stay tuned. You'll be learning about SQL injection and a lot of different hacking methods in the coming up videos. So this tool is mainly used to take over database servers. Moving on to the next phase, it is maintaining access. So now the surgical strike is done. Will you just leave from the enemy layer? No, you wouldn't. Now you would take actions to maintain you know the control over the enemy layer because you wouldn't want your enemies to occupy the layer again and then store destructive weapons because if they did if you just left and the enemies came back you would have to carry out another surgical strike to gain control over your enemy layer. So this is maintaining access when it comes to surgical strike. So when it comes to maintaining access in ethical hacking, the hacker maintains you know a connection between the target so that if he wants to use a target later in time, he doesn't have to you know start the attack right from the scratch. He just directly access the target. So this phase is maintaining access. So maintaining access is a phase where the hacker installs softwares or makes changes on the target system after the target has been hacked so that he can access the target later in time directly without having to you know hack the target right from the scratch. So some of the ways are doing this are there are different ways but I've listed down you know some of the most efficient or the most popular ways. So the first one is installing backd doors. So back doors are basically used to bypass login or authentication. Then the next way is creating new users. Suppose your target requires you to login to do something on your target. Then you would create a new user with a new username and password and uh later in time when you want to access the target you would use this username and password to log into your target. Another thing you can do is escalate the privileges. Suppose you want to run certain system commands on your target or certain system services on your target. And to run these system services, you need super user privileges. Then what you would do is make a normal user a super user and then use this user to run system services on your target. The next thing you can do is install rootkits. Rootkits are softwares used to enable access on your target. And finally, you can use Trojans. So let's see which are some of the most popular tools used for maintaining access. The first tool is powerslo. Ppploit is a tool mainly used for Windows operating system. And this tool is used to connect to the victim's powershell. So if you've used a Windows operating system, you should know that you know a PowerShell is a place where you can run system commands from. So when you're a hacker and you hack a Windows operating system and you want to do something on that system maybe you know delete the files copy the files or run any services which actually you shouldn't do you shouldn't be you know deleting the files or anything because you're on the track of being an ethical hacker but I'm just telling you for example if you want to do any such thing then having access to the victim's power cell will be really useful. The next tool I'm going to talk about is Vei. Webly is a PHP web shell that can be used to install stealth backd doors or to manage web accounts and then you can use DNS to TCP. DNS to TCP is a network tool that relays TCP connections through DNS traffic. You probably don't understand a lot when I'm trying to explain about these tools but you know given time when you're learning maybe watching the next videos I'm sure you'll understand all these topics. So for now just know about these tools and yeah that's all. So let's move on to the next phase that is covering tracks. So you're done with the surgical strike and you've gone control over the enemy layer. So the main thing you would want to do is keep your strategy, your plan confidential because you wouldn't want the enemies or any unauthorized person to know what your strategy or plan or any information about your surgical strike. So you erase all the details regarding this. But when it comes to ethical hacking, it's a little different. A hacker erases all the details, all the information regarding his identity and also how he carried out the exploit so that the target doesn't know that someone has hacked the target first of all and if at all he knows that his system was hacked then he shouldn't be able to trace back who this hacker was. So covering tracks is a phase where the hacker hides his identity and also the way the exploit has happened. So he wouldn't want the target to know how he was hacked. There are different ways of doing this. Some of the most common ways are clearing the cash and cookies. Then you would want to tamper the log file. Suppose like I told you in you know one of the slides if your target requires you to loging in using a username and password and you've done that you've logged in using a username and password then you would want to delete these log files so that the target doesn't know that some other user had logged into his system then you can close the ports that you might have started or stop the services that you might have started in order to install back doors rootkits or whatever purpose you did it for. So this is covering cracks and the final phase of ethical hacking is reporting. Now you're done with the surgical strike. You've cleared all the evidence, all the clues, all the information. And now you have to inform your higher officer on what actually happened. So you would inform him how you found the layer, what was your strategy, what was your plan, what weaknesses you found on the enemy layer, and how did you actually gain control of the enemy layer. So you create a documentation of it. Similarly, when it comes to ethical hacking, instead of reporting to your higher officer, you report to the target organization, you tell them what weaknesses you found on the target, which weaknesses the target was vulnerable for, and which attacks you used to hack the target. So, reporting is basically a phase where the hacker creates documentation of the weaknesses and loopholes found on the target. the way he used these weaknesses and loopholes to hack the target and also mention certain precautions that the target can take to make the security better. So like I told you earlier, this is the phase that differentiates a malicious hacker from an ethical hacker. I'll tell you why now. Because as an ethical hacker, you know what you should do? You should tell the target organization about the information found the way you hacked the target and also tell them how they can make the security better. But a malicious hacker wouldn't do this. A malicious hacker would hack the target, would hide his identity and whatever purpose he hacked the target for, he just do it and you know vanish. So this is the phase that differentiates a malicious hacker from an ethical hacker. So these are the six phases of ethical hacking. So if you want to hack a target successfully and efficiently, I suggest you follow these steps. And maybe while you're practicing you think reporting is not really that important because you know you have your own target you're trying to hack it you hack it successfully you might think why should I create a report for this but let me tell you make a habit of creating reports right from the beginning so that when you actually are working for an organization it's pretty simple you know what details to include and it'll be very helpful so you know don't take any of these phases lightly practice each phase you know with dedication now let Let me tell you about some of the great hacks that have happened over time. I made a list of four hacks. I know there are hundreds of great hacks that have happened, but I've made a list of four hacks just to give you the idea of how powerful a hacker can be. So the first hack I'm going to talk about is the FBI hack. So in 2016 the entire database of FBI was hacked and the identities of all undercover FBI and Homeland Security agents was made public due to which a lot of lives were in danger. The next hack is the NASA hack. A hacker hacked into NASA and downloaded the source code used to run the International Space Station. And to fix this issue, NASA had to shut down its network for 3 weeks. So just imagine how powerful you'd be if you have the source code to run the International Space Station on your system. So this is how powerful you can be as a hacker. But you can only do this when you've got enough skills. Let's move on to the next hack that is the commercial sites hack. A student of a university launched a DOS attack with 70 plus computers on 50 plus networks which affected a lot of commercial websites such as eBay, Amazon, etc. due to which these commercial sites face a lot of business loss. And the final hack I'm going to talk about in this session is the noble hack. So a hacker hacked into different banks around the world and then stole money from these banks and instead of using it for his own self, he donated this money to the countries living below the poverty line. So his intention was noble and that's why I've named this the noble hack. Though his intention was noble, what he did was illegal. And all of these hacks, the four hacks I spoke about was just to give you an idea of how powerful you can be. But all of these hacks were made for illegal purpose. As an ethical hacker, you should not be involved in any such illegal activities because that's not what ethical hackers do. As an ethical hacker, you should always contribute to make the security of the system, the network, basically any digital, you know, appliance or digital device, the security of these digital devices better. [Music] So the first point of comparison is function that is what each of them do. So ethical hacking helps us find different vulnerabilities in the system and helps to report against it while cyber security helps protect the data and the system from malicious activities. So coming to the mode of action the focus of ethical hacking is on how to attack the system while the focus of cyber security is how to protect the system that is ethical hacking is on the offensive side where cyber security is on the defensive side. Now coming to the spectrum, ethical hacking is a subpart of cyber security while cyber security is a broad domain that includes a range of security techniques which includes ethical hacking. Now coming to the purpose, the purpose of ethical hacking is to perform different penetration testing to find the vulnerabilities or exploit them. While the purpose of cyber security is to detect problems and guard the system against these security breaches. Now coming to the production environment, ethical hacking requires to evaluate the systems of the organizations according to the security policies that are pre-existing in the organization while cyber security involves auditing all the security technologies that are already being used in these businesses and look for infringement. Next comes update. So here we are talking about how ethical hacking requires the system to regularly get tested in order to find any bug and fix any weaknesses that may already exist. While in cyber security it has a routine checkup that is a maintenance to keep the security system up to date every day. After this we're talking about reporting. So in ethical hacking it is very important to make reports and documentation of the entire process of hacking. Like starting from the very initial phase to final phase it is very important to understand the entire process of hacking. While in cyber security more than documentation it is more important to have accountability for creating a systems access rights. Now talking about ease of learning, ethical hacking requires intensive creating thinking to crack into different systems of organization while in cyber security you can learn different technologies and tools in order to get started. So in ethical hacking the popular job roles include penetration tester and security manager while in cyber security the job roles includes security analyst or SOC engineer. Now coming to the average salary in India the average salary of any ethical hacker is around five lakhs peranom while in the US it is around $1AK per year. So talking about the average salary in India the average salary of an ethical hacker is around 5 lakhs peranom while in the US it is $1 per year whereas in cyber security in India the average salary is around 6 lakhs peranom and in US it is $117,000 per year. So now let us understand which one is better. So depending on how an organization approaches the challenge, cyber security and ethical hacking play critical roles in system security. Data and computer assets for a specific company's networks are safeguarded by cyber security while anything that goes into assaulting these components with authorization is considered as ethical hacking. So the cyber security experts role is to safeguard informatics against any danger before, during or after any violation has occurred. While ethical hackers go by many titles including white hat which is considered the best security professional with experience in discovering and leveraging flaws and faults in networks much like any illegal hacker would do. So these hackers utilize the same tactics but with authorization and legally before malvolent intruders can get access. The cyber security and ethical hacking sectors are more important than ever because of many online threats and assaults. The need for cyber security experts and ethical hackers is continuously expanding. It depends upon your interest, skills and relevant educational background to answer cyber security versus ethical hacking which one is better. So choose your career option keeping these factors in mind. [Music] Now talking about what fishing actually is on a day-to-day base. Everyone that use internet use a web application. You can be using a web application through your apps on your smartphone or some applications on your desktop or you might be using a web browser. Now consider the case where you're using a web browser and you have to shop something online. Now you search for a product and you come across different websites and you like the product on two different websites. So one of these websites is a very famous, very popular, very trustworthy e-commerce website and there is another website which is selling your product for the same price and uh or maybe for a more discounted price but it is not popular. you've never heard of that e-commerce website before. Now you choose to pay for your product online and for that you might have to enter your credit card or your debit card details. Now the question is which website would you trust more with your personal details with your sensitive details that is your credit card details? Obviously, you would be less hesitant while you're entering the credit card details onto the e-commerce website that is trustworthy and you would be more hesitant, you would be worried while entering these details onto the website that you are hearing the name for the first time. This is because you don't trust the new website, the other website, the popular website. You've heard of the name before, you've used it before and you have a trust factor with that website. So this psychology is what hackers take advantage of in fishing attacks. So hackers take advantage of this trust factor and they fake themselves as a trustworthy entity to steal your sensitive data or your personal data. So fishing is a attack of gathering sensitive information of a target such as username, password, email ID or other sensitive information maybe your bank details, your credit card, your debit card details by disguising themselves as a trustworthy entity. So as I told you previously if you are entering any sensitive information maybe your card details onto a trustworthy website you wouldn't be hesitant. So ill fishing attacks a hacker disguises himself as a trustworthy entity. Then he makes you he tricks you into entering your sensitive information into that fake web application. So this is fishing. Now let us see how fishing works. Like I told you fishing is a web- based application and this is mainly used to steal credentials. So we need a web application that is using a web server. Now every web application is connected to a web server. When you're using a web application, what happens is there is some data, the packets, the information that is being sent from your web application to the web server and from the web server back to your web application. Now this is how the communication between the web application and the web server happens. Now what happens in fishing attack is the hacker disguises himself as this web server. So you think that you are communicating with the genuine with the actual web server, but in reality you're just communicating with the fake web server or the fake web application that the hacker has built. And when you enter sensitive information onto this web server or this web application, the hacker steals your credentials. So this is how fishing works. Now let's see what are the steps for a fishing attack. So the first thing a hacker must do is create a fake website because like I told you a fishing is a attack where a hacker disguises himself as a trustworthy entity. So first he has to create a fake website a fake of a genuine website and to trick the victim to enter the credentials. The next step is to send this fake website to the victim. Now suppose a victim is trying to access Facebook for example. If he goes to the web application by himself, uh maybe he'd enter a URL of the website or he would search for that website on a search engine and then use the link to go to that website. Now when he does that, he goes to the actual the genuine website and not to the fake website. So the second step is that the hacker has to send this fake website to the victim where the victim enters the credentials. The third step that happens is the victim thinks that this fake website is a trustworthy website and enters credentials and finally the hacker gets the credentials. So this is how fishing works. Now let's see how you can use fishing to steal credentials of a victim. There are different ways of using fishing and fishing is basically stealing credentials by disguising yourself as a trustworthy entity. Now how you use fishing depends on your victim. So there are different ways you can use fishing and I'll be talking about two ways. The first one is using already existing tools. There are different tools that are already available. Some of these tools are already pre-installed in certain penetration testing operating system and most of them almost every one of them are present online on the internet and most of them are available on GitHub for you to download and use. So the first thing I'll be telling you the first way is using tools. So for this demo I'll be using SE toolkit which stands for social engineering toolkit and there are different tools like VM social fish that I'm not going to be showing because it's basically the same thing you're trying to do. And when you're using a tool there are two things you can do. The first thing is using pre-available templates. So most of these fishing tools come with preavailable templates and you just have to use these templates to create a fake web application. So what if you want to fake a web application or creating a fishing page of a web application that is not pre-installed. In that case you can go for the second option that is cloning a website. So in this method what you do is you enter the URL of the web application that you want to fake and then the tool creates a clone of that web application. So first let us see how you can use SE toolkit tool that is social engineering toolkit tool to clone a website using pre- available templates. So to enter this tool I'll be typing SE toolkit. I'll be getting a lot of different options that I can choose from. I'll be using the first option that is social engineering attacks because that's what facing comes under. So I'll choose option one. I'll hit enter. And there are different websites. I'll be choosing option two that is website attack vectors and then I'll be choosing option three that is credential harvester attack method because we are trying to seal the credentials of the victim. Now I've got different options like I told you you can use pre-available web templates or you can use site looner. So first I'll be telling you how you can create a fake fishing web page using preavailable template. So I'll choose option one. The first thing you have to do is enter the IP address that the results of the fishing has to be returned to because when you create a fake web application and the victim enters credentials, those credentials has to be sent back to you so that you can use them. So you have to enter your IP address. To find out your IP address, you can open the terminal then type if config and you can see different interfaces. And because I'm using a local machine for this demo, I'll be using Ethernet 0 and the IP address for this is 192.168.1181. So I'll copy this. And as you can see that this tool is by default taking the same IP address. I can just go ahead and hit enter. And suppose you want to change the IP address. Suppose you have different interfaces and you want to use a different interface. In that case you can use the IP address of the other interface. Uh for this demo I'll be keeping the IP address same and I'll just go ahead and hit enter. Now there are three options. There is Java required, there is Google and Twitter. And for this demo I'll be creating a fishing page for Google. So I'll choose option two that is Google. Now the tool will run. It will create a web application a fishing web application and I'll just hit enter. Uh now the fishing web application is ready. So I'll just open the browser and because I'm running this on my local server, I'll just hit local host and enter. Well, you can see that uh there is a Google login page that is asking for an email id and a password. And as you can see in the URL that it is not the actual Google page because the actual Google login page would have a different URL. Now what you have to observe is what is shown on the terminal because whatever the victim enters those details can be seen on the terminal. Now what you have to do after creating a fake fishing page you have to send this page to your victim and when you send this page to your victim and the victim enters some details maybe abcxyz.com and some random password and then he hits the enter button. You can see on the terminal that the tool the fishing tool shows the email id and the password that is entered by the victim. So this is how you can use preavailable templates to create a fishing page. Now what if you want to create a fishing page of a web application that is not available as a web template. In that case there is another option that you can use that is the site cloner. So let's see how you can use site cloner to create a fishing page. Well, for this demo, I'll be creating a fishing page of Edureka community and the URL for that is edureka.co/ community. I'll hit the enter button. Edureka community is basically a forum where people can ask questions, their doubts regarding various technologies and there are other community members that answer to your questions. So uh there are different options here latest most viewed there's ask a question it's also integrated with a blog and what we are actually interested in this part that is the login and sign up because we want to seal the credentials so this is what we are interested in and I want to clone this site to create a fishing page so I'll just copy the URL of this page now coming back to the terminal I'll enter the fishing tool again that is SE toolkit and I'll choose option one. Here I'll be choosing option two that is website attack vectors. And similar to the previous way I'll be using credential harvester attack method that is option three. And here instead of using uh option one that is web templates I'll be using a site cloner that is option two. And similar to the previous time it asks for the IP address. I'll hit enter because this is the IP address I want to use. And now you have to enter the URL for the web application that you want to clone. And because I copied the web application of Adurea community, I'll just paste it here and I'll hit enter. Now this tool will take a little bit of time to clone the website. And well, it is ready. Now let's see how the fishing website looks. I'll open a new tab. I'll just close the other tab. And because I'm running this on a local server, I'll hit local host. Well, this is the fake website. This is the fake edurea community website. Now, you can see that the interface looks exactly the same. All the options here are available. All the questions, all the details, there are different categories here and also the login button. Now, if you have a victim that uses Edureka community regularly, then you can create a fake website, a fishing website of Edureka community and then send this fishing website to him. So what happens is when he hits the login button he has to enter the email id and password and uh when he enters the email id and password for example I'll be entering this email id and some random password and I'll hit the login button. Now let's see on the terminal what details we get. Now as you can see that there's a message that tells possible username found, possible password found and you can see that the username and the password that I entered on the fishing page is available to me on this site. So this is how you can use fishing tools to steal credentials of your victim. Now the question is when you create a fishing page using these tools and you send these fishing pages to your victim, the URL is something different. there is local host or there is an IP address and suppose you want to steal credentials of Gmail and you send one IP address and your victim opens it he sees there's a Gmail login page so do you think he would actually enter his information because it would be fishy because if he has to login into Gmail he would just enter the URL by himself or go to Gmail login page by himself he would obviously think why he has to enter his credentials on the web application the website that you sent. So if you're just using fishing tools and just sending the IP address in most cases you will fail because the victim will know that something's fishy. In that case what you have to do is use the second way for fishing. So the second way for fishing is creating a custom fishing website. Now to do this you have to study your victim. You have to understand your victim. You have to understand what pages he usually visits, what fields, what things he is usually interested in and then depending on his interest, you have to create a fishing website. Now let me show you how you can use fishing by creating a custom fishing page. Now coming back to the Kali Linux operating system, I have created a fishing page uh that I will show you and I have created a fishing page that gives you some offer. there's a special offer. And when I was creating this fishing page, I had this one friend in mind that uh usually keeps looking for offers to buy food because he's a foodie. He usually orders online and every day he goes on to different websites and checks for coupons available or promo codes available. So this friend uh was what I had in mind and I created this fishing page that tells special offer offer valid on Swiggy, Zomato, Uber Eatats, Food Panda basically different food ordering services and I've also written that uh you can get 80% off on your food delivery and to do this you have to login with your Gmail account. So you have to login with your Gmail account to avail this offer. And also under the get promo code I have created a login button and just to make it a little legit because usually promo codes have expiry dates and uh yeah so if I send this thing it would look legit and because there's a expiry date he would log in with GB. Now I've also connected this web application to a database where I've designed this web application in such a way that when the user logs in to Gmail using his email id and password then that email id and password is sent and stored onto my database. So if I send this fishing page to my friend obviously because he needs promo code he would go and hit the login button and I've redirected this to a fake Gmail login page. He would enter his email ID and password because he wants the promo code for food. And uh he would enter his email id and password and hit the login button. And then I'm just displaying something telling coupon details will be sent to your email address. And he'll be checking for the coupon details for the promo code on his email ID. But what happens in the background is his credentials are sent to my database and stored in it. So let me just check what details I've got on my database. So I'll be logging into my database first and uh for this I'm using the database called test. So I'll just select that database. Let me see what tables are available here. There are two tables and there's this table called fishing details where I'm storing the data in. So I'll just print out I'll just display all the rows from this table. So select star from fishing details. This is the query to print all the rows of the database table. Now let me hit enter. Well, you can see that there are two rows. This was a previously entered username and password. And this is the username and password that we just entered. So this is how you can create a custom fishing page depending on the interest of your victim and then steal credentials of your victim. Now that you've seen how to use fishing to steal credentials, now what if someone is trying to execute a fishing attack on you? How can you be safe from fishing method? So you've seen how fishing works. You've seen that the main part of fishing is the URL. So the first important point that you have to keep in mind uh to be safe from fishing attacks is never enter sensitive information on a web application that you don't trust. Because if it's a genuine web application, if it's Gmail, if it's Facebook, and you're typing the URL and then going to the web application, then you know it is a trustworthy web application. But if there is some random web application that you've never heard of before that you don't trust and that web application is asking for sensitive information, especially your bank details because most of the time fishing is used to get bank credentials and also email ID and password. So always be careful not to enter sensitive information on web applications that you don't trust. The second thing is always look at the URL of the web application. Suppose you want to login into Facebook then the URL would be www.fas.com. This is the homepage of Facebook. Suppose you have another URL some other URL and a Facebook page is displayed that is asking you for your login credentials. Then you have to understand that there is something fishy. this might not be the genuine Facebook page. In that case, always be careful to look at the URL when you're entering sensitive information. [Music] So, what exactly is malvertising? Well, malvertising refers to the practice of embedding malicious code within online advertisements. And these ads are often displayed on legitimate websites which make them seem trustworthy. So when a user clicks on the advertisement or sometimes just visit the infected site, malware gets installed on their device. Now imagine you click on an ad for a Black Friday sale, but instead of a great deal, you get a warning saying your computer might be compromised. The site then prompts you to download an application to fix the issue, but that app is actually malicious and installs the malware on your computer. So this is how malvertisements work. They trick you into interacting with an ad that seems harmless, but in reality, it's designed to exploit your device and steal your data. Now, how does malvertising operate? Malvertisements can appear on both real and fake websites, and they usually run through ad networks without proper checks. So, let's discuss how they work. First, ad placements. Publishers integrate ads into their website using third-party ad networks. These networks deliver a variety of advertisements to the site. Then malicious code injection. Some advertisements are embedded with hidden malicious code which often sneaks through ad networks without thorough checks. Next, user interaction. Malvertisements target users in two main ways depending on how they interact with the advertisements. First, clickbased infection. This method relies on the user clicking the malicious advertisement. So once clicked, the hidden malicious code activates and installs malware on the device. Like for example, clicking an ad for a special offer might lead to a fake download page which infects your system. The next method is drive by download. This is even sneakier because it doesn't require the user to click anything. Just visiting a web page containing a malvertisement can trigger the download of malware and the malicious code runs silently in the background compromising the system without the users's awareness. Next is the malware activation. Once the malware is installed, it can steal sensitive data, damage the system or even grant attackers control of your device all without your knowledge. This seamless and deceptive process makes malotizing one of the sneakiest threat in the digital world. Now a question that many people have is, isn't malizing just another form of adear? Well, not exactly. So let's break down the key differences between the two. First let us talk in terms of definition. Malvertising refers to malicious code injected into online advertisement displayed on legitimate websites. And on the other hand, adear is software that is installed directly onto your system and displays unwanted advertisements. Like for example, malvertising can compromise a trusted website while adear hides in a program you may have downloaded. Next talking about placement, malvertising is found on compromised websites meaning you are at the risk when you visit an infected page. However, adear is already installed on your device and doesn't depend on external sites. Next, talking about target audience. Malverising primarily targets user who visit infected websites. Once you leave those website, the immediate thread diminishes whereas adear continues to affect you long after installation constantly showing unwanted ads on your device. Next, talking about mode of operation. Malvertising operates by leveraging infected websites. Without those website, it can't execute its attack. However, adear is persistent. It runs continuously in the background of your system. affecting performance and bombarding you with ads. Next, moving on to purpose. Malverizing aims to harm users by stealing data or injecting malware. And in comparison, adear has a different goal. It generates revenue by floating users with advertisements. And to summarize all this, we can see that malvertising relies on infected websites to attack. Admin lives on your device running non-stop to serve ads. So both can disrupt your experience and compromise security. But understanding their differences helps you to identify and defend against these threats effectively. Next, moving on to how these ads harm users. Malvertising isn't just about annoying advertisements. It's a significant threat that can expose users to serious risk. So let's talk about some of these risks. First, drive by downloads. So this is one of the most dangerous aspects of malvertising. Without any action from your site, no clicks or downloads, malware can automatically infiltrate your device just by visiting a website hosting a malicious advertisement. This stealthy method makes it incredibly hard to detect until it's too late. Next, forced browser redirects. Malvertisements can secretly redirect you to harmful websites without your consent. These sites may host ransomware, exploit kits, or fishing pages designed to capture your personal data or financial credentials. Next, through overloaded ads and pop-ups, malvertisements often trigger extensive ads or pop-ups, overwhelming your screen and slowing down your device. Beyond just being irritating, these ads may lead to malicious sites, adding to the security risk if accidentally clicked. Next, through clicked initiated infections. If you interact with a malicious advertisement, you could unintentionally open the door to several threats. And this includes malware installations that can compromise your device. Then fishing websites which are designed to steal sensitive information such as login credentials or payment details. The ranges of malvertising extend for beyond inconvenience. They threaten your privacy, data security, and even financial well-being. often operating in a ways that are invisible to the average user. Next, let us look at the impact of malvertisements on publishers. Well, malvertising doesn't just harm users. It also poses significant risk for publishers. So, let's talk about how it affects them. Here, first we have a reputation damage. When malicious advertisements are displayed on a publisher's website, users often associated the harmful experience with the site itself. Even through publishers may not have direct control over the ads, their credibility takes a hit. So over time this erosion of trust can drive users away for good. Next, loss of traffic and revenue. As users become way of visiting sites with maladvertisements, publishers experience a decline in website traffic. For e-commerce sites or businesses reliant on ad revenue, this means favor sales, lower engagement and loss of income. Next is legal consequences. If a user's personal or financial data is compromised due to malvertising on a publisher site, the publisher could face legal action. In some cases, they may be held accountable for not maintaining a secure ad environment leading to costly lawsuits or fines. These are some reasons why it's crucial for them to carefully examine networks and implement robust security measures to prevent malicious ads from slipping through. Next, moving on to methods of malware insertions into ads. There are multiple techniques through which malware can be inserted into online ads. So, let's discuss how it happens. First, malware in ad calls. So, when the browser request an ad, attackers can inject malicious code during the fetching process. And this happens through third party ad networks or services that the publisher might be using. This malicious ad request deliver harmful code to the user's device even before they interact with the ad. Next, malware injected post click. After a user clicks on an ad, they are often redirect to a landing page. If that page has been compromised, it can automatically download malware onto the user system. And this is known as the postclick injection where that malware isn't activated until the user clicks, but it can still cause significant damage once the page loads. Next, harmful code embedded in ads. Ads can contain hidden malicious code which may be embedded within text, images, banners, or even videos. This code can execute once the ad is displayed on the user's browser even without clicking. Like, for example, hidden scripts in banners or embedded videos can exploit browser vulnerabilities and infect the system. And these methods show how malware can be stealthily introduced into your system through ads even without your direct interaction with the ad itself. Next, let us see the strategies to prevent malvertising. Preventing malvertising involves both proactive measures for users and publishers. So let's start with how users can stay proactive against them. So for users, use an ad blocker. One of the easiest and most effective ways to prevent maladvertising is to use an ad blocker. These tools block all the ads on websites, including potentially harmful ones, ensuring that malicious ads never reach your device. Next, keep your software updated. Make sure to update your browser, operating systems, and plugins regularly. Updates often contain important security patches that fix vulnerabilities that malisers could exploit to deliver malicious content. and keeping everything up to date is a crucial defense against threats. Next, use antivirus software. So, you can install reliable antivirus software that can detect, block, and remove malware before it can infect your system. These programs are continuously updated to recognize new types of threats and provide an extra layer of protection against malicious ads. Now, let's talk about the steps publishers can take to protect their platforms. So for publishers screen ads carefully. Publishers must verify that ads comes from trusted sources. So before appearing on a website ads should be scanned for malicious code helping to ensure that harmful content doesn't reach users. Next limit dangerous content. Restrict the types of files that can be included in ads. Like for example avoid allowing ads with executable files, scripts or other potential dangerous content. And by limiting what can be embedded in the ads, the risk of malvertising is greatly reduced. Next, publishers can use strict ad scanning processes. Before allowing ads to be shown, implement a rigorous ad scanning process. And this process involves testing and inspecting ads with advanced security tools to ensure they are free from malicious code. Only advertisements that pass these checks should be allowed on the site. And by following these strategies, both users and publishers can significantly reduce the risk of being victimized by malvertising, ensuring a safer browsing experience for everyone. [Music] What exactly is a virus hoax? A virus hoax is a type of a scam or misinformation that tricks you into believing your computer, phone, or device is infected with the virus when it's not. These hoaxes might show you in the form of emails, pop-ups, social media messages, or text messages. And they often use scary language to make you feel like your system is at risk even though there's no actual virus. So why do they do this? The goal behind these hoaxes is to create panic and fear so that people act quickly such as clicking on a harmful link, downloading malicious software, or sharing personal information. And remember, virus hoaxes are fake, but they can still cause problems. They might waste your time, create unnecessary stress, or lead you to make decisions that could expose you to real risk. Now that we know what virus hoaxes are, so let's break down how these scams appear in different forms and trick us into taking hasty actions. So, how do these hoaxes show up? Hoaxes can appear in several different forms, but they all aim to deceive you into thinking you need to take immediate action. And here's how they typically manifest. First, emails. A typical hoax might land in your inbox with an urgent message like your computer is infected. Click here to remove the virus. And the goal is to get you to open an attachment, download malicious software, or follow instructions that will put your data at risk. Next is pop-ups. While you're browsing the web, you might encounter pop-ups, ad or warning messages that seems to come from your anti virus software. This pop-up claim that your system has been infected and often direct you to fake websites that ask for personal details or prompt you to download harmful programs. Next is the social media post. Sometimes hoaxes spread on social media platforms like Facebook, Twitter or Instagram. And this post might warn about a new virus that spreads through certain links or attachments. And the message might say something like, "Share this with your friends to protect them." This tactic is designed to spread the hoax to as many people as possible. And next we have is text messages. You might receive a text messages claiming that your phone is infected with a virus. The message could contain a link to a shady website or offer you to help you fix your device for a fee. Next is the phone scams. Scammers sometimes call you and claim to be from a company like Microsoft saying your system is compromised. They may ask you to give them remote access to your device or provide personal information. And regardless of the format, these hoaxes rely on urgency and fear to get you act quickly and they prey on your emotions to trick you into making decisions that benefit the scammer. Now that you understand how virus hoes show up, so let's move on to some real world example of these hoaxes that have spread like wildfire. Let's examine two real world virus hoaxes that have circulated on the internet over the years. These are great examples of how hoaxes spread and how they can trick even the most cautious users. Let's start with the good times virus. In 1994, an email warning about a virus called good times or good times began circulating. The email warned users that if they received an email with the subject line good times or good times, they should delete it immediately without opening it. And according to the hawks, opening this email would infect your system with a virus that would destroy everything on your computer. It was said to be especially dangerous because it could spread quickly and easily. Now, here is the catch. The good times virus didn't actually exist. It was a completely madeup threat. The hawk was never based on any real virus. But the warning itself became a widespread that it turned into a kind of viral panic. What made it dangerous was that people were actually deleting legitimate emails just because they had the words good times in the subject line even if they had nothing to do with any virus. And this example shows how fear-based hoaxes can create widespread confusion and harm even when there is no actual threat. The second example is the Olympic torch virus which circulated in 2006. This one was a bit more creative. The email claimed that the virus was called the Olympic torch virus and was supposedly hidden in email attachments with a name like invitation or postcard from Hallmark. And the message warned that opening the attachment would activate the virus and immediately wipe out the data on your hard drive. It even claimed that the big companies like Mac Cafe and Microsoft had recognized it as one of the most dangerous viruses of all time. But guess what? There was no Olympic torch virus. It was all a hoax. The real danger was the email itself. People were tricked into thinking they had to act fast or risk losing their data. and they might have even deleted important files or ignored legitimate emails because of this hoax. So what can we learn from these examples? The good times virus and Olympic torch virus hoaxes shows us how easily information can spread especially when it plays on our fear. So even when the warnings are completely false, they can still cause chaos. So it's important to remember that while virus hoaxes can seem alarming, they just hoaxes and nothing more. Seeing how these hoaxes work in real life gives us valuable insights. But now let's shift focus to how we can spot a hoax and protect ourself from falling victim. Knowing how to spot a hoax is critical to protecting yourself. So here are some of the key signs to look out for. First, hoaxes are too good to be true. Hoaxes love to make promises that sound too good to be true. Like for example, you might receive an email claiming you have won a huge prize or being offered free software that promises to protect your computer from virus. So while these offers might seem exciting, they are usually too good to be true. The truth is that most legitimate offers or rewards don't just appear out of nowhere in your inbox. So if something seems too perfect, it's time to be suspicious. Next, a major tactic used by hoaxes is to create a sense of urgency. You will often see phrases like immediate action required or your computer will be destroyed or maybe you might act now or risk losing everything. This is meant to pressure you into acting quickly, often without thinking or questioning the message. Hoaxes depend on your panic to get your click on malicious links or attachments. legitimate messages from companies or service providers won't demand such immediate actions unless it's necessary. Next, we have suspicious links. So, when you receive an email or message, always hover over any link before clicking on them. They will show you the actual URL where the link will take you. So, if the link looks suspicious, unfamiliar, or has strange character in it, don't click on it. Hoaxes messages often contain links that seems like they lead to a trustworthy website, but in reality, they may direct you to malicious sites or fishing pages designed to steal your personal information. Like for example, a link that looks like something that we have here on the screen is a red flag. Always double check the URL to ensure it's legitimate. Next, moving on to typos and grammar issues. A quick giveaway that something is a hoax is poor grammar, spelling mistakes, or awkward phrasing. So, official messages from reputable companies or organizations are usually well written and error-free. So, if an email is full of typos or awkward sentences, it's a sign that it might not be legitimate. Like for example, a message saying urgent, your account will be locked if not updated immediately. To ensure your safety, click the link below. Failure to update will result in your account being disabled. Act fast. So this is a definitely a warning sign. These types of errors are often found in hoaxes and fishing emails because they do not come from professional source but from someone who is trying to deceive you. Knowing how to spot a hoax is a half the battle. Now let's look at the next critical step. What you should do if you ever encounter a virus hoax message. So, it's easy to panic when you receive a virus warning, but reacting too quickly can cause more harm than good. So, here's what you should and you should not do when you encounter a virus hawk's message. So, what not to do? Don't panic. The first thing to do is stay calm. This messages are designed to cause fear and confusion, but reacting impulsively can lead to mistakes. Next, don't click on the links or open attachments. So never click on the links or open attachments in the message. Doing so could lead to malicious website or trigger the download of harmful software. Then don't respond to request for personal information. If the message asks for personal details, login credentials, or remote access to your device, don't respond. Legitimate companies will never ask for such information via such messages. Next, what to do? Verify the alert. If you are unsure about the message, verify it with the official company or service provider that allegedly sent it. Use their official contact details from their website and not the ones provided in the message. Next, search for hoax information. If you're still unsure, look up information about the alert online. Many hoaxes are widespread, so you will likely find details that confirm whether it's fake or not. Then, do not forward. Avoid forwarding the message to others. Hoaxes spread quickly and forwarding it could help propagate the scam. Next, delete suspicious alerts. Once you have determined that it's a hoax, delete the message immediately and don't keep it in your inbox as a reminder. Then report to the IT team. If you work in a workspace, report the hoax message to your IT team. They can investigate further and ensure that other employees are aware of the threat. And by following these simple steps, you can stay safe and help prevent hoaxes from spreading further. And by knowing how to respond to a hoax, you can stay protected. But to ensure you don't falls for hoaxes in the future, let's now explore some trusted resources to cross check claims. Here are some trusted resources to verify hoaxes. First, we have Snopes. It helps people identify virus hoaxes by providing fact-checked articles that debunk misinformation and viral rumors, offering reliable explanation based on evidence. Next, fact check.org. It combats virus hoaxes by analyzing and verifying claims related to health and viruses, ensuring accurate information is available to the public. Next, quality fact. It works to expose virus hoaxes by rating the truthfulness of viral claims and misinformation using a thorough fact-checking process. Next, full fact. It helps detect virus hoaxes by scrutinizing health related claims and correcting misleading or false information to inform the public. Next, lead stories. It identifies virus hoaxes by providing real-time fact-checking and debunking viral claims, helping users avoid misinformation. And with these resources in hand, you will be well equipped to verify hoax claims. And these platforms help ensure the information you encounter is accurate and reliable. [Music] Let's now dive into the top 10 antivirus solution for cyber security that offers complete protection for both individuals and businesses. So first on the list we have not 360. So this is the best antivirus for Windows, Android and iOS. Nonin 360 approved by experts are the choice of most people. It boost a 100% malware detection rate. So here's what makes it stand out. So some of the key features include AI based scanner, VPN, secure firewall, password manager, fishing protection with a private browser, dark web monitoring, identity theft protections, optimization tools, parental controls, Wi-Fi security alerts for Android and iOS, cloud solution up to 500GB, ransomware protection, and much more. So when we talk about devices and compatibility, it protects up to 10 devices and works across all major operating system. Then the money back guarantee is 60 days risk-free. Now let's talk about pricing. So the basic prediction for one device with antivirus plus is at rupees 799 per year. Next, 360 Deluxe is a favorite at 1,199 rupees per year for three devices including VPN, dark web monitoring, and cloud storage. And for complete identity theft protection, Nton's lifelock subscription starts at rupees 7,718 per year. Not 360 utilizes a unique scanning engine powered by herostic analysis and machine learning, constantly outperforming built-in antiviruses like Microsoft Defender. Its additional features such as the secure firewall, parental controls, and even a free browser called private browser makes it a comprehensive security suit. Next up, we have Bit Defender total security, which also delivers a 100% malware detection rate. This antivirus uses a massive malware database, machine learning, and artificial intelligence to detect threads more effectively than almost any competitor. So, here are some of the key features such as cloud-based scanner that minimizes system strain, web protection, vulnerability scanner, system optimizer, VPN, parental controls, password manager, webcam protection, ransomware protection, identity theft protections, and much more. And when we talk about performance during full system scans, it averages 21% CPU usage, dropping to less than 1% when running in the background. Next, let us talk about the devices and compatibility. So, it covers up to 10 devices across major operating systems and money back guarantee is for 30-day risk-free. Now, let us have a look at the pricing. So, Bit Defender Antivirus Plus for one device starts at rupees,199 per year. Bit Defender Internet Security for up to three windows is available at rupees,799 per year. The Bit Defender total security plan covers five license for Windows, Mac OS, Android and iOS at rupes 2,499 per year. However, Bit Defender premium security at rupes 2,9.99 per year offers unlimited VPN usage and additional features. Its cloud-based scanning not only keeps your system running smoothly, but also provides extensive cyber security tools, making it an excellent value for anyone looking for a comprehensive protection suit. And for those seeking simplicity without compromising on protection, Total AV is an outstanding choice with a 99.60% 60% malware detection rate. So, here's why Total AV is perfect for beginners and advanced users alike. So, the key features include an intuitive dashboard, fast and reliable antivirus scanner, web shield for blocking dangerous website, total browser for secure browsing that alerts you if a page was involved in a data breach, and a performance optimizer that cleans up unnecessary files. So, let's have a look at the additional tools. Total ASVPN is a secure and compatible with popular streaming sites while its password manager offers autosaving, autofilling and customizable generator and cross device synchronization. So when we talk about devices and compatibility, it supports up to eight devices and it is compatible with all major operating systems including Chromebooks and even Kindle Fire tablets. So when we talk about money back guarantee then it is 30-day risk-free. So let us have a look at the pricing. Total A's total security for up to eight devices at rupees 4,22 per year. For budget users, Total A's premium covers up to three devices at rupees 2,487 per year. So with its powerful antivirus engine and user-friendly interface, Total AV is a perfect allrounder for those new to cyber security total protection is next on our list. Delivering a flawless 100% malware detection rate and a suit of features ideal for families. And the key features include comprehensive malware protection, anti-ishing, a password manager, VPN, identity theft monitoring, and even an app for Chromebooks. Its anti-ishing protection, reliable blocks, dangerous website. And its scam protection warns you about risky links across emails, text, and browsers. And family features include advanced parental controls with accurate location tracking makes it one of the best choices for family safety. So when we talk about devices and compatibility, it offers protection for an unlimited number of devices. Money back guarantee is up to 30day risk-free. Now let us have a look at the pricing. So the basic plan is at rupes $7.99 per year for one device and the premium family package at rups,699 per year offers unlimited device coverage plus enhanced features and advanced and unlimited plans provide even more protection including identity theft coverage. So despite a slightly heavier impact on system performance during full scan, Macafei's robust protection and extensive features makes it a top contender for comprehensive online security. So if you're a Mac user, Inigo is the antivirus built just for you, delivering a 100% malware detection rate for both Mac OS and even PC based malware. So some of the key features include realtime malware protection, MAC optimization and cleaning tools, advanced backup options, network security, and parental controls. Its fast scanning engine can scan over eight lakh files in under two hours with subsequent scans taking just minutes. And it's all because of its file caching system. So unique features include Inigo's customizable firewall monitors both incoming and outgoing network connections automatically adjusting its setting based on your environments. So when we talk about devices and compatibility, it protects up to five Macs with an additional Windows product also available. So money back guarantee is for 30-day risk-free. Now let's have a look at the pricing. So the Mac premium bundle X9 includes all features at a competitive price starting at rupes 5,715 per year. So Indigo not only enhance Apple's built-in security but also ensures your devices are optimized and protected making it the best choice for the Mac OS users. Next on the list we have Panda Dome. Panda Dome offers flexible pricing and an advanced virus scanner with a 95% malware detection rate. It stands out with its versatile range of plans and extras. So key features includes web protections, optimization tools, VPN, firewall, parental controls, password manager, dunk web monitoring, file encrypter, and even a free bootable antivirus rescue kit. Now let's have a look at the flexible plans. Panda free provides basic real-time protection for Windows, an app scanner for Android, a rescue kit, and a limited VPN. The essential plan is at rupees 2,134 per year, adds a firewall and a vital protection. The advanced plan is at rupees 2,834 per year and adds a ransomware protection. The complete package includes a password manager and optimization tools. Panda Dome Premium offers an unlimited data VPN and 24 by7 support at 5,9.99 rupees per year and also it supports unlimited devices and money back guarantee is for 30-day risk-free. Panda dome's variety of plans let you choose the exact features you need making it a highly adaptable solution for every user cyber security requirements. The next antivirus on our list, we have Casper Ski Premium. Casper Ski Premium is our next pick, offering excellent antivirus protection with a 100% malware detection rate and specialized features for online shopping and banking. So some of the key features include robust antivirus engine, anti- fishing, parental controls, webcam protection, a safe browser for online transaction, VPN with unlimited data, password manager, and even a smart home monitor to oversee your connected devices. So additional benefits includes its safety money feature creates a sandbox browser window that's secure for handling payments while the virtual keyboard helps avoid key loggers. So when we talk about devices and compatibility, it covers up to 20 devices and money back guarantee for 30-day risk-free. Now let us have a look at the pricing. Casper keep premium is available at rupees $8.99 per year for the best value plan and with options to cover 1 3 5 10 or 20 devices. Despite current restrictions for United State users due to regulatory bans, Caspers key remains GDPR compliance SOC2 audited and is a trusted choice globally for secure online transaction. So the next antivirus on our list is Avira Prime. Avira Prime combines a powerful antivirus engine consistently scoring a 100% detection rate with advanced system optimization tools. It's perfect if you need both robust protection and performance improvements. So, some of the key features include privacy optimization, system optimization tools such as startup optimizer saving up to 2 minutes on boost time, a game booster, a junk file cleaner, a duplicate file finder, and a streamline deliver updater. So, it also includes a VPN with unlimited data and a password manager. Performance advantages are its antivirus engine operates entirely in the cloud minimizing the impact on system performance which is ideal for older and a slower PCs and when we talk about devices and compatibility it protects up to five devices across all major operating systems and money back guarantee for 60 days risk-free. Now let us have a look at the pricing. Avira Prime is offered a 2,31 rupees per year for five devices with other cheaper plans such as Aira Internet Security are available for,22 rupees per year for one device. Avira Prime is an excellent all-in-one solution for those who not only need security but also want to optimize their devices performance. Next on the list, we have Trend Micro. Trend Micro delivers solid protection with a 97 percentage malware detection rate and excels in ensuring secure web browsing. So some of the key features include its anti-malware engine enhanced with a robust browser extension blocks online scams, unsafe websites, scam links, malicious code, and even misinformation. It also comes with a password manager secured by 256bit AES encryption and an ad blocker. Now let us talk about the web protection. Trend Micros browser extension outperforms those built into Chrome, Firefox or Safari in detecting fishing and scam sites. So when we talk about devices and compatibility, it protects up to 10 devices across various operating systems. Money back guarantee for 30-day risk-free. Now let us talk about pricing. So it is starting at rupees,386 per year with the maximum security plan covering up to one device and the premium security suit at rups 4,710 per year for 10 devices. It is offering additional identity theft protection and a fully featured VPN. Trend Micro's excellent web protection features makes it a strong contender for those who prioritize secure browsing. Now rounding out our list is malware bites. Also known for its simplicity and ease of use while providing a 95% malware detection rate. So some of the key features include a secure browser extension that blocks ads, trackers, fishing sites and other potential scams. It also offers exploit protections that are highly customizable and effective against zero day threats. Now let us talk about additional benefits. So, it comes bundled with a VPN offering unlimited data and servers in 45 plus countries along with identity threat protection available as an add-on. So, when we talk about devices and compatibility, it covers up to 20 devices and works seamlessly across all major operating systems including Chromebooks. So, money back guarantee for 60 days risk-free. Now, let us have a look at the pricing. Malware Bite starts at rupees 3,855 per year making it a solid choice for those who need basic and reliable protection without a plethora of extra features. So despite its minimalist approach, Malware Bite remains a dependable option for everyday antivirus protection. So that wraps up our comprehensive review of the top 10 antivirus for cyber security. Each of these products brings its strength from Nton's robust allround security to a vera system optimization and malware bite strength forward protection. Whether you're a home user, a family or a dedicated professional, there's a solution here to meet your needs. [Music] What is social engineering? Social engineering is a technique that uses human psychology rather than technically hacking to gain access to the system or data. The criminal use human emotions such as fear, curiosity, pride, and anger to trick a victim into clicking malicious links. Hackers using social engineering manipulate their target into performing specific action or sharing confidential information. The hackers first investigate the intended victim to gather the necessary background information such as potential point to access or weak security protocol for the next attack. Now that you are clear about what is social engineering, let's move on to how does social engineering work. A typical social engineering attack involves a cyber criminal communicating with a person that they are targeting while claiming to be from a trusted organization. In some cases, they may imitate someone the victim knows. Suppose if the manipulation is successful, the victim believes that the attacker is who they say are. The attackers then convince the victim to take additional action which includes disclosing sensitive information such as password, date of birth or bank account information. Alternatively, they may encourage the victim to visit a website where spyware has been installed. In worst cases, the malicious website deletes the sensitive information or completely takes over the device. Next, we will move on to the common social engineering attack techniques. And the first one is fishing. Fishing is the most common and successful type of social engineering attack. A criminal employs and deception through email, chat, web ads or website to get a person or organization to reveal their personal information or other valuables. For example, the criminal could pretend that he's from a bank, a government organization, or a well-known company that victim trust. The source could be an email asking the user to click on the link to log to their account. Then it will redirect to a fake website that appears to be valid and this is where the attack occurs. Next is spear fishing. Spear fishing is the most targeted form of fishing. The scammer personalizes their attack email with the targets name, position, phone number, and other information in attempting to trick the person who receives them in assuring that they have a connection with the center. For example, consider receiving an email claimed from a company CEO requesting immediate action on a confidential project. The email is valid as it addresses by your name and refers to internal information. Wanting to confirm, you click on the attached document, unknowingly launching malware that enters the organization network and demonstrate a targeted fishing attack that uses personalized information to trick and harm specific individual or organization. Next, we have baiting. In cyber security, baiting refers to encouraging people with promises of something important such as free software or media in exchange for your personal information or device access. This frequently takes the form of leaving infected USB device, CDs or other media in public places. Focusing on human curiosity to attack security. For example, baiting in cyber security includes leaving the USB device labeled confidential project plan on the cafeteria table and hoping that the employee will pick it up and plug it into their computer out of curiosity. Next is wishing. Wishing is also known as voice fishing. It is a method of social engineering in which attackers use phone call to trick people into disclosing sensitive information or taking action. For example, an attacker may pretend to be a bank representative claiming that there is a security issue with the victim's account and requesting their account information or verification code. Lastly, we have scare. Scarewware is a type of malicious software or application that confuses users into believing their computer is infected with viruses or malware. It usually promotes the user to buy fake antivirus software or devices to remove the supported threats. In reality, the danger is the scareware itself which is frequently designed to steal money from the victim who are unaware or install malware on their devices. For example, Scareware is designed as a pop-up message that appears on user computer claiming that their system has been infected with multiple viruses and encouraging them to download and install a specific antivirus program right away to remove the threats. However, clicking on the popup or following the instruction could install malicious software on the user computer, harming its security as well as stealing sensitive informations. I hope now you have a clear understanding about the common social engineering attack techniques. So be aware of these techniques. Now let's move on to protecting against social engineering. To protect yourself and organization from social engineering, you must first arise awareness, educate others and put in place security measures. Here are few strategies. And the first one is employee training and awareness. Hold regular training session to educate employees on common social engineering techniques like fishing emails and fake newses. Teach them how to identify and ensure communication. Configure the accuracy of request and immediately notify any unusual behaviors. Next is execute strong security guidelines. Develop and implement strong security measures and processes such as password management, access control, and data handling protocols. Ensure that employees understand and follows these policies to reduce the risk of unauthorized access or disclosure of sensitive informations. Next, we have implement multiffactor authentication. Implement multiffactor authentication across all systems and application to add a layer of security beyond password. request user to provide additional authentication factors such as temporary codes sent to their mobile device to configure the identity and prevent unauthorized access even if their passwords are affected. Next is regular security assessment. Conduct regular security assessment such as examination and hacking test to identify and address potential flaws in your organization structure, processes and controls. Be active in discovering and reducing security risk. And lastly, we have stay informed and upto-date. Stay uptodate on the latest social engineering strategies and cyber security threats by following industry newses, subscribing to safety notification and practicing in appropriate decisions or communities. Update software and security tools with the most recent patches and update to ensure protection. Next we will discuss why do cyber criminals use social engineering. Social engineering have become a popular method for hackers among cyber security. In recent years, it has been demonstrated to be the most effective method for criminals to inside an organization. Cyber criminals are employing more complex human hacking scam. A social engineer will learn everything possible about a person or business. This could include using social media or searching for a target's information online. To avoid the danger of social engineers, you must pay close attention, educate yourself, and be aware of the method used by the hackers. Now you know why cyber criminals use social engineering. Let's move on to why is social engineering so dangerous. One of the most dangerous aspect of social engineering is that the attack do not have to be directed at anyone. A single successful food victim can provide enough information to trigger an attack that affects the entire organization. Over time, social engineering attack have become more complex. Not only do fake website or emails appear realistic enough to trigger a victim into disclosing sensitive information or personal information that can be used to identify theft. But social engineering has also become one of the most common ways of attackers to get past an organization first defense in order to cause more confusion and harm. Now we will take a look at the best practices to prevent social engineering attacks. Be careful in what you share and know you don't have to be afraid about these attacks. It is possible to prevent them and here are few ways to help. First is set spam filter to high. Never use the same password for different accounts. Then use two factor or multiffactor authentication. When doubt, change the password right away. And lastly, educate employees. I hope now you have a clear understanding about social engineering and cyber security. In this video, we have covered many topics such as what are the attacks, how will they attack your system or organization and what are the prevention. [Music] Now, cyber attacks are taking place all the time. Even as we speak, the security of some organization big or small is being compromised. For example, if you visit this site out here that is threat cloud, you can actually view all the cyber attacks that are actually happening right now. Let me just give you a quick demonstration of how that looks like. Okay, so as you guys can see out here, these are all the places that are being compromised right now. The red parts actually show us the part that is being compromised and the yellow places actually show us from where it's being compromised from. Okay, as you guys can see now that someone from the Netherlands is actually attacking this place and someone from USA was attacking Mexico. It's a pretty interesting site and actually gives you a scale of how many cyber attacks are actually happening all the time in the world. Okay, now getting back I think looking at all these types of cyber attacks, it's only necessary that we educate ourselves about all the types of cyber threats that we have. So these are the eight cyber threats that we're going to be discussing today. Firstly, we're going to start with malware. So malware is an all-encompassing term for a variety of cyber attacks including Trojans, viruses, and worms. Malware is simply defined as code with malicious intent that typically steals data or destroys something on the computer. The way malware goes about doing its damage can be helpful in categorizing what kind of malware you're dealing with. So let's discuss it. So first of all, viruses. Like their biological namesakes, viruses attach themselves to clean files and infect other clean files, and they can spread uncontrollably, damaging a systems core functionality and deleting or corrupting files. They usually appear as executable files that you might have downloaded from the internet. Then there are also Trojans. Now, this kind of malware disguises itself as legitimate software or is included in legitimate software that can be tampered with. It tends to act discreetly and creates back doors in your security to let other malares in. Then we have worms. Worms infect entire networks of devices either local or across the internet by using the network's interfaces. It uses each consecutive infected machine to infect more. And then we have botn nets and such where botnets are networks of infected computers that are made to work together under the controller of an attacker. So basically you can encounter malware if you have some OS vulnerabilities or if you download some illegitimate software from somewhere or you have some other email attachment that was compromised with. Okay. So how exactly do you remove malware or how exactly do you fight against it? Well, each form of malware has its own way of infecting and damaging computers and data and so each one requires a different malware removal method. The best way to prevent malware is to avoid clicking on links or downloading attachments from unknown senders. And this is sometimes done by deploying a robust and updated firewall, which prevents the transfer of large data files over the network in a hope to weed out attachments that may contain malware. It's also important to make sure your computer's operating system, whether it be Windows, Mac OS, Linux, uses the most up-to-date security updates, and software programmers update programs frequently to address any holes or weak points. And it's important to install all these updates as well as to decrease your own system weaknesses. So next up on our list of cyber threats, we have fishing. So what exactly is fishing? Well, often posing as a request for data from a trusted third party, fishing attacks are sent via email and ask users to click on a link and enter their personal data. Fishing emails have gotten much more sophisticated in recent years and making it difficult for some people to discern a legitimate request for an information from a false one. Now, fishing emails often fall into the same category as spam, but are way more harmful than just a simple ad. So, how exactly does fishing work? Well, most people associate fishing with email message that spoof or mimic bank, credit card companies, or other businesses like Amazon, eBay, and Facebook. These messages look authentic and attempt to get victims to reveal their personal information. But email messages are only one small piece of a fishing scam. From beginning to end, the process involves five steps. The first step is planning. The fisher must decide which business to target and determine how to get email addresses for the customers of that business. Then they must go through the setup phase. Once they know which business to spoof and who their victims are, fishes create methods for delivering the messages and collecting the data, then they have to execute the attack and this is the step most people are familiar with. That is the fisher sends a phony message that appears to be from a reputable source. After that, the fisher records the information the victims enter into the web page or pop-up windows. And in the last step, which is basically identity theft and fraud, the fishers use the information they've gathered to make illegal purchases or otherwise commit fraud. And as many as a fourth of the victims never fully recover. So how exactly can you be actually preventing yourself from getting fished? Well, the only thing that you can do is being aware of how fishing emails actually work. So first of all, a fishing email has some very specific properties. So firstly you will have something like a very generalized way of addressing someone like dear client. Then your message will not be actually from a very reputable source. So out here as you can see it's written as Amazon on the label but if you actually inspect the email address that it came from it's from management masonada.ca which is not exactly a legitimate Amazon address. Third you can actually hover over the redirect links and see where they actually redirect you to. Now, this redirects me to www.fakeamazon.com as you can see out here. So, basically, you know, this is actually a fishing email and you should actually report this email to your administrators or anybody else that you think is supposed to be concerned with this. Also, let me give you guys a quick demonstration on how fishing actually works from the perspective of an attacker. So first of all, I have actually created a fishing website for harvesting Facebook credentials. I simply just took the source code of the Facebook login page and pasted it and then made a backend code in PHP which makes a log file of all the Facebook passwords that get actually entered onto the fishing page. Now, I've also sent myself an email as to make sure this looks legitimate, but this is only for spreading awareness. So, please don't use this method for actually harvesting credentials. That's actually a very illegal thing to do. So, let's get started. First of all, you'll go to your email and see that you'll get some email saying your Facebook credentials has been compromised. So, when you open it, it looks pretty legit. Well, I haven't made it look all that legit. It should look legit, but the point out here is to actually make you aware of how this works. So, as you guys can see, it says, "Dear client, we have strong reasons to believe that your credentials may have been compromised and might have been used by someone else. We have locked your Facebook account. Please click here to unlock. Sincerely, Facebook associate team." So, if we actually click here, we are actually redirected to a nicel looking Facebook page, which is exactly how Facebook looks like when you're logging in. Now suppose I were to actually log to my Facebook account which I won't. I'll just use some random ID like this is an email adagemail.com and let's put password as admin 1 2 3 and we click login. Now since my Facebook is actually already logged in, it'll just redirect to facebook.com and you might just see me logged in. But on a normal computer, it'll just redirect you to www.fas.com facebook.com which should just show this site again. Okay. So once I click login out here all that the backend code that I've written in PHP out here will do is that it's going to take all the parameters that I've entered into this website that is my email address and the password and just generate a log file about it. So let's just hit login and see what happens. So, as you guys can see, I've been redirected to the original Facebook page that is not meant for fishing. And on my system out here, I have a log file. And this log file will show exactly, as you can see, I have fished out the email address. This is an email at the rategmail.com. And it's also showed the password that is admin 123. So, this is how exactly fishing works. You enter an email address and you're entering the email address on a fishing website and then it just redirects you to the original site but by this time you've already compromised your credentials. So always be careful when dealing with such emails. So now jumping back to our session, the next type of cyber attacks we're going to discuss is password attacks. So an attempt to obtain or decrypt a user's password for illegal use is exactly what a password attack is. Hackers can use cracking programs, dictionary attacks, and password sniffers in password attacks. Password cracking refers to various measures used to discover computer passwords. This is usually accomplished by recovering passwords from data stored in or transported from a computer system. Password cracking is done by either repeatedly guessing the password, usually through a computer algorithm in which the computer tries numerous combinations until the password is successfully discovered. Now, password attacks can be done for several reasons, but the most malicious reason is in order to gain unauthorized access to a computer with the computer's owner's awareness not being in place. Now, this results in cyber crime, such as stealing passwords for the purpose of accessing bank information. Now, today there are three common methods used to break into a password protected system. The first is a brute force attack. A hacker uses a computer program or script to try to login with possible password combinations. Usually starting with the easiest to guess password. So just think if a hacker has a company list, he or she can easily guess usernames. If even one of the users has a password 1 2 3, he will quickly be able to get in. The next are dictionary attacks. Now a hacker uses a program or script to try to login by cycling through the combinations of common words. In contrast with brute force attacks where a large proportion key space is searched systematically, a dictionary attack tries only those possibilities which are most likely to succeed. Typically derived from a list of words, for example, a dictionary. Generally, dictionary attacks succeed because most people have a tendency to choose passwords which are short or such as single words found in the dictionaries or simple easy predicted variations on words such as appending a digit or so. Now the last kind of password attacks are used by key logger attacks. A hacker uses a program to track all of the user's keystrokes. So at the end of the day everything the user has typed including the login ids and passwords have been recorded. A key logger attack is different than a brute force or dictionary attack in many ways. Not the least of which the key logging program used as a malware that must first make it onto the user's device. And the key logger attacks are also different because stronger passwords don't provide much protection against them which is one reason that multiffactor authentication is becoming a must have for all businesses and organizations. Now the only way to stop yourself from getting killed in the whole password attack conundrum is by actually practicing the best practices that are being discussed in the whole industry about passwords. So basically you should update your password regularly. You should use alpha numeric in your password and you should never use words that are actually in the dictionary. It's always advisable to use garbage words that make no sense for passwords as they just cruise your security. So moving on, we're going to discuss DDoS attacks. So what exactly is a DDoS or a DOSS attack? Well, first of all, it stands for distributed denial of service. And a DOSS attack focuses on disrupting the service to a network. As the name suggests, attackers send high volume of data of traffic through the network until the network becomes overloaded and can no longer function. So there are a few different ways attackers can achieve DOSS attack, but the most common is the distributed denial of service attack. This involves the attacker using multiple computers to send the traffic or data that will overload the system. In many instances, a person may not even realize that his or her computer has been hijacked and is contributing to the DOSS attack. Now, disrupting services can have serious consequences relating to security and online access. Many instances of large-scale DOSs attacks have been implemented as a single sign of protests towards governments or individuals and have led to severe punishment, including major jail time. So, how can you prevent DOSs attacks against yourself? Well, firstly, unless your company is huge, it's rare that you would be even targeted by an outside group or attackers for a DOSs attack. Your site or network could still fall victim to one. However, if another organization on your network is targeted. Now, the best way to prevent an additional breach is to keep your system as secure as possible with regular software updates, online security monitoring, and monitoring of your data flow to identify any unusual or threatening spikes in traffic before they become a problem. DOSs attacks can also be perpetrated by simply cutting a table or dislodging a plug that connects your website server to the internet. So due diligence in physically monitoring your connections is recommended as well. Okay. So next up on our list is man-in-the-middle attacks. So by impersonating the end points in an online information exchange, the man-in-the-middle attack can obtain information from the end user and the entity he or she is communicating with. For example, if you are banking online, the man in the middle would communicate with you by impersonating your bank and communicate with the bank by impersonating you. The man in the middle would then receive all of the information transferred between both parties, which could include sensitive data such as bank accounts and personal information. So, how does it exactly work? Normally an MITM gains access through a non- enrypted wireless access point which is basically one that doesn't use WAP, WPA or any of the other security measures. Then they would have to access all of the information being transferred between both parties by actually spoofing something called address resolution protocol. That is the protocol that is used when you are actually connecting to your gateway from your computer. So how can you exactly prevent MITM attacks from happening against you? So firstly you have to use an encrypted WAP that is an encrypted wireless access point. Next you should always check the security of your connection because when somebody is actually trying to compromise your security he will try to actually strip down the HTTPS or HSTS that is being injected in the website which is basically the security protocols. So if something like this HTTPS is not appearing in your website, you're on an insecure website where your credentials or your information can be compromised. And the last and final measure that you can actually use is by investing in a virtual private network which spoofs your entire IP and you can just browse the internet with perfect comfort. Next up on our list is drive by downloads. So, gone are the days where you had to click to accept a download or install a software update in order to become infected. Now, just opening a compromised web page could allow dangerous code to install on your device. You just need to visit or drive by a web page without stopping or to click accept any software and the malicious code can download in the background to your device. A drive by download refers to the unintentional download of a virus or malicious software onto your computer or mobile device. A drive by download will usually take advantage or exploit a browser or app or operating system that is out ofd and has security flaws. This initial code that is downloaded is often very small and since it job is often simply to contact another computer where it can pull down the rest of the code onto your smartphone, tablet or other computers. Often a web page will contain several different types of malicious code in hopes that one of them will match a weakness on your computer. So how does this exactly work? Well, first you visit the site and during the three-way handshake connection of the TCP IP protocol, a backend script is triggered. As soon as a connection is made while the last ACK packet is sent, a download is also triggered and the malware is basically injected into your system. Now, the best advice I can share about avoiding driveby downloads is to avoid visiting websites that could be considered dangerous or malicious. This includes adult content, file sharing websites, or anything that offers you a free trip to the Bahamas. Now, some other tips to stay protected include keep your internet browser and operating system up to date. Use a safe search protocol that warns you when to navigate to a malicious site and use comprehensive security software on all your devices like Macaffy all access and keeping it up to date. Okay, so that was it about drive by downloads. Next up is mal advertising or malvertising. So malvertising is the name we in the security industry give to criminally controlled advertisements which intentionally infect people and businesses. These can be any ad on any site often ones which you use as a part of your everyday internet usage and it is a growing problem as is evident by a recent US Senate report and the establishment of bodies like trust and ads. Now whilst the technology being used in the background is very advanced. The way it presents to the person being infected is simple to all intents and purposes the advertisement looks the same as any other but has been placed by a criminal. Like you can see the mint ad out here. It's really out of place. So you could say it's been made by a criminal. Now without your knowledge, a tiny piece of code hidden deep in the advertisement is making your computer go to the criminal servers. These then catalog details about your computer and its location before choosing which piece of malware to send you. And this doesn't need a new browser window and you won't know about it. So basically, you're redirected to some criminal server. The malware injection takes place and voila, you're infected. It's a pretty dangerous thing to be in. So how exactly can you stop maletizing? Well, first of all, you need to use an ad blocker which is a very must in this day and age. You can have ad blocker extensions installed on your browser, whether it be Chrome, Safari or Mozilla. Also, regular software updates of your browser and other software that work peripheral to your browser always helps. And next is some common sense. Any advertisement that is about a lottery that's offering you free money is probably going to scam you and inject a malware, too. So, never click on those ads. So the last kind of cyber attacks we're going to discover today and discuss about is rogue software. So rogue security software is a form of malicious software and internet fraud that misleads users into believing that there is a virus on their computer and manipulates them into paying money for a fake malware removal tool. It is a form of scareware that manipulates users through fear and a form of ransomware. Rogue security software has been a serious security threat in desktop computing since 2008. So now how does a rogue security software work? These scams manipulating users into download the program through a variety of techniques. Some of these methods include ads offering free or trial versions of security programs, often pricey upgrades or encouraging the purchase of the deluxe versions. Then also popups warning that your computer is infected with a virus which encourages you to clean it by clicking on the program and then manipulated SEO rankings that put infected website as the top hits when you search. These links then redirect you to a landing page that claims your machine is infected and encourages you a free trial of the rogue security program. Now once the Scareware is installed, it can steal all your information, slow your computer, corrupt your files, disable updates for legitimate antivirus softwares, or even prevent you from visiting legitimate security software vendor sites. Well, talking about prevention, the best defense is a good offense. And in this case, an updated firewall makes sure that you have a working one in your office that protects you and your employees from these type of attacks. It is also a good idea to install a trusted antivirus or anti-spyware software program that can detect threats like these. And also a general level of distrust on the internet and not actually believing anything right off the bat is the way to go. [Music] Let us understand what is cyber killchain. Well, the cyber killchain is a concept borrowed from the military's keychain adapted to cyber security by Loheed Martin in 2011 and it's a step-by-step framework that helps organization identify and stop cyber attacks at different stages. And this model is particularly useful for defending against advanced persistent threats which are sophisticated attacks that involve recognizance, malware, social engineering and more. The cyber kill chain is all about understanding the attacker's process so that you can detect, prevent, and respond to threats effectively. Now that we know what the cyber kill chain is, so let's break it down into seven stages that make up this framework. Here, each stage plays a critical role in an attack. So let's take a closer look. Now let's break down the seven stages of the cyber kill chain and see what happens at each stage. Stage one is reconnaissance. Attackers gather information about the target and this includes collecting publicly available data, scanning for vulnerabilities with tools and identifying potential entry points. Stage two is weaponization. Here attackers create malicious payloads tailored to the targets vulnerabilities and they may develop new malware, modify existing tools to bypass defenses. Stage three is delivery. This is when the malicious payload reaches the target through methods like fishing emails, exploiting hardware or software vulnerabilities. Stage four is exploitation. The payload is activated and then the attacker exploit vulnerabilities to gain access. This often includes a lateral movement across the network. Stage five is installation. Here attackers install malware or backd doorors to establish persistent access. Examples include Trojan horses command line interfaces. Stage six is command and control. Attackers establish a remote connection to monitor and guide their attack and often using opuscation techniques to aid detection. Stage seven is actions on objectives and this is the final stage where attackers achieve their goal such as data theft, encrypting files for ransom and compromising supply chains. While the cyber kill chain provides a strong foundation, it's not only the framework out there. One of the most popular comparison is with the MITER attack framework. So how do they stack up? So let's compare. So here we are going to compare the cyber kill chain versus miter attack. The cyberkill chain is often compared to the miter attack framework but there are some key differences. First in terms of structure. The cyber kill chain has the linear structure with seven stages while the miter attack is more flexible and focuses on tactics and techniques in no specific order. Next, in terms of focus, the cyber kill chain provides a highle overview whereas miter attack examines the granular details of attack execution. Now, both are valuable, but the choice depends on your organization's need and threat landscape. As cyber threats have grown more sophisticated, the cyber kill chain has evolved to stay relevant. But what changes have been made and how has it adapted to modern challenges? Let's explore its evolution. Since its introduction in 2011, the cyber kill chain has evolved to address modern threats. However, attackers have become more sophisticated, often skipping or combining stages. For example, fileless malware and AIdriven attacks don't always follow traditional patterns. Here, attackers exploit newer technologies like IoT, cloud computing, and cryptocurrency. This evolution has challenged defenders to adapt and integrate more dynamic frameworks like MITER attack. Even with its strength, the cyber kill chain isn't perfect. It has some limitations that cyber security professionals need to consider. So, what are these weaknesses and how do they impact its effectiveness? So let us see the weaknesses in cyber kill chain. While the cyber kill chain is a powerful tool, it has some limitations such as limited deduction and it focuses heavily on malware but struggles with newer threats like fileless attacks and insider threats. Next is the rigid structure. Not all attacks follow the linear sevenstage process. Next is the emerging threats. Advanced techniques like deep fake fishing and AIdriven attacks require more flexible defenses. And to overcome these weaknesses, organizations should complement the cyber kill chain with other frameworks and advanced technologies. Despite its limitations, the cyber kill chain remains a valuable tool in the fight against cyber threats. So let's wrap things up by understanding how it contributes to strengthening cyber security strategies today. So here are the roles of cyber killchain in cyber security. So as I said despite its limitation the cyber kill chain remains an essential tool for understanding and combating cyber attacks such as provides a clear road map for identifying threats then helps organizations to design proactive defenses and encourages a mindset of active threat hunting rather than passive defense. [Music] Let's see some of the top cyber attacks in the history. Starting off with Adobe. Adobe was going through hell. Well, you see, Adobe announced on October 2013 a massive attack or massive hacking of its IT infrastructure where personal information of about 22.9 million accounts was stolen which includes login IDs, passwords, name, credit card numbers, and expir date. Another file discovered on the internet later, but number of accounts that were affected by this attack was about 150 million. To access this information, hackers took advantage of security breaches at publisher specifically related to security practices and around passwords. The stolen passwords have been encrypted instead of being chopped as per recommendation. Fortunately, this led to banking data not being stolen. This because of high quality encryption by Adobe. The company was attacked not only for its customer information but also for its product data. Indeed, the most worrying part about Adobe was about 40 GB of source code. For instance, the entire source code of cold fusion product was stolen as well as the part of source code of adob acrobat reader and Photoshop was also stolen. So the next one is a target. So people usually said as target targeted, right? So target this is the second largest US discount retailer chain which was a victim of large scale cyber attack in December 2013. Data from about 110 million customers was hijacked between 27th November to December 15th, including banking data of 40 million customers and personal data which included names, postal address, telephone numbers and emails. And it was not the target who discovered the attack, the American Secret Service who detected abnormal banking movement and warmed the brand. According to several US security services, the hacker group was located in Eastern Europe. It had installed malware in the cash registers to read information from credit card terminals. The technique is known as RAM scaping. Once the data has been hacked, attacker resold it to the black market. Target was ultimately required to pay over $18 million as a settlement for state investigation into the attack. Moving ahead to the next one that is Sony. So there was a panic at Sony. In April 2011, Sony's PlayStation Network was attacked. The multiplayer gaming service online games purchasing and live content distribution of Japanese brand contained the personal data of 77 million users was leaked. Banking information of tens and thousands of players was also compromised. After the intrusion was detected, PlayStation Network as well as Sony online entertainment were closed for 1 month. To appease the users, Sony paid around $15 million US in compensation plus few million as a legal fees in addition to having to refund people whose banking accounts were illegally used. This cyber attack could have been largely avoided. Indeed, hackers were well known about vulnerability that Sony chose to ignore. Data was unencrypted and could easily be hijacked to a very simple technique that is SQL injection. Moving ahead to our next crisis that is at Equifax. Equifax, a American credit company, revealed that it had suffered a cyber security attack over a course of months. Detected in 2017, it contained personal data which had names, date of birth, social security numbers, and driver license numbers. It contained information of about 143 million Americans, Canadians, and British customers, as well as 200,000 credit card numbers. So, moving ahead, we have a cyber attack which occurred in South Korea. South Korea learned in January 2014 that data from about 100 million credit cards have been stolen over the course of several years. In addition to that, 20 million bank accounts have been hijacked. For fear of having their bank accounts emptied, more than 200 million South Koreans had their credit card blocked or replaced. Behind the theft was an employee of South Korean credit bureau. He stole personal information from customers of credit card companies when he worked for them for a consultant by simply copying the data to an external hard drive. He then resold the data to credit card traders and telemarketing companies. As you see here, this is a classic example of a insider threat. So the next cyber attack that occurred was with Marriott hotels. You see information of about 500 million guests at Marriott hotel was compromised. Their banking details, date of birth and many other information were have been swift out. It seems that the account or the hacking was taking place since 2014 but was only spotted during the month of September of 2018. Marriott was first alerted to the potential breach in September. It said that there are internal security tools found someone was trying to access its database. It then found out people seem to have been hacking its database since 2014 and they copied information apparently with the intent of taking it. All right guys, these were some of the top cyber attack that struck the industry. So moving ahead, let's check out some of the challenges that we are facing with respect to cyber security. Starting off with ransomware attack. Ransomware attack have become popular in last few years and pose one of the most India's prominent cyber security challenge in 2020. According to cyber security firm Sophia about 82% of India's organizations were hit by ransomware attack in last 6 months. You see ransomware attack involves hacking into a user's data and preventing them from accessing it until a ransom amount is being paid. Although ransomware attacks are critical for individual users but more so for businesses who can't access the data for running the daily operation. However, with the most ransomware attack, attackers don't release the data even after the payment. Instead try to exploit more money. The next most common cyber security challenge is IoT attack. According to IoT analysis, there will be about 106 billion IoT device in 2021. IoT device are computing digital and mechanical device that can autonomously transmit data over a network. Example of an IoT device include desktop, laptop, mobile phone, smart security device and many more. As the adoption of IoT devices increasing in an unpredicted rate, so are the challenges of cyber security. Attacking IoT device can result in compromise of sensitive user data and safeguarding IoT device is one of the biggest challenge in the cyber security domain. The next type of attack is the cloud attack. We all know most of us today use cloud services for personal and professional needs. Also, hacking cloud platform to steal our user data is one of the challenges in cyber security for businesses. We all are aware of the infamous iCloud hack which expose private photos of celebrity. If such attacks is carried out in enterprise data, it could pose a massive threat to the organization and maybe could even lead to its possible collapse. Finally, we have fishing attack. You see fishing is a type of social engineering attack often used to steal user data including login credentials or credit card numbers and many more. Unlike ransomware attack, the hacker upon gaining access to the confidential user data doesn't block it. Instead, they use it for their own advantage such as online shopping and illegal money transfer. Fishing attacks are prevalent among hackers as they can exploit user data until the user finds out about it. Fishing attack remains one of the major challenges for cyber security in India as a demographic here is in wellversed with handling confidential data. So moving ahead let's see the future of cyber security. The rate at which cyber crime is increasing is alarming. Almost every week a high-profile cyber crime is being reported. Every business is in its own unique stage of digital transformation. However, it doesn't matter how far your business is going. It should consider security as its topmost priority. Cyber security professionals will be in high demand. You see the need for cyber security professional is a dire as with the passing days as new attacks are being coined which are more harmful than the previous one. These rising threats require skilled cyber security professional to help ensure safeguard for the individual as well as for the organization. We can also expect robust integration of artificial intelligence in cyber security tools and techniques. This is because it improves security expert analyzation, study and understanding cyber crime. It enhances security technology that companies use to combat cyber crimes and help keep their organization and customers safe. We can also expect more of automation in the future. Automation of many roles and tools can also be heavily implemented. This will allow performing a constant search for threats and deploying immediate remedies. Right? [Music] Firstly, let's go over what DOSs and DDoS means. Now, to understand a DDoS attack, it is essential to understand the fundamentals of a DOSS attack. DOSS simply stands for denial of service. The service could be of any kind. For example, imagine your mother confiscates your cell phone when you are preparing for your exams to help you study without any sort of distraction. While the intentions of your mother is truly out of care and concern, you are being denied the service of calling and any other service offered by your cell phone. Now with respect to a computer and computer networks, a denial of service could be in the form of hijacking web servers, overloading ports with requests, rendering them unusable, denying wireless authentication, and denying any sort of service that is provided on the internet. Attacks of such intent can be performed from a single machine. While single machine attacks are much easier to execute and monitor, they are also easy to detect and mitigate. To solve this issue, the attack could be executed from multiple devices spread across a wide area. Not only does this make it difficult to stop the attack, but it also becomes near impossible to point out the main culprit. Such attacks are called distributed denial of service or DDoS attacks. Now let's see how they work. The main idea of a DDoS attack as explained is making a certain service unavailable. Since everything that is attacked is in reality running on a machine, the service can be made unavailable if the performance of the machine can be brought down. This is the fundamental behind DOSs and DDOS attacks. Now, some DOSS attacks are executed by flooding servers with connection requests until the server is overloaded and is deemed useless. Others are executed by sending unfragmented packets to a server which they are unable to handle. These methods when executed by a botnet exponentially increase the amount of damage that they are doing and their difficulty to mitigate increases in leaps and bounds. To understand more about how these attacks work, let us look at the different types of attacks. Now, while there are plenty of ways to perform a DDoS attack, I'll be listing down the more famous ones. These methodologies have become famous due to their success rate and the damage they have caused over time. It is important to note that with the advancement in technology, the more creative minds have devised more devious ways to perform DOS attacks. Now, the first type of methodology that we're going to discuss is called ping of death. Now according to the TCP IP protocol, the maximum size of packet can be 65,535 bytes. The ping of death attack exploits this particular fact. In this type of attack, the attacker sends packets that are more than the max packet size when the packet fragments are added up. Computers generally do not know what to do with such packets and end up freezing or sometimes crashing entirely. Then we come to reflected attacks. This particular attack is more often than not used with the help of a botnet. The attacker sends a host of innocent computers a connection request using a botnet which are also called reflectors. Now this connection that comes from the botnet looks like it comes from the victim and this is done by spoofing the source part in the packet header. This makes the host of computers send an acknowledgement to the victim computer. Since there are multiple such requests from the different computers to the same machine, this overloads the computer and crashes it. This type of attack is also known as a smurf attack. Another type of attack is called mailbomb. Now mailbomb attacks generally attack email servers. In this type of attack, instead of packets, oversized emails filled with random garbage values are sent to the targeted email server. This generally crashes the email server due to a sudden spike in load and renders them useless until fixed. Last but not the least, we have the teardrop attack. So in this type of attack, the fragmentation offset field of a packet is abused. One of the fields in an IP header is a fragment offset field indicating the starting position or offset of the data contained in a fragmented packet relative to the data in the original packet. If the sum of the offset and the size of one fragmented packet differs from that of the next fragmented packet, the packets overlap. Now when this happens, a server vulnerable to teardrop attacks is unable to reassemble the packets resulting in a denial of service condition. Okay, so that was all the theoretical portion of this video. Now it's time to actually perform our very own DDUs attack. Okay, so now that we finished the theoretical part of how DDoS actually works and what it actually is with different types, let me just give you guys a quick demonstration on how you could apply a denial of service attack on a wireless network anywhere around you. Like this could be somewhere like Starbucks where you're sitting or this could be a library also or your college institution. No matter where you're sitting, this procedure will work. So the first thing we want to do is actually open up a terminal as because we will be doing most of our work on a command line basis. Now for this particular demonstration we will be actually using two tools. First is airrng which is a suit of tools which contains airrng airmong airplay nng and aerodyump. So these are the four tools that come along with it. And the second one that we'll be using is called max change. Okay. So let me just put my terminal on maximum so you guys can see what I'm actually writing out. So first thing we want to do is actually log in as a root. So let me just do that quickly. So we need to login as root because most of the stuff that we're going to do right now will need administrator access. Now the first thing we want to do is check out our wireless network cards name. And we can do that easily by typing if config. Now you can see that my wireless card is called WL1. And uh we get the MAC address and we also get the IPv6 address. So that's my wireless network card and we'll be actually setting that up in monitor mode. Now before we actually go into and start up our network car in monitor mode, let me just show you how you can install the two tools that I just spoke about that is airrng and Mac changanger. So to install airrackeng you can just go apppt get install airrackeng hit enter and this should do it for you. I already have it installed so it's not going to do much. To install Mac changanger you could just go the same command that is app get install Mac changanger and you can check if both the tools have been installed properly by opening the manual pages by typing man airrng. And this will open up the manual page for you. And let's also do the same for MAC changer. So what we're going to do first is set up our network interface card into monitor mode. So to do that, all we have to do is type if config and we need to put our network interface card down. So we go WL1 down and with the command IW config, we go mode monitor. Don't forget to specify the interface that you're working on. So IW config1 mode monitor. And all we have to do now is put it back up. So what we are going to type is if config wl1 up you can check the mode it'll say managed if it's in monitoring mode. So as you guys can see it says mode managed. So that's how we're going to go ahead. So you can check that just for your own purposes. So we can also check for only w1 by specifying the interface or you could also check the mode only by passing it through a pipe function and that is using gp mode. So IW config WL1 GP and mode. Well, mode begins with a capital M. So that's how you would probably return it. So as you guys can see that has returned the mode for us on along with the access point and the frequency. Okay, so that was a little fun trivia on how you could fetch the mode from a certain command that like I config by passing it through a pipe and grabbing it with mode. Grab basically means grab. Okay, so now moving on, we'll get to the more important stuff now. So firstly we need to check for some subprocesses that might still be running and that might actually interfere with our scanning process. So to do that what we do is airmong check and then the name of the interface. Now as you guys can see I have the network manager that is running out here and we need to kill that first and that can be easily done by going kill with the P ID. After that you can run a general command called airmong check and kill. So whatever it finds, it will kill it accordingly. And when it produces no results like this, that means you're ready to go as there are no subprocesses running that might actually interfere with our scan. Now what we want to do is we want to run a dump scan on the network interface card and check out all the possible access points that are available to us. So as you guys can see this produces bunch of access points and they come with their BSS IDs. They also have the power which is the PWR that is the power of the signal and let me go down back again. So yeah you can see the beacons you can see the data you can see the channels available and what the BSS ID is. It's the MAC ID that is actually tied in with the ESS ID which basically represents the name of the router. Now what we want to do from here is we want to choose which router we want to actually doss. Now the whole process of dosing is actually we will continuously deauthenticate all the devices that are connected to it. So for now I have chosen edurea Wi-Fi to actually doss out and once I send a deauthentication broadcast it will actually deauthenticate all the devices that are connected to it. Now this deauthentication is done with a tool called airplay which is a part of the airrack nng suit of tools. Now let us just see how we can use airplay by opening up the help command. So we go d-help and this opens up the help command for us. Now as you guys can see it shows us that we can send a deau authentication message by typing in the hyphen zero and then we need to type in the count. So what we are going to do is type in hyphen 0 which will send a deauthentication message and now we can type one or zero. So one will send only one deauthentication message while zero will continuously loop it and send a bunch of deauthentication messages. We are going to say zero because we want to be sure that we are deauthenticating everybody and we can also generally specify the person we also want to specifically deauthenticate but for this demonstration I'm just going to try and deau authenticate everybody that is there. So what we are going to do is we are going to copy down the MAC address or the BSS ID as you would know it and then we are going to run the authentication message. Now as you guys can see our deauthentication message is beginning to hunt on channel 9. Now as you guys know and as I already know that our BSS ID or the MAC address is working on channel 6. Now we can easily change the channel that our interface is working on by just going iwconfig 1 and then channel and then specifying the channel. Now as you guys can see our chosen router is working on channel 6. So that's exactly what we're going to do. Now, as you guys can see, it immediately starts sending deauthentication codes to the specified router. And this will actually make any device that is connected to that router almost unusable. You might see that you are still connected to the Wi-Fi, but try browsing the internet with them. You will never be able to actually reach any site as I'm constantly deauthenticating your service. You will need that four-way handshake all the time. And even if it completes, you are suddenly deauthenticated again because I'm running this thing on a loop. Now, you can let this command run for a few moments or how much of a time you want to do that guy for. Well, this is not exactly a DOS because you're doing it from one single machine, but you can also optimize this code to actually looks like it's running from several different machines. So, let me just show you how to do that. We're going to write a script file to actually optimize our code a lot. So, this script file will actually automate most of the things that we just did and also optimize a little by changing our MAC address every single time. So we become hard to actually point out. So the first thi
Original Description
🔥CEH v13 Certification Training - Powered by AI: https://www.edureka.co/ceh-ethical-hacking-certification-course
🔥Integrated MS+PGP Program in Data Science & AI:https://www.edureka.co/dual-certification-programs/ms-data-science-pgp-gen-ai-ml-birchwood
In this comprehensive *Cybersecurity Full Course* by Edureka, you'll explore the fundamental principles of cybersecurity. Whether you're new to the field or a seasoned professional, this Cybersecurity course is designed to help you grasp the core concepts of cybersecurity. Throughout this Cybersecurity course, you'll cover a wide range of topics essential for understanding digital security.
🔥𝐄𝐝𝐮𝐫𝐞𝐤𝐚 𝐂𝐲𝐛𝐞𝐫 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐓𝐫𝐚𝐢𝐧𝐢𝐧𝐠 (𝐔𝐬𝐞 𝐂𝐨𝐝𝐞: 𝐘𝐎𝐔𝐓𝐔𝐁𝐄𝟐𝟎) : https://www.edureka.co/cybersecurity-certification-training
00:00:00 Introduction
00:01:46 Cybersecurity Explained
00:53:59 What is Ethical Hacking?
01:07:49 Phases of ethical hacking
01:28:50 Ethical Hacking vs Cybersecurity
01:33:13 What is Phishing
01:51:47 What is Malvertising?
02:03:07 What is a Virus Hoax?
02:15:01 Best Antiviruses for Cybersecurity
02:30:02 Social Engineering in Cyber Security
02:39:07 Cybersecurity Threats
02:59:51 What is Cyber Kill Chain?
03:05:09 Top Cyber Attacks
03:13:29 DDOS Attack
03:32:47 Brute Force Attack
03:49:31 What is CSRF?
04:06:21 Cross Site Scripting
04:36:51 What is SSRF
04:49:35 SQL injection
05:08:18 What Is Identity and access management (IAM)?
06:20:29 Nmap
06:50:41 Password Cracking with John the Ripper
07:24:51 Cybersecurity Tools
07:38:49 Cybersecurity Projects
07:50:07 AI in Cybersecurity
07:59:56 Cybersecurity at the Age of AI
08:05:42 Future of Cybersecurity
08:15:14 Exploring Cybersecurity as a Career: Is it Worth it?
08:22:49 Cybersecurity Certifications
08:32:53 CEH v13 Certification
08:50:02 Cybersecurity Roadmap
09:28:10 Top Cybersecurity Skills
09:36:10 Cybersecurity Interview Questions
🔴 𝐋𝐞𝐚𝐫𝐧 𝐓𝐫𝐞𝐧𝐝𝐢𝐧𝐠 𝐓𝐞𝐜𝐡𝐧𝐨𝐥𝐨𝐠𝐢𝐞𝐬 𝐅𝐨𝐫 𝐅𝐫𝐞𝐞! 𝐒𝐮𝐛𝐬𝐜𝐫���
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from edureka! · edureka! · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
ChatGPT Not Working - 4 Fixes | How To Fix ChatGPT Not Working | Why Is ChatGPT Not Working |Edureka
edureka!
Advanced Java script Tutorial | JavaScript Training | JavaScript Programming | Edureka Rewind
edureka!
Java script interview question and answers | Java script training | Edureka Rewind
edureka!
OpenAI API Tutorial using Python | How to use OpenAI GPT-3 API - Ada Babbage Curie Davinci | Edureka
edureka!
What is Unsupervised Learning ? | Unsupervised Learning Algorithms| Machine Learning | Edureka
edureka!
Top 10 Applications of Machine Learning in 2023 | Machine Learning Training | Edureka Rewind - 7
edureka!
Machine Learning Engineer Career Path in 2023 | Machine Learning Tutorial | Edureka Rewind - 6
edureka!
10 Must Have Machine Learning Engineer Skills That Will Get You Hired | Edureka Rewind - 7
edureka!
Data Structures in Python | Data Structures and Algorithms in Python | Edureka | Python Live - 5
edureka!
Python Lists | List in Python | Python Training | Edureka Rewind
edureka!
Predictive Analysis Using Python | Learn to Build Predictive Models | Python Training | Edureka
edureka!
Machine Learning Tutorial | Machine Learning Algorithm | Machine Learning Engineer Program | Edureka
edureka!
How to use Pandas in Python | Python Pandas Tutorial | Python Tutorial | Edureka Rewind
edureka!
Parameters in Tableau | Tableau Parameters Examples | Tableau Tutorial | Edureka Rewind
edureka!
Top 10 Reasons to Learn Tableau in 2023 | Tableau Certification | Tableau | Edureka Rewind
edureka!
Tableau Developer Roles & Responsibilities | Become A Tableau Developer | Tableau | Edureka Rewind
edureka!
Deep Learning With Python | Deep Learning Tutorial For Beginners | Edureka Rewind
edureka!
Realtime Object Detection | Object Detection with TensorFlow | Edureka | Deep Learning Rewind - 2
edureka!
Top 20 Tableau Tips and Tricks in 20 Minutes | Tableau Tutorial | Tableau Training | Edureka Rewind
edureka!
Climate Change Prediction using Time Series | Python Projects | Edureka | DS Rewind - 5
edureka!
ReactJS Installation Tutorial | ReactJS Installation On Windows | ReactJS Tutorial | Edureka Rewind
edureka!
Phases in Cybersecurity | Cybersecurity Training | Edureka | Cybersecurity Rewind - 2
edureka!
What Is React | ReactJS Tutorial for Beginners | ReactJS Training | Edureka Rewind
edureka!
Cybersecurity Frameworks Tutorial | Cybersecurity Training | Edureka | Cybersecurity Rewind- 2
edureka!
React vs Angular 4 | Angular 2 vs React | React & Angular | ReactJS Training | Edureka Rewind - 5
edureka!
ReactJS Components Life-Cycle Tutorial | React Tutorial for Beginners | Edureka Rewind
edureka!
Ethical Hacking using Kali Linux | Ethical Hacking Tutorial | Edureka | Cybersecurity Rewind - 3
edureka!
Types Of Artificial Intelligence | Artificial Intelligence Explained | What is AI? | Edureka
edureka!
Top 10 Applications Of Artificial Intelligence in 2023 | Artificial Intelligence| Edureka Rewind
edureka!
The Future of AI | How will Artificial Intelligence Change the World in 2023? | Edureka Rewind
edureka!
What is Artificial Intelligence | Artificial Intelligence Tutorial For Beginners | Edureka Rewind
edureka!
Google Cloud IAM | Identity & Access Management on GCP | Edureka | GCP Rewind - 5
edureka!
Google Cloud AI Platform Tutorial | Google Cloud AI Platform | GCP Training | Edureka Rewind
edureka!
Projects in Google Cloud Platform | GCP Project Structure | GCP Training | Edureka Rewind
edureka!
How to Become a Data Scientist | Data Scientist Skills | Data Science Training | Edureka Rewind - 3
edureka!
Agglomerative and Divisive Hierarchical Clustering Explained | Data Science Training | Edureka Live
edureka!
Climate Change Prediction using Time Series | Python Projects | Edureka | DS Rewind - 5
edureka!
Data Science Project - Covid-19 Data Analysis | Python Training | Edureka | DS Rewind - 6
edureka!
What is Honeycode? | Introduction to Honeycode | Edureka
edureka!
Difference between Amazon AWS and Google Cloud | GCP Training Google Cloud | Edureka Live
edureka!
DevOps Lifecycle | Introduction To DevOps | DevOps Tools | What is DevOps? | Edureka Rewind
edureka!
Introduction to DevOps | DevOps Tutorial for Beginners | DevOps Tools | DevOps | Edureka Rewind
edureka!
How to Create Login System using Python | Python Programming Tutorial | Edureka Rewind
edureka!
Python Developer | How to become Python Developer | Python Tutorial | Edureka Rewind
edureka!
How to become a Data Engineer | Complete Roadmap to become a Data Engineer| Data Engineer | Edureka
edureka!
Azure Data Engineer Certification [DP 203] | How to Become Azure Data Engineer [2023] | Edureka
edureka!
Data Analyst vs Data Engineer vs Data Scientist | Data Analytics Masters Program | Edureka Rewind
edureka!
DevOps Engineer day-to-day Activities | DevOps Engineer Responsibilities | Edureka Rewind
edureka!
How to Become a DevOps Engineer? | DevOps Engineer Roadmap | Edureka | DevOps Rewind
edureka!
How to Become a Data Engineer? | Data Engineering Training | Edureka
edureka!
How To Become A Big Data Engineer? | Big Data Engineer Roadmap | Edureka Rewind
edureka!
Python Integration for Power BI and Predictive Analytics | Power BI Training | Edureka
edureka!
Power BI KPI Indicators Tutorial | Custom Visuals In Power BI | Power BI Training | Edureka Rewind
edureka!
Apache HBase Tutorial For Beginners | What is Apache HBase? | Big Data Training | Edureka Rewind
edureka!
Big Data Hadoop Tutorial For Beginners | Hadoop Training | Big Data Tutorial | Edureka Rewind
edureka!
Big Data Analytics | Big Data Analytics Use-Cases | Big Data Tutorial | Edureka Rewind
edureka!
What Is Power BI? | Introduction To Microsoft Power BI | Power BI Training | Edureka Rewind
edureka!
Triggers in Salesforce | Salesforce Apex Triggers | Salesforce Tutorial | Edureka Rewind
edureka!
How To Become A Salesforce Developer | Salesforce For Beginners| Salesforce Training Edureka Rewind
edureka!
Java ArrayList Tutorial | Java ArrayList Examples | Java Tutorial | Edureka Rewind
edureka!
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
I Built a Free Privacy-First Developer Toolkit - No Data Leaves Your Browser
Dev.to · RavikiranReddy Balemla
A Non-Technical Way to Look at SSH
Dev.to · AbdulRasheed Agunbiade
CCIP Has Three Ways to Move Tokens Cross-Chain. Choosing the Wrong One Is an Audit Finding.
Dev.to · Ramprasad Edigi
Electron's docs quietly dropped their recommended security tool. What now?
Dev.to · Gyu
Chapters (33)
Introduction
1:46
Cybersecurity Explained
53:59
What is Ethical Hacking?
1:07:49
Phases of ethical hacking
1:28:50
Ethical Hacking vs Cybersecurity
1:33:13
What is Phishing
1:51:47
What is Malvertising?
2:03:07
What is a Virus Hoax?
2:15:01
Best Antiviruses for Cybersecurity
2:30:02
Social Engineering in Cyber Security
2:39:07
Cybersecurity Threats
2:59:51
What is Cyber Kill Chain?
3:05:09
Top Cyber Attacks
3:13:29
DDOS Attack
3:32:47
Brute Force Attack
3:49:31
What is CSRF?
4:06:21
Cross Site Scripting
4:36:51
What is SSRF
4:49:35
SQL injection
5:08:18
What Is Identity and access management (IAM)?
6:20:29
Nmap
6:50:41
Password Cracking with John the Ripper
7:24:51
Cybersecurity Tools
7:38:49
Cybersecurity Projects
7:50:07
AI in Cybersecurity
7:59:56
Cybersecurity at the Age of AI
8:05:42
Future of Cybersecurity
8:15:14
Exploring Cybersecurity as a Career: Is it Worth it?
8:22:49
Cybersecurity Certifications
8:32:53
CEH v13 Certification
8:50:02
Cybersecurity Roadmap
9:28:10
Top Cybersecurity Skills
9:36:10
Cybersecurity Interview Questions
🎓
Tutor Explanation
DeepCamp AI