Cyber Security
🔒 Log in to trackCyber attacks and social engineering
🔒 Log in to track| Attack | How it works |
|---|---|
| Phishing | Fake e-mail/site mimicking a bank or service to harvest credentials |
| Spear phishing | Phishing targeted at one person/organisation |
| Vishing / Smishing | Phishing by Voice calls / SMS |
| Pharming | Redirects users to fake sites by poisoning DNS/host files - no click needed |
| DoS / DDoS | Flooding a server with traffic; DDoS = Distributed, from a botnet of many machines |
| Man-in-the-Middle (MITM) | Attacker secretly intercepts/relays communication between two parties (open Wi-Fi sniffing) |
| SQL Injection | Malicious SQL typed into input fields to manipulate the database |
| Brute force / Dictionary | Trying every possible password / a wordlist of likely passwords |
| Social engineering | Manipulating humans (urgency, authority) - the 'human hacking' umbrella |
| Spoofing | Faking an identity: e-mail, IP, caller ID, website |
| Sniffing/Eavesdropping | Passive capture of network traffic |
| Identity theft | Stealing personal data to impersonate (Sec 66C IT Act) |
| Website defacement | Replacing a site's content (electronic vandalism) |
| Salami attack | Stealing tiny amounts (rounding offs) that accumulate large |
| Zero-day | Attack through a vulnerability the vendor has not yet patched |
Detailed notes
Attacks on people and systems
Beyond malware, exams list named attacks — methods of cheating users or breaking services. Group them by target.
Attacks that target PEOPLE (social engineering)
- Phishing: a fake mail/site dressed as your bank or company, asking for passwords, OTPs, card details. "Phish" = fishing for victims with bait.
- Spear phishing: phishing aimed at one specific person or office, with personal details to look genuine.
- Vishing (Voice) and smishing (SMS): the same bait delivered by phone call or SMS.
- Pharming: even a correctly typed URL lands you on a fake site — the attacker poisons the DNS/server side.
- Social engineering is the umbrella: manipulating people (fear, urgency, authority — "your account will be blocked in 1 hour") instead of breaking code.
Attacks that target SERVICES
- DoS (Denial of Service): flooding a server with useless requests so genuine users are shut out.
- DDoS (Distributed DoS): the flood comes from many machines at once, usually a botnet.
- Man-in-the-Middle (MITM): the attacker secretly sits between two parties, reading or altering what they exchange (e.g. on open Wi-Fi).
Classic named attacks from exam history
| Attack | Trick |
|---|---|
| Salami slicing/salami attack | stealing tiny amounts from very many accounts — paise shaved off, hard to notice |
| Data diddling | changing data before or during entry into the system (false figures) |
| Logic bomb | malicious code that sleeps until a trigger — a date or event — then detonates |
| SQL injection | typing database commands into a web form's input box to read the database |
| Brute force | trying every possible password combination until one works |
| Eavesdropping | passively listening to data as it travels |
Telling the twins apart
Phishing asks the user to hand over data; pharming needs no user mistake — the address itself is hijacked. DoS asks nothing of users — it drowns the server. MITM does not flood or fake a site — it listens in the middle of a real conversation. Salami steals small and often; data diddling alters records; a logic bomb waits for its trigger.
Quick revision
- Phishing = mail bait; Vishing = voice; Smishing = SMS; Pharming = fake site despite correct URL.
- DoS/DDoS = flood the server (DDoS from a botnet); MITM = listen between two parties.
- Salami = tiny thefts, many accounts; Logic bomb = waits for a trigger; SQL injection = commands in a form.
- Social engineering = attacking the person, not the machine.
Types of questions asked
Every way this subtopic shows up in exams — how to recognise it, the formula or logic to use, and a solved example.
Type 1: Phishing family (mail, voice, SMS, pharming)very common4 practice Q
A fake-bank-mail / fake-call / fake-SMS / correct-URL-fake-site scenario asking for the attack's name, or 'vishing/smishing mean ___'.
- Bait by e-mail or fake site = Phishing; by phone call = Vishing; by SMS = Smishing.
- Correct URL still lands on a fake site = Pharming (address hijacked, no user mistake).
- Aimed at ONE chosen person = Spear phishing. All are social engineering — attacking the person, not the machine.
Example: A caller claiming to be from the bank asks for the OTP sent to Meena's phone. This fraud is:
Vishing — voice phishing; a real bank never asks for OTPs.
Type 2: DoS, DDoS and botnet floodscommon3 practice Q
'Server is flooded with requests and genuine users are shut out', 'attack from thousands of machines at once'.
- Flood from one source = DoS; from many machines at once (usually a botnet) = DDoS.
- The aim is denial of service, not data theft — the service drowns.
- DDoS question almost always names 'distributed/thousands of computers' — that word IS the answer key.
Example: A shopping site crashes as thousands of hijacked machines hammer it with fake requests together. This is:
DDoS — Distributed Denial of Service; 'distributed' = many sources at once.
Type 3: Man-in-the-Middle and eavesdroppingoccasional3 practice Q
'Communication between A and B is read/changed by a hidden third party', risks of open public Wi-Fi.
- MITM = attacker sits silently between two parties, reading or altering the exchange — neither side notices.
- Classic setting: open public Wi-Fi without encryption.
- Defence: encrypted connections (HTTPS/VPN) — the middle man sees only ciphertext.
Example: On free airport Wi-Fi, an attacker secretly reads the data exchange between Amit and the site he is using. This attack is:
Man-in-the-Middle (MITM) — the hidden listener between two ends.
Type 4: Classic named attacks (salami, diddling, logic bomb, SQLi)common4 practice Q
'Tiny amounts stolen from many accounts', 'records changed during entry', 'code that waits for a date', 'commands typed into a login box'.
- Salami attack = many tiny thefts (paise from lakhs of accounts).
- Data diddling = data changed before/during entry.
- Logic bomb = sleeps until a trigger (date/event).
- SQL injection = database commands typed into a web form; Brute force = trying every password.
Example: A bank clerk's program quietly takes one rupee from thousands of accounts into his own. This is a:
Salami attack — slicing tiny amounts off very many accounts.
Shortcut tricks
⚡ The -ishing family
Phishing = fake mail/site; Vishing = Voice; SMishing = SMS; Pharming = fake site with NO click (DNS poisoned). If the victim 'entered a real-looking site without clicking any link', think pharming.
Example: A fake banking site reached via a corrupted DNS entry is?
Pharming.
⚡ MITM = postman reading letters
Man-in-the-Middle: both parties think they talk to each other; the attacker relays (and reads/edits) everything - classic on open Wi-Fi. Pure listening without relaying = sniffing.
Example: Attacker secretly relaying messages between a user and the bank is?
Man-in-the-Middle attack.
Where students lose marks
Confusing pharming with phishing - pharming needs no victim click; DNS is poisoned.
Calling DDoS a single-machine attack - the D means distributed (botnet).
Believing strong passwords alone stop phishing - awareness + 2FA are needed; no password resists a fake site.
Practice sets — 20 questions
Sets of 10, mixed across the question types above. Each answer comes with a step-by-step explanation.
Topic test · 10 questions
Suggested time 5 min · wrong answers go to your mistake notebook automatically.