Word Notes

Word Notes

By N2K NetworksNewsTechnologyTech News
Download on the App Store

Word Notes episodes

  • credential stealing (verb)

    From the intrusion kill chain model, the first part of an exploitation technique where the hacker tricks their victims into revealing their login credentials. In the second part of the technique, hackers legitimately log into the targeted system and gain access to the underlying network with the same permissions as the victim. Hackers use this method 80% of the time compared to other ways to gain access to a system like developing zero day exploits for known software packages. The most common way hackers steal credentials is with some version of a phishing attack.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    4 min
  • The Bombe (noun)

    An electro-mechanical device used to break Enigma-enciphered messages about enemy military operations during the Second World War. The first bombe–named Victory and designed by Alan Turning and Gordon Welchman– started code-breaking at Bletchley Park on 14 March 1940, a year after WWII began. By the end of the war, five years later, almost 2000, mostly women, sailors and airmen operated 211 bombe machines in the effort. The allies essentially knew what the German forces were going to do before the German commanders in the field knew. Historians speculate that the effort at Bletchley Park shortened the war by years and estimate the number of lives saved to be between 14 and 21 million.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    5 min
  • cross-site scripting (noun)

    From the intrusion kill chain model, a malicious code delivery technique that allows hackers to send code of their choosing to their victim’s browser. XSS takes advantage of the fact that roughly 90% of web developers use the JavaScript scripting language to create dynamic content on their websites. Through various methods, hackers store their own malicious javascript code on unprotected websites. When the victim browses the site, the web server delivers that malicious code to the victim’s computer and the victim’s browser runs the code.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    4 min
  • penetration test (noun)

    The process of evaluating the security of a system or network by simulating an attack on it. Sometimes called "ethical hacking" or white hat hacking. The phrase started to appear in U.S. military circles in the mid 1960s as time sharing computers became more necessary for daily operations. Computer security experts from Rand Corporation began describing computer compromises as “penetrations.” By the early 1970s, government leaders formed tiger teams of penetration testers to probe for weaknesses in various government systems.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    5 min
  • social engineering (noun)

    The art of convincing a person or persons to take an action that may or may not be in their best interests. Social engineering in some form or the other has been around since the beginning of time. The biblical story of Esau and Jacob might be considered one of the earliest written social engineering stories. As applied to cybersecurity, it usually involves hackers obtaining information illegitimately by deceiving or manipulating people who have legitimate access to that information. Common tactics involve phishing attacks and watering hole attacks.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    5 min
  • zero-day (adjective)

    A class of software-security-weakness-issues where independent researchers discover a software flaw before the owners of the code discover it. Zero-day, or 0-day in hacker slang, refers to the moment the race starts, on day zero, between network defenders who are trying to fix the flaw before hackers leverage it to cause damage. It is a race because on day zero, there is no known fix to the issue.

    Learn more about your ad choices. Visit megaphone.fm/adchoices

    4 min
  • NMAP (noun)

    A network mapping tool that pings IP addresses looking for a response and can discover host names, open communications ports, operating system names and versions. Written and maintained by Gordon Lyon, a.k.a. Fyodor, it is a free and open source software application used by both system admins and hackers alike and has been a staple in the security community for well over two decades.

    CyberWire Glossary link: https://thecyberwire.com/glossary/nmap


    Learn more about your ad choices. Visit megaphone.fm/adchoices

    4 min

About Word Notes

From the publisher's feed

A fun and informative cybersecurity audio glossary from N2K.

More shows like Word Notes

WSJ What’s News by The Wall Street Journal

WSJ What’s News

4,348 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,639 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Daily Tech Headlines by Sarah Lane, Robb Dunewood and Jenn Cutter

Daily Tech Headlines

157 Listeners

WSJ Minute Briefing by The Wall Street Journal

WSJ Minute Briefing

677 Listeners

The Indicator from Planet Money by NPR

The Indicator from Planet Money

9,537 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Caveat by N2K Networks

Caveat

93 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The FAIK Files by Perry Carpenter | N2K Networks

The FAIK Files

18 Listeners