How unit 5 is examined
This unit covers the tools attackers use (proxies, password crackers, keyloggers, malware, DoS, buffer overflow, wireless attacks) and phishing; malware, DoS, phishing and Trojans carry most marks.
Proxy Servers and Anonymizers
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. A proxy server is an intermediary computer that forwards a user's requests to the destination so the destination sees the proxy's IP address, not the user's; an anonymizer is a tool or website that hides the user's identity and IP address and browsing details while surfing.
Key points.
- A proxy sits between client and server, receives the request, sends it on its own behalf and returns the reply, so the target only sees the proxy address.
- Legitimate uses are caching, content filtering and access control, but criminals use them to hide identity and location.
- Anonymizers (web anonymizers, VPNs, Tor) strip or encrypt identifying data such as IP address, cookies and browser details.
- Phishers host fake sites and mail servers behind proxies and anonymizers, so the trace stops at the proxy and not at the criminal.
- They also redirect victims through proxy chains to the fake page and relay stolen credentials to the attacker without exposing his address.
- Chaining several proxies across countries makes tracing slow because each hop needs separate legal action.
- Countermeasures are blocking known open proxies and Tor exit nodes, logging and correlating traffic, checking mail headers, and international cooperation with ISPs.
Answer frame. Open with the definition of proxy and anonymizer; draw client -> proxy -> target if space allows; develop points 1-7 in order, stressing points 4-5 for the phishing question; close with the countermeasures line.
<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-01" viewBox="0 0 553 80" width="553" height="80" role="img" aria-label="Attacker hides behind proxy (Prx); victim and site see only the proxy address"><style>#dsfig-u5-01 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-01 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-01 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-01 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-01 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-01 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-01 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-01 .t{fill:#16181D;font-weight:500}#dsfig-u5-01 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-01 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-01 .dot{fill:#16181D}#dsfig-u5-01 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-01 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-01 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-01 .ah{fill:#454C5A}#dsfig-u5-01 .ah.hi{fill:#2340B8}#dsfig-u5-01 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-01 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-01 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-01 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-01 .e{stroke:#B1B7C3}html.dark #dsfig-u5-01 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-01 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-01 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-01 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-01 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-01 .t{fill:#E6E8ED}html.dark #dsfig-u5-01 .t.inv{fill:#0F1115}html.dark #dsfig-u5-01 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-01 .dot{fill:#E6E8ED}html.dark #dsfig-u5-01 .ann{fill:#8FA3FF}html.dark #dsfig-u5-01 .lbl{fill:#858D9C}html.dark #dsfig-u5-01 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-01 .ah{fill:#B1B7C3}html.dark #dsfig-u5-01 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-01 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-01 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-01 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah8" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh8" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,40 L191,40" marker-end="url(#ah8)"/><path class="e" d="M231,40 L363,40" marker-end="url(#ah8)"/><path class="e" d="M403,40 L492,40" marker-end="url(#ah8)"/><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">Atk</text><circle class="n" cx="212" cy="40" r="18"/><text class="t" x="212" y="40" dy=".35em" text-anchor="middle">Prx</text><circle class="n" cx="384" cy="40" r="18"/><text class="t" x="384" y="40" dy=".35em" text-anchor="middle">Web</text><circle class="n" cx="513" cy="40" r="18"/><text class="t" x="513" y="40" dy=".35em" text-anchor="middle">Vic</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">Attacker hides behind proxy (Prx); victim and site see only the proxy address</figcaption></figure>
<mark>A proxy server hides the real IP address of the user behind its own, and an anonymizer removes identifying information, so cyber criminals use them to conceal identity and location.</mark>
Asked: [7 marks] (Nov 2023) What is the role of proxy servers and anonymizers in phishing? Asked: [7 marks] (Dec 2025) Explain tools used in cybercrimes such as proxy servers, anonymizers, key loggers, spyware and backdoors.
Password Cracking
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>
Definition. Password cracking is the process of recovering or guessing passwords from stored data (usually hashes) or from a system, to gain unauthorised access.
Key points.
- A dictionary attack tries every word of a wordlist, which succeeds against common or weak passwords.
- A brute-force attack tries every possible character combination, so it always succeeds eventually but time grows exponentially with password length.
- A hybrid attack mixes a dictionary with modifications such as adding digits or symbols ("password" to "P@ssw0rd1").
- Rainbow tables are precomputed hash-to-password lookups that crack unsalted hashes quickly, and salting defeats them.
- Other methods are shoulder surfing, social engineering, guessing, keylogging, sniffing on the network and phishing.
- Common tools are John the Ripper, Hashcat, Cain and Abel, THC-Hydra and Ophcrack.
- Countermeasures are long passwords with mixed characters, salted strong hashes, account lockout after failed attempts, multi-factor authentication and no password reuse.
Answer frame. Open with the definition; list the methods (points 1-5), then tools, then countermeasures; close by saying strong, unique passwords with MFA make cracking impractical. For a "any two" short-note question, pair it with Types of Hackers or Nature of Criminality from other units.
<mark>Password cracking is recovering passwords from stored or transmitted data by dictionary, brute-force, hybrid and rainbow-table attacks.</mark>
Pitfall: Naming only brute force loses marks; the examiner wants methods, tools and countermeasures.
Asked: [14 marks] (Dec 2024) Write short notes on any two: i) Password Cracking ii) Nature of Criminality iii) Types of Hackers
Key Loggers and Spyware
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>
Definition. A keylogger is a hardware device or software that secretly records every keystroke a user types, and spyware is software that secretly gathers information about a user and sends it to a third party.
Key points.
- Software keyloggers run hidden as a driver, hook or process, capture keystrokes (and sometimes screenshots and clipboard) and save them to a file or send them by mail or FTP.
- Hardware keyloggers are small devices plugged between keyboard and computer, or built into a keyboard, and are invisible to antivirus software.
- They steal passwords, card numbers and private messages, so they support identity theft and banking fraud.
- Keyloggers arrive through Trojans, infected downloads, phishing attachments or physical access.
- Spyware monitors browsing, installs adware, changes browser settings and steals personal data, usually bundled with free software.
- Detection uses antivirus and anti-spyware scans, checking running processes, and inspecting USB ports for unknown devices.
- Prevention is updated antivirus, downloading only trusted software, virtual on-screen keyboards, two-factor authentication and not using public computers for sensitive work.
Answer frame. Open with the definition of keylogger; give hardware vs software types; then spyware; then detection and prevention; close with one real example such as stealing bank passwords.
<mark>A keylogger records everything typed on the keyboard and passes it to the attacker, while spyware silently collects user information without consent.</mark>
Asked: [14 marks] (Jun 2025) Write short notes on: a) Key loggers b) Email spoofing c) Software piracy
Email spoofing (Unit 1) is sending mail with a forged sender address by editing the From and Reply-To header fields so it appears to come from a trusted person. Software piracy (Unit 2) is unauthorised copying, distribution or use of licensed software, and is punishable under the Copyright Act and IT Act with fines and imprisonment.
Virus and Worms
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>
Definition. A virus is self-replicating malicious code that attaches itself to a host file or program and spreads when the infected host is run or shared; a worm is standalone self-replicating malware that spreads over networks by itself without needing a host or human action.
Key points.
- A virus needs a host file and a user action such as opening the file, whereas a worm runs independently.
- Virus life cycle has four phases: dormant (idle, waiting for a trigger), propagation (copies itself into other files), triggering (a date, event or count activates it) and execution (the payload runs).
- Viruses spread through email attachments, removable media such as pen drives, downloads, pirated software and network shares.
- Types of virus: boot sector (infects the boot record), file infector (attaches to executables), macro (in Word and Excel documents), polymorphic (changes its code to evade scanners), stealth (hides changes from the OS) and multipartite (infects both boot sector and files).
- Types of worm: email worm, network (Internet) worm exploiting vulnerabilities, file-sharing or instant-messaging worm, with examples Morris, ILOVEYOU, Code Red and Blaster.
- A logic bomb is code hidden in a program that runs its damage only when a condition is met, such as a date or an employee's name missing from payroll.
- Damage includes deleting files, slowing systems, and network congestion by worm traffic.
- Countermeasures are updated antivirus, patching, not opening unknown attachments, backups and firewalls.
<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-02" viewBox="0 0 510 80" width="510" height="80" role="img" aria-label="Virus life cycle: Dormant, Propagation, Triggering, Execution"><style>#dsfig-u5-02 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-02 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-02 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-02 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-02 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-02 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-02 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-02 .t{fill:#16181D;font-weight:500}#dsfig-u5-02 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-02 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-02 .dot{fill:#16181D}#dsfig-u5-02 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-02 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-02 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-02 .ah{fill:#454C5A}#dsfig-u5-02 .ah.hi{fill:#2340B8}#dsfig-u5-02 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-02 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-02 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-02 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-02 .e{stroke:#B1B7C3}html.dark #dsfig-u5-02 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-02 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-02 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-02 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-02 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-02 .t{fill:#E6E8ED}html.dark #dsfig-u5-02 .t.inv{fill:#0F1115}html.dark #dsfig-u5-02 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-02 .dot{fill:#E6E8ED}html.dark #dsfig-u5-02 .ann{fill:#8FA3FF}html.dark #dsfig-u5-02 .lbl{fill:#858D9C}html.dark #dsfig-u5-02 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-02 .ah{fill:#B1B7C3}html.dark #dsfig-u5-02 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-02 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-02 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-02 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah9" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh9" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,40 L165.2,40" marker-end="url(#ah9)"/><path class="e" d="M205.2,40 L311.4,40" marker-end="url(#ah9)"/><path class="e" d="M351.4,40 L449,40" marker-end="url(#ah9)"/><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">Dor</text><circle class="n" cx="186.2" cy="40" r="18"/><text class="t" x="186.2" y="40" dy=".35em" text-anchor="middle">Pro</text><circle class="n" cx="332.4" cy="40" r="18"/><text class="t" x="332.4" y="40" dy=".35em" text-anchor="middle">Trg</text><circle class="n" cx="470" cy="40" r="18"/><text class="t" x="470" y="40" dy=".35em" text-anchor="middle">Exe</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">Virus life cycle: Dormant, Propagation, Triggering, Execution</figcaption></figure>
| Basis | Virus | Worm |
|---|---|---|
| Host | Needs a host file | Standalone program |
| Activation | Needs user to run the host | Runs and spreads on its own |
| Spread | Slow, via files and media | Fast, over networks |
| Target | Files and programs | Network and system resources |
| Impact | Corrupts or deletes files | Congests networks, creates backdoors |
| Example | CIH, Melissa | Morris, Code Red |
Which is more threatening. Worms are generally more threatening because they spread without any human action, reach thousands of machines in minutes, overload networks and carry payloads such as backdoors; viruses are limited by needing a host and user action. Countermeasures are the same: patching, antivirus and firewalls.
Answer frame. Open with both definitions; draw the life-cycle diagram for the life-cycle question; give types and spread; add the table for comparison questions; for "more threatening" state the verdict (worm) with reasons; close with prevention.
<mark>A virus needs a host and human action to spread, whereas a worm is self-replicating and spreads across networks on its own.</mark>
Pitfall: Do not say worms need a host file; that is the key difference examiners mark.
Asked: [7 marks] (Jun 2020, Dec 2024) What do you understand by term VIRUS and WORMS? Give definitions along with their types in detail. Asked: [7 marks] (Nov 2022, Jun 2025) Which are more threatening to cyber security between viruses and worms? Describe precisely. Asked: [7 marks] (Nov 2019) What is computer virus? How the virus spread? Asked: [7 marks] (Dec 2020) Write down the life-cycle phases of virus.
Trojan Horses
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>
Definition. A Trojan horse is a malicious program disguised as useful or legitimate software that tricks the user into installing it and then performs hidden harmful actions.
Key points.
- A Trojan does not replicate itself; it relies on the user to run it, which separates it from viruses and worms.
- It spreads through email attachments, fake downloads, cracked software, malicious websites and infected removable media.
- It conceals itself by looking like a game, utility, document or update.
- Payload actions include opening a backdoor for remote control, stealing passwords and data, installing keyloggers, deleting files and downloading more malware.
- Effect on the system: slow performance, crashes, changed settings and unknown processes; effect on the network: the machine becomes a bot for DDoS, spam or proxy use.
- Types are remote access Trojan (RAT), data-stealing or banking Trojan, downloader, and destructive Trojan.
- Ransomware encrypts the victim's files and demands payment (ransom), usually in cryptocurrency, for the decryption key; it is often delivered by a Trojan or phishing mail (WannaCry, Petya are examples).
- Email abuse means misuse of email such as spam, phishing, harassment, bombing and spoofing.
- Prevention: antivirus, do not run unknown files, patch systems, regular offline backups against ransomware, and email filtering.
| Basis | Trojan horse | Backdoor |
|---|---|---|
| Meaning | Disguised malicious program | Secret way to bypass authentication |
| Purpose | Deceive user into running it, then harm | Give hidden, repeated access |
| Spread | Through user installing it | Planted by attacker, developer or malware |
| Function | Steals, damages, drops other malware | Remote control and entry |
| Example | Fake game with RAT | Hidden admin account, Netcat listener |
| Relation | A Trojan often installs a backdoor | A backdoor can exist without a Trojan |
Answer frame. Open with the definition; for "how it affects" cover infection vector, payload and system/network effects; for the 14-mark question give email abuse, Trojans and ransomware about 4 points each with prevention; for the comparison use the table.
<mark>A Trojan horse is malware that appears to be legitimate software but secretly carries out harmful actions once the user runs it.</mark>
Asked: [7 marks] (Dec 2020) How Trojan Horses affect the computer System/Network? Asked: [7 marks] (Nov 2023) What is the differences between Trojan horses and Backdoors? Asked: [14 marks] (Dec 2024) Discuss the following attacks/crimes in detail: i) Email Abuse ii) Trojan Horses iii) Ransomware attack
Backdoors
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. A backdoor (trapdoor) is a hidden method of bypassing normal authentication to gain remote access to a computer, left by a developer or installed by malware.
Key points.
- Attackers install backdoors through Trojans or worms so they can return later without logging in.
- Examples are hidden admin accounts, open ports with listeners such as Netcat, and remote access tools such as Back Orifice.
- A firewall filters network traffic by rules and blocks unauthorised connections, which helps stop backdoor and worm traffic.
- Detect with port scans, netstat and antivirus; prevent with patching, firewalls and removing unused accounts.
Asked: [14 marks] (Nov 2019, Dec 2020) Write short notes on any three: a) Back door b) Logic Bomb c) Worm d) Spyware e) Firewalls (Logic bomb and worm are under Virus and Worms, spyware under Key Loggers)
DoS and DDoS Attacks
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>
Definition. A Denial of Service (DoS) attack floods a server, service or network from one source so legitimate users cannot use it; a Distributed DoS (DDoS) does the same from many compromised computers (a botnet) at once.
Key points.
- The goal is availability loss by exhausting bandwidth, CPU, memory or connection tables, not stealing data.
- Attack steps: the attacker builds a botnet by infecting machines, controls it through a command and control server, then commands all bots to send traffic at the victim at the same time.
- SYN flood sends many TCP SYN requests without completing the handshake, filling the server's half-open connection table.
- ICMP (ping) flood and Smurf attack use huge ping traffic, and UDP flood sends floods of UDP packets to random ports.
- Ping of Death sends an oversized malformed packet; teardrop sends overlapping fragments that crash the host.
- DDoS is harder to stop because traffic comes from thousands of real IPs, so blocking one address does nothing.
- Impact: website downtime, financial loss, lost reputation and disruption of services.
- Mitigation: firewalls and rate limiting, ingress filtering, SYN cookies, load balancers, CDN and traffic scrubbing services, and blackholing.
<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u5-03" viewBox="0 0 510 252" width="510" height="252" role="img" aria-label="DDoS: attacker, command server (CC), bots (B1-B3), victim server"><style>#dsfig-u5-03 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u5-03 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u5-03 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u5-03 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u5-03 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u5-03 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u5-03 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u5-03 .t{fill:#16181D;font-weight:500}#dsfig-u5-03 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u5-03 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u5-03 .dot{fill:#16181D}#dsfig-u5-03 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u5-03 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u5-03 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u5-03 .ah{fill:#454C5A}#dsfig-u5-03 .ah.hi{fill:#2340B8}#dsfig-u5-03 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u5-03 .wl .t{font-size:12px;font-weight:700}#dsfig-u5-03 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u5-03 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u5-03 .e{stroke:#B1B7C3}html.dark #dsfig-u5-03 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u5-03 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u5-03 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u5-03 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u5-03 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u5-03 .t{fill:#E6E8ED}html.dark #dsfig-u5-03 .t.inv{fill:#0F1115}html.dark #dsfig-u5-03 .kd{stroke:#E6E8ED}html.dark #dsfig-u5-03 .dot{fill:#E6E8ED}html.dark #dsfig-u5-03 .ann{fill:#8FA3FF}html.dark #dsfig-u5-03 .lbl{fill:#858D9C}html.dark #dsfig-u5-03 .ptr{fill:#8FA3FF}html.dark #dsfig-u5-03 .ah{fill:#B1B7C3}html.dark #dsfig-u5-03 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u5-03 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u5-03 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u5-03 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah10" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh10" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,126 L148,126" marker-end="url(#ah10)"/><path class="e" d="M184.8,115.5 L280.5,51.6" marker-end="url(#ah10)"/><path class="e" d="M188,126 L277,126" marker-end="url(#ah10)"/><path class="e" d="M184.8,136.5 L280.5,200.4" marker-end="url(#ah10)"/><path class="e" d="M315,48.5 L451.2,116.6" marker-end="url(#ah10)"/><path class="e" d="M317,126 L449,126" marker-end="url(#ah10)"/><path class="e" d="M315,203.5 L451.2,135.4" marker-end="url(#ah10)"/><circle class="n" cx="40" cy="126" r="18"/><text class="t" x="40" y="126" dy=".35em" text-anchor="middle">Att</text><circle class="n" cx="169" cy="126" r="18"/><text class="t" x="169" y="126" dy=".35em" text-anchor="middle">CC</text><circle class="n" cx="298" cy="40" r="18"/><text class="t" x="298" y="40" dy=".35em" text-anchor="middle">B1</text><circle class="n" cx="298" cy="126" r="18"/><text class="t" x="298" y="126" dy=".35em" text-anchor="middle">B2</text><circle class="n" cx="298" cy="212" r="18"/><text class="t" x="298" y="212" dy=".35em" text-anchor="middle">B3</text><circle class="n" cx="470" cy="126" r="18"/><text class="t" x="470" y="126" dy=".35em" text-anchor="middle">Vic</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">DDoS: attacker, command server (CC), bots (B1-B3), victim server</figcaption></figure>
Answer frame. Open with both definitions; draw the botnet diagram; develop the techniques (SYN, ICMP, UDP), then steps and impact; close with mitigation. For the combined Dec 2025 question give two lines each to DoS/DDoS, buffer overflow and phishing.
<mark>DoS makes a service unavailable to legitimate users by overloading it from one source, and DDoS does it using a botnet of many machines.</mark>
Asked: [7 marks] (Dec 2020, Jun 2020, Jun 2025) How DOS and DDOS attack can be performed? Define DoS and DDoS attacks in brief. What are the techniques behind such attacks? Asked: [7 marks] (Dec 2025) Discuss Dos and DDoS attacks, buffer overflow and phishing techniques.
Buffer Overflow
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. A buffer overflow occurs when a program writes more data into a fixed-size buffer than it can hold, overwriting adjacent memory such as the saved return address.
Key points.
- In the stack, local buffers sit below the saved return address, so an overlong input overwrites it.
- The attacker's input contains shellcode (malicious machine code) and a new return address pointing to it, so when the function returns, the shellcode runs with the program's privileges.
- Unsafe functions such as
strcpy,getsandsprintfdo no length checking. - Countermeasures: bounds checking with
strncpyandfgets, stack canaries, non-executable stack (DEP), ASLR and safer languages.
void f(char *s) {
char buf[8];
strcpy(buf, s); // input longer than 8 bytes overwrites saved return address
}
| Stack (low to high) | Content |
|---|---|
| buf[8] | attacker's shellcode and padding |
| saved frame pointer | overwritten |
| return address | overwritten with address of shellcode |
Answer frame. Open with the definition; draw the stack table; show the example; close with countermeasures.
<mark>A buffer overflow lets an attacker overwrite the return address with the address of injected shellcode and so run code of his choice.</mark>
Asked: [7 marks] (Nov 2022) How can attacker inject the malicious code in a specific address and execute it as per requirement using buffer overflow attack? Explain with suitable example.
Attack on Wireless Networks
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. Wireless attacks exploit the open radio medium and weak security of WLANs such as Wi-Fi to intercept traffic or gain access.
Key points.
- Sniffing captures unencrypted packets with tools such as Wireshark and Kismet, and war driving finds open networks.
- A rogue or evil-twin access point imitates a genuine one so victims connect and their data is captured.
- Deauthentication attacks force clients off the network so their handshake can be captured.
- WEP and weak WPA passphrases are cracked with aircrack-ng; weak encryption is the main vulnerability.
- Countermeasures: WPA2/WPA3 with long passphrases, disabling WPS, MAC filtering, and rogue AP detection.
Asked: [7 marks] (Dec 2020) How attack on Wireless network perform?
Phishing: Method of Phishing
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">High weight</span>
Definition. Phishing is a fraudulent attempt to obtain sensitive information such as usernames, passwords and card details by pretending to be a trustworthy entity in electronic communication.
Key points.
- The attacker sends a mass email, SMS or message that appears to come from a bank, company or government and creates urgency.
- The message links to a fake website that copies the real one, and the victim enters credentials which go to the attacker.
- Other methods: malicious attachments, fake login pop-ups, and phone calls (vishing).
- Pharming redirects users to a fake site even when they type the correct address, by poisoning DNS or changing the hosts file.
- Impact on web transactions: stolen internet-banking and e-commerce credentials, unauthorised transfers, card fraud, identity theft and loss of customer trust.
- Detection signs: mismatched URLs, spelling errors, generic greeting, urgent threats and no HTTPS padlock.
- Prevention: do not click unknown links, type the URL yourself, use anti-phishing filters, two-factor authentication, keep DNS and browsers updated and report phishing.
Answer frame. Open with the definition; draw sender -> fake mail -> fake site -> attacker if space allows; develop working, types, pharming and impact; close with detection and prevention. For phishing vs pharming, define both and state that pharming needs no bait.
<mark>Phishing is the criminal act of tricking people into revealing confidential information by impersonating a trusted source through fake emails and websites.</mark>
Asked: [7 marks] (Nov 2019, Jun 2020, Dec 2024) Explain the term phishing in detail; write various methods or activities which constitute phishing. Asked: [7 marks] (Nov 2022) Analyse how phishing and pharming assaults have affected various web-based transactions.
Phishing Techniques
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Medium weight</span>
Definition. Phishing techniques are the different forms in which the phishing fraud is carried out, depending on target and channel.
Key points.
- Email phishing is the bulk, untargeted mail to many users, such as a fake bank alert.
- Spear phishing is a personalised attack on a specific person or organisation using known details, such as a mail appearing to come from the victim's manager.
- Whaling targets senior executives such as the CEO or CFO with high-value requests like an urgent fund transfer.
- Vishing is phishing by voice call, for example a caller posing as the bank asking for an OTP.
- Smishing is phishing by SMS with a malicious link, such as a fake courier or KYC message.
- Clone phishing copies a genuine earlier email and resends it with a malicious link or attachment.
- Pharming redirects traffic to a fake site through DNS poisoning; evil twin uses a fake Wi-Fi hotspot.
Answer frame. Open with the definition; give a table-like list of techniques with one-line example each; close with prevention (awareness, filters, 2FA).
<mark>Spear phishing targets specific individuals, whaling targets executives, vishing uses voice calls, smishing uses SMS and clone phishing resends a real email with a malicious link.</mark>
Asked: [7 marks] (Dec 2020, Jun 2025) Explain the different types of phishing techniques.
Last-minute revision
- Proxy hides the user's IP behind its own; anonymizer removes identifying data.
- Password cracking methods: dictionary, brute force, hybrid, rainbow table; tools John the Ripper, Hashcat.
- Keylogger types: hardware and software; spyware secretly collects user data.
- Virus needs host and user action; worm is standalone and spreads by network.
- Virus life cycle: dormant, propagation, triggering, execution.
- Trojan does not replicate and is disguised; ransomware encrypts files for ransom.
- Backdoor is a hidden bypass of authentication.
- DoS is single-source flooding, DDoS uses a botnet; SYN, ICMP and UDP floods.
- Buffer overflow overwrites the return address with shellcode; use strncpy, canary, DEP, ASLR.
- Wireless attacks: sniffing, rogue AP, deauthentication, WEP/WPA cracking.
- Phishing types: spear, whaling, vishing, smishing, clone, pharming.
Memory hooks
- Virus = Vehicle needed (host); Worm = Walks alone.
- Life cycle: "Dogs Prowl To Eat" (Dormant, Propagation, Triggering, Execution).
- Phishing family: Spear = one person, Whale = boss, Vish = Voice, Smish = SMS.
- Trojan = gift-wrapped harm; Backdoor = hidden key.
- DDoS = many bots, one victim.
Coverage checklist
- Proxy Servers and Anonymizers: Nov 2023 proxy role in phishing; Dec 2025 tools in cybercrime.
- Password Cracking: Dec 2024 short notes.
- Key loggers and Spyware: Jun 2025 short notes; spyware in Q4.
- virus and worms: Jun 2020/Dec 2024 definitions and types; Nov 2022/Jun 2025 more threatening; Nov 2019 spread; Dec 2020 life cycle; worm and logic bomb in Q4.
- Trojan Horses: Dec 2020 effects; Nov 2023 vs backdoors; Dec 2024 email abuse, Trojans, ransomware.
- Backdoors: Nov 2019/Dec 2020 short notes with firewalls.
- DoS and DDoS Attacks: Dec 2020/Jun 2020/Jun 2025 how performed; Dec 2025 combined.
- Buffer and Overflow: Nov 2022 injection example.
- Attack on Wireless Networks: Dec 2020.
- Phishing : Method of Phishing: Nov 2019/Jun 2020/Dec 2024 explain; Nov 2022 phishing and pharming.
- Phishing Techniques: Dec 2020/Jun 2025 types.