Compléter
0478: SECTION 5: INTERNET AND ITS USES 5.3Version en ligne
5.3 Cyber Security
1
password
combinations
symbols
force
Brute
Force
Attack
:
If
a
hacker
wants
to
?
crack
?
your
password
,
they
can
systematically
try
all
the
different
of
letters
,
numbers
and
other
until
eventually
they
find
your
.
This
is
known
as
a
brute
attack
and
there
isn
?
t
a
lot
of
sophistication
in
the
technique
.
2
attempts
faster
common
generate
abc123
reduce
hacker
error
list
One
way
to
the
number
of
needed
to
crack
a
password
is
to
first
go
through
a
series
of
logical
steps
:
1
Check
if
the
password
is
one
of
the
most
ones
used
(
the
five
most
common
are
:
123456
,
password
,
qwerty
,
111111
and
)
;
since
these
simple
passwords
are
seen
so
many
times
it
?
s
a
good
place
for
the
to
start
.
2
If
it
isn
?
t
in
the
common
password
list
,
the
next
thing
to
do
is
to
start
with
a
strong
word
(
this
is
a
text
file
containing
a
collection
of
words
that
can
be
used
in
a
brute
force
attack
)
;
some
programs
will
a
word
list
containing
a
million
words
.
Nonetheless
this
is
still
a
way
of
cracking
a
password
than
just
total
trial
and
.
3
stealing
communication
wired
packet
information
network
Data
Interception
:
Data
interception
is
a
form
of
data
by
tapping
into
a
wired
or
wireless
link
.
The
intent
is
to
compromise
privacy
or
to
obtain
confidential
.
Interception
can
be
carried
out
using
a
sniffer
,
which
examines
data
packets
being
sent
over
a
.
The
intercepted
data
is
sent
back
to
the
hacker
.
This
is
a
common
method
when
networks
are
used
.
4
signal
software
personal
interception
Wi
-
Fi
(
wireless
)
data
can
be
carried
out
using
wardriving
(
or
sometimes
called
Access
Point
Mapping
)
.
Using
this
method
,
data
can
be
intercepted
using
a
laptop
or
smartphone
,
antenna
and
a
GPS
device
(
together
with
some
)
outside
a
building
or
somebody
?
s
house
.
The
intercepted
Wi
-
Fi
can
then
reveal
data
to
the
hacker
,
often
without
the
user
being
aware
this
is
happening
.
5
firewall
privacy
passwords
encryption
interception
protocol
To
safeguard
against
wardriving
,
the
use
of
a
wired
equivalency
(
WEP
)
encryption
,
together
with
a
,
is
recommended
.
It
is
also
a
good
idea
to
protect
the
use
of
the
wireless
router
by
having
complex
.
It
is
important
not
to
use
Wi
-
Fi
(
wireless
)
connectivity
in
public
places
(
such
as
an
airport
)
since
no
data
will
exist
and
your
data
is
then
open
to
by
anyone
within
the
airport
.
6
users
network
temporary
server
target
A
denial
of
service
(
DoS
)
attack
is
an
attempt
at
preventing
from
accessing
part
of
a
,
notably
an
internet
.
This
is
usually
but
may
be
a
very
damaging
act
or
a
large
breach
of
security
.
It
doesn
?
t
just
affect
networks
;
an
individual
can
also
be
a
for
such
an
attack
.
7
prevent
accessing
services
emails
DDOs
Attacks
:
The
attacker
may
be
able
to
a
user
from
:
»
accessing
their
»
websites
/
web
pages
»
accessing
online
(
such
as
banking
)
.
8
computers
email
server
clogged
browser
receive
spam
legitimate
One
method
of
attack
is
to
flood
the
network
with
useless
traffic
.
How
does
this
cause
a
problem
?
When
a
user
enters
a
website
?
s
URL
in
their
,
a
request
is
sent
to
the
web
that
contains
the
website
or
web
page
.
Obviously
,
the
server
can
only
handle
a
finite
number
of
requests
.
So
if
it
becomes
overloaded
by
an
attacker
sending
out
thousands
of
requests
,
it
won
?
t
be
able
to
service
a
user
?
s
request
.
This
is
effectively
a
denial
of
service
.
In
a
distributed
denial
of
service
(
DDoS
)
the
spam
traffic
originates
from
many
different
,
which
makes
it
hard
to
block
the
attack
.
This
can
happen
to
a
user
?
s
account
,
for
example
,
by
an
attacker
sending
out
many
spam
messages
to
their
email
account
.
Internet
service
providers
(
ISPs
)
only
allow
a
specific
data
quota
for
each
user
.
Consequently
,
if
the
attacker
sends
out
thousands
of
emails
to
the
user
?
s
account
,
it
will
quickly
become
up
and
the
user
won
?
t
be
able
to
legitimate
emails
.
9
firewall
date
server
slow
access
attacks
spam
email
An
individual
user
or
a
website
can
guard
against
these
to
some
degree
by
:
»
using
an
up
-
to
-
malware
checker
»
setting
up
a
to
restrict
traffic
to
and
from
the
web
or
user
?
s
computer
»
applying
email
filters
to
filter
out
unwanted
traffic
(
for
example
,
)
.
There
are
certain
signs
a
user
can
look
out
for
to
see
if
they
have
become
a
victim
of
a
DDoS
attack
:
»
network
performance
(
opening
files
or
accessing
certain
websites
)
»
inability
to
certain
websites
»
large
amounts
of
spam
email
reaching
the
user
?
s
account
.
10
passwords
firewalls
corrupted
illegal
access
permission
authorise
personal
theft
user
Hacking
is
generally
the
act
of
gaining
illegal
to
a
computer
system
without
the
user
?
s
.
This
can
lead
to
identity
or
the
gaining
of
information
;
data
can
be
deleted
,
passed
on
,
changed
or
.
As
mentioned
earlier
,
encryption
does
not
stop
hacking
;
it
makes
the
data
meaningless
to
the
hacker
but
it
doesn
?
t
stop
them
from
deleting
,
corrupting
or
passing
on
the
data
.
Hacking
can
be
prevented
through
the
use
of
,
user
names
and
frequently
changed
strong
.
Anti
-
hacking
software
and
intrusion
-
detection
software
also
exists
in
the
fight
against
hacking
.
Malicious
hacking
,
as
described
above
,
takes
place
without
the
?
s
permission
,
and
is
always
an
act
.
However
,
universities
and
companies
now
run
courses
in
ethical
hacking
.
This
occurs
when
companies
paid
hackers
to
check
out
their
security
measure
s
11
downloaded
install
attachments
trigger
up
malfunction
corrupting
run
replicate
Viruses
are
programs
or
program
code
that
(
copies
themselves
)
with
the
intention
of
deleting
or
files
,
or
causing
a
computer
to
(
for
example
,
by
deleting
.
exe
files
,
filling
up
the
hard
drive
with
?
useless
?
data
,
and
so
on
)
.
Viruses
need
an
active
host
program
on
the
target
computer
or
an
operating
system
that
has
already
been
infected
,
before
they
can
actually
and
cause
harm
(
that
is
,
they
need
to
be
executed
by
some
before
starting
to
cause
any
damage
)
.
Viruses
are
often
sent
as
email
,
reside
on
infected
websites
or
on
infected
software
to
the
user
?
s
computer
.
Apart
from
all
the
usual
safety
actions
(
for
example
,
don
?
t
open
emails
from
unknown
sources
,
don
?
t
non
-
original
software
)
,
always
run
an
-
to
-
date
virus
scanner
12
dangerous
security
network
corrupt
attachments
opened
user
self
Worms
are
a
type
of
stand
-
alone
malware
that
can
-
replicate
.
Their
intention
is
to
spread
to
other
computers
and
whole
networks
;
unlike
viruses
,
they
don
?
t
need
an
active
host
program
to
be
in
order
to
do
any
damage
.
They
remain
inside
applications
which
allows
them
to
move
throughout
networks
.
In
fact
,
worms
replicate
without
targeting
and
infecting
specific
files
on
a
computer
;
they
rely
on
failures
within
networks
to
permit
them
to
spread
unhindered
.
Worms
frequently
arrive
as
message
and
only
one
user
opening
a
worm
-
infested
email
could
end
up
infecting
the
whole
network
.
As
with
viruses
,
the
same
safeguards
should
be
employed
,
together
with
the
running
of
an
up
-
to
-
date
anti
-
virus
program
.
Worms
tend
to
be
problematic
because
of
their
ability
to
spread
throughout
a
without
any
action
from
an
end
-
;
whereas
viruses
require
each
end
-
user
to
somehow
initiate
the
virus
.
All
of
this
makes
them
more
than
viruses
.
13
fake
logging
executed
trial
harm
useless
downloaded
software
personal
A
Trojan
horse
is
a
program
which
is
often
disguised
as
legitimate
but
with
malicious
instructions
embedded
within
it
.
A
Trojan
horse
replaces
all
or
part
of
the
legitimate
software
with
the
intent
of
carrying
out
some
to
the
user
?
s
computer
system
.
They
need
to
be
by
the
end
-
user
and
therefore
usually
arrive
as
an
email
attachment
or
are
from
an
infected
website
.
For
example
,
they
could
be
transmitted
via
a
fake
anti
-
virus
program
that
pops
up
on
the
user
?
s
screen
claiming
their
computer
is
infected
and
action
needs
to
be
taken
.
The
user
will
be
invited
to
run
anti
-
virus
as
part
of
a
free
.
Once
the
user
does
this
,
the
damage
is
done
.
Once
installed
on
the
user
?
s
computer
,
the
Trojan
horse
will
give
cyber
criminals
access
to
information
on
your
computers
,
such
as
IP
addresses
,
passwords
and
other
personal
data
.
Spyware
(
including
key
software
)
and
ransomware
are
often
installed
on
a
user
?
s
computer
via
Trojan
horse
malware
.
Because
they
rely
on
tricking
end
-
users
,
firewalls
and
other
security
systems
are
often
since
the
user
can
overrule
them
and
initiate
the
running
of
the
malware
.
14
harmful
remove
security
advertising
pop
browser
toolbar
Adware
is
a
type
of
malware
.
At
its
least
dangerous
it
will
attempt
to
flood
an
end
-
user
with
unwanted
.
For
example
,
it
could
redirect
a
user
?
s
to
a
website
that
contains
promotional
advertising
,
it
could
appear
in
the
form
of
-
ups
,
or
it
could
appear
in
the
browser
?
s
and
redirect
search
requests
.
Although
not
necessarily
harmful
,
adware
can
:
»
highlight
weaknesses
in
a
user
?
s
defenses
.
»
be
hard
to
?
it
defeats
most
anti
-
malware
software
since
it
can
be
difficult
to
determine
whether
or
not
it
is
»
hijack
a
browser
and
create
its
own
default
search
requests
.
15
installed
key
locked
restricts
encrypt
demands
hostage
Essentially
,
ransomware
are
programs
that
data
on
a
user
?
s
computer
and
?
hold
the
data
?
.
The
cybercriminal
waits
until
the
ransom
money
is
paid
and
,
sometimes
,
the
decryption
is
then
sent
to
the
user
.
It
has
caused
considerable
damage
to
some
companies
and
individuals
.
Imagine
a
situation
where
you
log
on
to
your
computer
,
only
to
find
the
screen
is
and
you
can
?
t
unlock
it
until
the
of
the
cybercriminal
have
been
met
.
This
malware
access
to
the
computer
and
encrypts
all
the
data
until
a
ransom
is
paid
.
It
can
be
on
a
user
?
s
computer
by
way
of
a
Trojan
horse
or
through
social
engineering
.
16
back
phishing
encrypts
ransom
malware
When
ransomware
is
executed
,
it
either
files
straightaway
or
it
waits
for
a
while
to
determine
how
much
of
a
the
victim
can
afford
.
The
can
be
prevented
by
the
usual
methods
(
for
example
,
by
avoiding
,
emails
)
but
once
it
is
executed
,
it
is
almost
impossible
to
reverse
the
damage
caused
.
The
best
way
to
avoid
a
catastrophe
is
to
ensure
regular
-
ups
of
key
files
are
kept
and
thus
avoid
having
to
pay
a
ransom
.
17
links
fake
opened
initiate
legitimate
email
Phishing
occurs
when
a
cybercriminal
sends
out
-
looking
emails
to
users
.
The
emails
may
contain
or
attachments
that
,
when
initiated
,
take
the
user
to
a
website
;
or
they
may
trick
the
user
into
responding
with
personal
data
(
for
example
,
bank
account
details
or
credit
/
debit
card
details
)
.
The
usually
appears
to
be
genuine
coming
from
a
known
bank
or
service
provider
.
The
key
point
is
that
the
recipient
has
to
some
act
before
the
phishing
scam
can
cause
any
harm
.
If
suspicious
emails
are
deleted
or
not
,
then
phishing
attacks
won
?
t
cause
any
problems
.
18
padlock
links
https
click
scams
email
anti
There
are
numerous
ways
to
help
prevent
phishing
attacks
:
»
users
need
to
be
aware
of
new
phishing
;
those
people
in
industry
or
commerce
should
undergo
frequent
security
awareness
training
to
become
aware
of
how
to
identify
phishing
(
and
pharming
)
scams
»
it
is
important
not
to
on
any
emails
unless
totally
certain
that
it
is
safe
to
do
so
;
fake
emails
can
often
be
identified
by
?
Dear
Customer
.
.
.
.
.
.
?
or
?
Dear
email
person@gmail
.
com
.
.
.
.
.
.
.
.
.
?
and
so
on
»
it
is
important
to
run
-
phishing
toolbars
on
browsers
(
this
includes
tablets
and
mobile
phones
)
since
these
will
alert
the
user
to
malicious
websites
contained
in
an
»
always
look
out
for
or
the
green
symbol
in
the
address
ba
r
19
firewall
security
phishing
hacking
passwords
ups
»
regular
checks
of
online
accounts
are
also
advisable
as
well
as
maintaining
on
a
regular
basis
»
ensure
an
up
-
to
-
date
browser
is
running
on
the
computer
device
(
which
contains
all
of
the
latest
upgrades
)
and
run
a
good
in
the
background
at
all
times
;
a
combination
of
a
desktop
firewall
(
usually
software
)
and
a
network
firewall
(
usually
hardware
)
considerably
reduces
the
risk
of
,
pharming
and
phishing
on
network
computers
»
be
very
wary
of
pop
-
and
use
the
browser
to
block
them
;
if
pop
-
ups
get
through
your
defences
,
don
?
t
click
on
?
cancel
?
since
this
can
ultimately
lead
to
or
pharming
sites
?
the
best
option
is
to
select
the
small
in
the
top
right
-
hand
corner
of
the
pop
-
up
window
which
closes
it
down
.
20
personal
trusted
identity
code
browser
Pharming
is
malicious
installed
on
a
user
?
s
computer
or
on
an
infected
website
.
The
code
redirects
the
user
?
s
to
a
fake
website
without
the
user
?
s
knowledge
.
Unlike
phishing
,
the
user
doesn
?
t
actually
need
to
take
any
action
for
it
to
be
initiated
.
The
creator
of
the
malicious
code
can
gain
data
,
such
as
bank
details
,
from
the
user
.
Often
the
website
appears
to
come
from
a
source
and
can
lead
to
fraud
and
theft
.
|