Hands-On Ethical Hacking and Network Defense, Third Edition 3-1
Chapter 03
Network and Computer Attacks
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Quick Quizzes
Hands-On Ethical Hacking and Network Defense, Third Edition 3-2
Lecture Notes
Overview
Chapter three describes different types of malicious software. Malicious software, sometimes
referred to as malware, includes viruses, Trojan horses, and worms. Students will learn about
different types of malware and network attacks and how to protect their resources from them.
Finally, the chapter explains the physical aspect of security and why it is essential for security
and network professionals to pay attention to physical security.
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Describe the different types of malicious software and what damage they can do
Teaching Tips
Malicious Software (Malware)
1. Explain malicious software, sometimes referred as malware. Malware includes:
a. Viruses
b. Worms
c. Trojan programs
Teaching
Tip
Many users call all types of malware viruses. This is a misconception and you
should explain the differences between the various types of malware to your
students.
2. Discuss the main goal of malware which is making money. Point out that malware was
Hands-On Ethical Hacking and Network Defense, Third Edition 3-3
Viruses
1. Explain the following characteristics of a virus:
a. Attaches itself to an executable file
Teaching
Tip
Find more information about viruses and their types at
https://www.webroot.com/us/en/home/resources/articles/pc-security/computer-
security-threats-computer-viruses.
3. Describe ransomware as a type of virus that locks a target system until a ransom is paid.
Point out that it is a growing trend in viruses.
5. Describe mechanisms used to detect and eradicate viruses. You should start by defining
a virus signature. Then, explain how antivirus solutions use virus signatures to identify
Macro Viruses
1. Explain that a macro virus is a virus encoded as a macro in programs that support a
macro language, such as Visual Basic for Applications (VBA).
2. A macro is a list of commands that can be executed. Although macros can be very
3. Do not forget to mention that macros are not a menace when used correctly. The main
problem with macros is that even nonprogrammers can create macros with either good
Worms
1. Explain that a worm, like a virus, replicates and propagates itself but without having to
2. Worms can rapidly replicate to multiple users on the same network or over the Internet.
In theory, worms can infect every computer in the world over a short period of time.
Teaching
Tip
To read an article about the most famous virus and worms of all time, visit:
http://www.eweek.com/c/a/Security/The-Most-Famous-or-Infamous-Viruses-
and-Worms-of-All-Time.
3. Use Table 3-2 to describe common computer worms. You can use your favorite search
Trojan Programs
1. Explain how Trojan programs infect your computer by disguising malicious content
using apparently normal computer programs. Users are tricked to install and use these
2. Describe how you can help your network from being infected by Trojan programs using
hardware firewalls, because many Trojan programs use uncommon ports for
3. Using Table 3-3 illustrate some Trojan program examples and what ports they use for
Spyware
1. Spyware is used by attackers to collect information about their victims. When a spyware
2. Explain that users shouldn’t assume physical security measures, such as locked doors,
Adware
1. Describe the similarities and differences between spyware and adware. Both can be
3. Explain that the biggest problem with adware is that it slows down the computer it’s
running on.
Teaching
Tip
Find best practices for protecting against spyware and adware at
http://www.sophos.com/virusinfo/bestpractice/.
Quick Quiz 1
1. What term is used to describe malicious software, such as a virus, worm, or Trojan
program, introduced to a network to prevent a business from operating?
2. Which of the following is a computer virus encoded as a macro in programs that
support a macro programming language, such as Visual Basic for Applications (VBA)?
A. adware
B. Trojan program
C. phishing
D. macro virus
3. True or False: Antivirus software compares signatures of known viruses against
signatures of every file on a computer; if there’s a match, the program warns you that
the program you’re installing is infected.
4. True or False: A worm is a computer program that replicates and propagates itself by
attaching itself to a host.
5. Which type of malware is considered more of a nuisance because it slows the
performance of the computer down?
a. Trojan program
b. adware
c. macro virus
d. rootkit
Hands-On Ethical Hacking and Network Defense, Third Edition 3-6
Protecting Against Malware Attacks
1. Explain the problems you might face when protecting your network from malware
attacks and what tools you can use to fight back. These tools include:
2. Use Figure 3-3 to illustrate antivirus software detecting a virus.
Educating Your Users
1. Describe what structural training is and how it can help you prevent malware attacks.
2. Explain to your students that because many malware programs can be detected using
antivirus solutions, it is very important that your users update the virus signature file as
4. Explain to your students why using fear tactics to scare users into compliance is not the
right approach. As a security tester, you cannot use fear to generate business. It is not
Intruder Attacks on Networks and Computers
1. Explain the following concepts:
a. Attack
Hands-On Ethical Hacking and Network Defense, Third Edition 3-7
Denial-of-Service Attacks
1. Explain the nature of a Denial-of-Service (DoS) attack to your students. A DoS attack
prevents legitimate users for accessing network resources. Some forms of DoS attacks
2. As a security professional you should not try to perform a DoS attack yourself. Instead,
3. Describe a Ping of Death attack as an attack that causes the victim computer to freeze
Distributed Denial-of-Service Attacks
1. Explain how a DoS attack can be enhanced to perform a distributed attack known as a
2. Mention to your class that loss of bandwidth and degradation of speed are symptoms
3. Discuss how an attacker might use a Dark DDOS attack as a smokescreen to distract
Buffer Overflow Attacks
1. Describe a buffer overflow attack. You might start by defining the concept of buffers.
Every input field on a program is associated with a buffer of a defined capacity. A
3. The best way to protect against this type of attack is to train your programming team to
Hands-On Ethical Hacking and Network Defense, Third Edition 3-8
Eavesdropping
1. Explain that an attacker will use eavesdropping tools (sniffing tools) in order to
2. Mention to students that to defend against the threat of eavesdropping, network
Man-in-the-Middle
1. Explain to students that in a man-in-the-middle attack, attackers inject themselves
Network Session Hijacking
1. Explain to your students that session hijacking enables the attacker to join a TCP
session and make both parties think he or she is the other party.
Security
Tip
To read an article on how to help prevent session hijacking, click:
https://technet.microsoft.com/en-us/magazine/2005.01.sessionhijacking.aspx.
Addressing Physical Security
Keyloggers
1. Describe keyloggers to your students as software or hardware devices that can be used
to capture keystrokes on a computer.
3. Hardware-based keyloggers are devices that are placed between the keyboard and the
actual computer. Random visual tests must be periodically conducted on your premises
Hands-On Ethical Hacking and Network Defense, Third Edition 3-9
Behind Locked Doors
1. You have already mentioned to your students that physical security is important. Good
2. Teach your students to take the time to look for good deadbolt locks or some other
strong door locking mechanism. Some companies implement a security card solution.
Quick Quiz 2
1. What line of defense is used to allow only approved programs to run on a computer?
A. antivirus software
B. malware
C. whitelisting
D. phishing
2. True or False: A denial-ofservice (DoS) attack prevents legitimate users from
accessing a network.
3. What type of attack is an attack on a host from multiple servers or workstations?
A. Trojan horse
B. rootkit
C. man-in-the-middle
D. Distributed Denial-of-Service Attacks
4. In which type of attack would an attacker find a vulnerability in poorly written code that
doesn’t check for a defined amount of memory space use?
A. buffer overflow
B. rootkit
C. Trojan horse
D. man-in-the-middle
5. Devices or computer programs used to capture keystrokes on a computer are known as
which of the following?
a. Keyloggers
b. rotary lock
c. firewall
d. intrusion detection system
Class Discussion Topics
1. Education is a key component of a good network security. Many companies invest good
money on training their employees. Why do these companies still have security issues
caused by their own employees?
2. What type of malware do you think is the most destructive: viruses, worms, Trojan
programs, spyware, or adware?
Additional Projects
1. Ask your students to research online to find more information about some of the
2. Ask your students to find tutorials and tools for picking locks. Remember that some
Additional Resources
1. The Morris Worm:
2. MIT Guide to Lock Picking:
3. Macro virus stuff:
4. Spybot S&D:
5. Ad-aware:
Hands-On Ethical Hacking and Network Defense, Third Edition 3-11
Key Terms
See Glossary for definition of key terms.
adware
attack
backdoor
botnet
exploit
keyloggers
macro virus
malware
network security
Ping of Death attack
ransomware