1
00:00:06,540 --> 00:00:09,480
- So welcome to lesson
seven, deep dive quiz.

2
00:00:09,480 --> 00:00:12,360
In lesson seven, we focused
on explaining various types

3
00:00:12,360 --> 00:00:14,880
of vulnerabilities and
we had two sub lessons

4
00:00:14,880 --> 00:00:17,280
seven dot one and seven dot two.

5
00:00:17,280 --> 00:00:19,350
In seven one we did a vulnerability primer

6
00:00:19,350 --> 00:00:22,140
and in seven two, we focused on network

7
00:00:22,140 --> 00:00:25,260
and operating system and
cloud vulnerabilities.

8
00:00:25,260 --> 00:00:27,000
So, let's do a quiz together.

9
00:00:27,000 --> 00:00:27,833
You ready?

10
00:00:27,833 --> 00:00:30,870
Make sure you have a pen or a
pencil and a piece of paper.

11
00:00:30,870 --> 00:00:33,180
Put me on pause as often as you need to,

12
00:00:33,180 --> 00:00:34,620
so that you can answer the questions.

13
00:00:34,620 --> 00:00:37,320
Don't just listen to me, I want
you to answer the questions

14
00:00:37,320 --> 00:00:40,083
and then together we'll
go through an explanation.

15
00:00:42,270 --> 00:00:43,383
So let's start.

16
00:00:44,280 --> 00:00:45,300
Question one.

17
00:00:45,300 --> 00:00:49,080
Which of the following best
describes a zero day threat?

18
00:00:49,080 --> 00:00:51,870
Now, best describes is our key words here.

19
00:00:51,870 --> 00:00:54,240
There's no time between when
a vulnerability is known

20
00:00:54,240 --> 00:00:57,630
to developers and when is
exploited by adversaries.

21
00:00:57,630 --> 00:01:00,060
A vulnerability that has
been publicly announced,

22
00:01:00,060 --> 00:01:01,530
a threat that's in the wild,

23
00:01:01,530 --> 00:01:04,290
and has the potential to
cause significant harm,

24
00:01:04,290 --> 00:01:07,470
or denotes the day a
threat was identified.

25
00:01:07,470 --> 00:01:09,090
Hmm, this is a tough one,

26
00:01:09,090 --> 00:01:10,230
'cause it looks like maybe there's

27
00:01:10,230 --> 00:01:12,930
a couple of reasonable answers.

28
00:01:12,930 --> 00:01:15,420
But really what we're
trying to focus on here is,

29
00:01:15,420 --> 00:01:18,120
if you were explaining
what a zero day threat was

30
00:01:18,120 --> 00:01:19,350
to somebody else,

31
00:01:19,350 --> 00:01:21,900
which one of these explanations
would help them the most?

32
00:01:21,900 --> 00:01:23,340
Which one would they understand?

33
00:01:23,340 --> 00:01:26,340
And that's what we mean by best describes.

34
00:01:26,340 --> 00:01:28,200
So no time between a
vulnerability is known

35
00:01:28,200 --> 00:01:31,140
to developers and when it's
exploited by adversaries,

36
00:01:31,140 --> 00:01:33,210
a vulnerability that's publicly announced,

37
00:01:33,210 --> 00:01:34,590
a threat that's in the wild

38
00:01:34,590 --> 00:01:37,020
and has the potential to
cause significant harm,

39
00:01:37,020 --> 00:01:39,540
or denotes a day a threat was identified.

40
00:01:39,540 --> 00:01:40,840
What are you gonna choose?

41
00:01:41,700 --> 00:01:43,230
I'm gonna choose the first one.

42
00:01:43,230 --> 00:01:45,420
Because I think that
one best describes that

43
00:01:45,420 --> 00:01:47,700
there's no time between when
the vulnerability is known

44
00:01:47,700 --> 00:01:51,180
to developers and when it's
exploited by adversaries.

45
00:01:51,180 --> 00:01:53,700
The second one, a vulnerability
that's publicly announced,

46
00:01:53,700 --> 00:01:55,860
it may or may not be publicly announced.

47
00:01:55,860 --> 00:01:57,270
The third, a threat that's

48
00:01:57,270 --> 00:01:59,670
in the wild and has a
potential to cause harm.

49
00:01:59,670 --> 00:02:02,880
Absolutely it does, except
that that's not really

50
00:02:02,880 --> 00:02:05,490
what's specific to being a zero day.

51
00:02:05,490 --> 00:02:08,250
And denotes a day a threat was identified.

52
00:02:08,250 --> 00:02:11,100
Not a bad explanation, but
doesn't best describe it.

53
00:02:11,100 --> 00:02:12,540
So I'm gonna go with the first one.

54
00:02:12,540 --> 00:02:13,373
Do you like it?

55
00:02:14,550 --> 00:02:15,383
All right.

56
00:02:15,383 --> 00:02:16,216
And it is correct.

57
00:02:16,216 --> 00:02:17,610
Let's move on to question two.

58
00:02:18,480 --> 00:02:21,510
This type of disclosure
balances the need to know

59
00:02:21,510 --> 00:02:23,580
with harm that may be caused.

60
00:02:23,580 --> 00:02:27,210
Is this ethical disclosure,
responsible disclosure,

61
00:02:27,210 --> 00:02:30,663
limited disclosure, or full disclosure?

62
00:02:31,560 --> 00:02:35,640
Ethical, responsible, limited, or full?

63
00:02:35,640 --> 00:02:36,690
What do you think?

64
00:02:36,690 --> 00:02:38,963
You can put me in pause if
you wanna think about it.

65
00:02:40,080 --> 00:02:43,140
Well, I'm gonna choose,
responsible disclosure.

66
00:02:43,140 --> 00:02:45,360
Ethical disclosure is just the process

67
00:02:45,360 --> 00:02:47,463
of actually doing a disclosure.

68
00:02:48,360 --> 00:02:51,120
Limited disclosure,
that was a made up term.

69
00:02:51,120 --> 00:02:53,970
And full disclosure is when
everything is disclosed

70
00:02:53,970 --> 00:02:57,660
without any thinking about what
the ramifications might be,

71
00:02:57,660 --> 00:02:58,563
right, what our adversaries might be able

72
00:02:58,563 --> 00:03:00,390
able to do with that information.

73
00:03:00,390 --> 00:03:03,270
So I'm gonna go with
responsible disclosure.

74
00:03:03,270 --> 00:03:04,143
Let's check.

75
00:03:05,040 --> 00:03:06,183
And that is correct.

76
00:03:07,950 --> 00:03:10,800
Question three, a timing
and communication flaw

77
00:03:10,800 --> 00:03:13,830
that produces an unexpected
result when the timing

78
00:03:13,830 --> 00:03:16,380
of actions impacts other actions,

79
00:03:16,380 --> 00:03:20,700
Race condition, time of
evaluation, time of check,

80
00:03:20,700 --> 00:03:22,173
or time of use.

81
00:03:23,520 --> 00:03:25,380
So it's a timing and communication flaw

82
00:03:25,380 --> 00:03:28,290
that produces an unexpected result.

83
00:03:28,290 --> 00:03:31,380
Race condition, time of
evaluation, time of check

84
00:03:31,380 --> 00:03:32,940
and time of use.

85
00:03:32,940 --> 00:03:34,190
What do you wanna choose?

86
00:03:35,130 --> 00:03:36,570
I'm gonna choose race condition

87
00:03:36,570 --> 00:03:39,780
because that best describes
what a race condition is.

88
00:03:39,780 --> 00:03:41,970
Time of valuation, time of check, and time

89
00:03:41,970 --> 00:03:45,570
of use are all components
of a race condition.

90
00:03:45,570 --> 00:03:46,860
But taken together, we're really,

91
00:03:46,860 --> 00:03:47,850
what we're looking at when we talk

92
00:03:47,850 --> 00:03:49,740
about a timing and communication flaw,

93
00:03:49,740 --> 00:03:51,840
we're talking about a race condition.

94
00:03:51,840 --> 00:03:52,953
Let's double check,

95
00:03:53,970 --> 00:03:55,143
and that is correct.

96
00:03:56,850 --> 00:03:59,130
Okay, we are now gonna
match the vulnerability

97
00:03:59,130 --> 00:04:00,873
and the type of attack.

98
00:04:02,010 --> 00:04:03,540
Going down, let's see if we can

99
00:04:03,540 --> 00:04:04,710
make it so you can see all of it.

100
00:04:04,710 --> 00:04:05,550
There you go.

101
00:04:05,550 --> 00:04:06,930
Going down the left hand side

102
00:04:06,930 --> 00:04:11,190
we have side channel,
multi-tenancy, side loading,

103
00:04:11,190 --> 00:04:13,443
injection, and jail breaking.

104
00:04:14,430 --> 00:04:16,800
And then on the right hand side
we've got some descriptions.

105
00:04:16,800 --> 00:04:20,670
A shared infrastructure,
bypassing security restrictions,

106
00:04:20,670 --> 00:04:23,730
a physical property weakness
that can be exploited,

107
00:04:23,730 --> 00:04:26,040
installing a non-official app,

108
00:04:26,040 --> 00:04:29,073
or insertion of code or commands.

109
00:04:30,480 --> 00:04:32,520
So let's start up here with side channel.

110
00:04:32,520 --> 00:04:34,620
Hmm, as we go through our list,

111
00:04:34,620 --> 00:04:36,220
remember what a side channel is?

112
00:04:37,260 --> 00:04:38,370
it's also a great time to put me

113
00:04:38,370 --> 00:04:41,133
on pause if you wanna like,
take time to match this up.

114
00:04:42,270 --> 00:04:43,890
Well, I'm gonna go,

115
00:04:43,890 --> 00:04:46,590
with physical property
weakness that can be exploited.

116
00:04:47,700 --> 00:04:50,070
Multi-tenancy, now we
talked about multi-tenancy

117
00:04:50,070 --> 00:04:53,460
in the cloud, means when
there are multiple tenants,

118
00:04:53,460 --> 00:04:56,040
which sounds a lot like,

119
00:04:56,040 --> 00:04:57,813
a shared infrastructure.

120
00:04:59,040 --> 00:05:01,380
All right, now we have side loading.

121
00:05:01,380 --> 00:05:02,850
And our options are,

122
00:05:02,850 --> 00:05:05,040
bypassing security restrictions,

123
00:05:05,040 --> 00:05:07,680
installing a nonofficial app,

124
00:05:07,680 --> 00:05:10,110
or insertion of code and commands.

125
00:05:10,110 --> 00:05:12,450
Now let's say you get to this
point, you're like, oh man

126
00:05:12,450 --> 00:05:14,130
I'm not really sure what that one is.

127
00:05:14,130 --> 00:05:17,760
Well, go ahead to the next one,
and then you can come back.

128
00:05:17,760 --> 00:05:18,990
So never, you know,

129
00:05:18,990 --> 00:05:21,720
never hesitate to use a
process of elimination,

130
00:05:21,720 --> 00:05:24,753
or, kind of answer one part of
the question before another.

131
00:05:25,740 --> 00:05:27,720
So I'm gonna skip that one for now.

132
00:05:27,720 --> 00:05:28,620
Go to injection.

133
00:05:28,620 --> 00:05:32,880
And we know that injection is
insertion of code or commands.

134
00:05:32,880 --> 00:05:34,890
And we know that jailbreaking,

135
00:05:34,890 --> 00:05:37,440
is bypassing security restrictions.

136
00:05:37,440 --> 00:05:38,520
So side loading,

137
00:05:38,520 --> 00:05:42,060
well that must have been
installing a non-official app.

138
00:05:42,060 --> 00:05:43,283
So let's go through these.

139
00:05:43,283 --> 00:05:46,020
A side channel is a
physical property weakness

140
00:05:46,020 --> 00:05:47,370
that can be exploited.

141
00:05:47,370 --> 00:05:50,400
Multi-tenancy, refers to
shared infrastructure.

142
00:05:50,400 --> 00:05:53,820
Side loading ,is installing
a nonofficial app.

143
00:05:53,820 --> 00:05:56,490
Injection, insertion of code of commands,

144
00:05:56,490 --> 00:05:59,580
and jailbreaking, bypassing
security restrictions.

145
00:05:59,580 --> 00:06:00,750
Do you like it?

146
00:06:00,750 --> 00:06:01,713
Let's check it out.

147
00:06:02,760 --> 00:06:03,993
And those are correct.

148
00:06:08,040 --> 00:06:10,290
And let's go to our last question.

149
00:06:10,290 --> 00:06:12,540
And this is asking us to determine

150
00:06:12,540 --> 00:06:15,450
if the flaw description is true or false.

151
00:06:15,450 --> 00:06:16,830
So we're gonna choose true or false

152
00:06:16,830 --> 00:06:19,080
for each one of these statements.

153
00:06:19,080 --> 00:06:20,910
The first statement, I'll read them all

154
00:06:20,910 --> 00:06:22,590
to you actually before we decide.

155
00:06:22,590 --> 00:06:23,520
The first statement is,

156
00:06:23,520 --> 00:06:26,070
a buffer overflow happens
when excess data is written

157
00:06:26,070 --> 00:06:28,233
into non allocated system memory.

158
00:06:29,100 --> 00:06:30,360
The second statement,

159
00:06:30,360 --> 00:06:32,490
is a memory leak is a failure of an OS

160
00:06:32,490 --> 00:06:36,090
or application to free up
dynamically request memory.

161
00:06:36,090 --> 00:06:37,110
Number three,

162
00:06:37,110 --> 00:06:39,960
directory traversal is the
ability to access files

163
00:06:39,960 --> 00:06:44,070
and directories inside of
the intended directory.

164
00:06:44,070 --> 00:06:45,450
And number four is,

165
00:06:45,450 --> 00:06:47,490
maintenance hooks are designed to be used

166
00:06:47,490 --> 00:06:49,530
by programmers in the prod,

167
00:06:49,530 --> 00:06:51,303
or in the production environment.

168
00:06:52,410 --> 00:06:54,390
All right, so let's start at the top.

169
00:06:54,390 --> 00:06:56,730
Buffer overflow happens
when excessive data

170
00:06:56,730 --> 00:06:59,850
is written into non
allocated system memory.

171
00:06:59,850 --> 00:07:02,013
Do you think that's true or false?

172
00:07:03,540 --> 00:07:04,623
I think that's true.

173
00:07:06,210 --> 00:07:08,490
Number two, a memory leak is the failure

174
00:07:08,490 --> 00:07:10,740
of an operating system or an application

175
00:07:10,740 --> 00:07:13,590
to free up dynamically requested memory.

176
00:07:13,590 --> 00:07:15,813
Do you think that's true or false?

177
00:07:17,220 --> 00:07:18,243
I think that's true.

178
00:07:19,860 --> 00:07:21,660
Number three,

179
00:07:21,660 --> 00:07:24,240
directory traversal is the
ability to access files

180
00:07:24,240 --> 00:07:28,050
and directories inside of
the intended directory.

181
00:07:28,050 --> 00:07:31,140
Hmm, is that gonna be true or false?

182
00:07:31,140 --> 00:07:33,120
Well, if you just read this quickly

183
00:07:33,120 --> 00:07:35,160
and said the ability to
access files and directories,

184
00:07:35,160 --> 00:07:37,620
you'd be like, yeah, yeah,
that's directory traversal.

185
00:07:37,620 --> 00:07:39,211
But there's a tricky word in here.

186
00:07:39,211 --> 00:07:42,330
Inside of the intended directory.

187
00:07:42,330 --> 00:07:44,490
Remember, directory traversal
is really the ability

188
00:07:44,490 --> 00:07:46,260
to access files and directories,

189
00:07:46,260 --> 00:07:48,840
outside of the intended directory.

190
00:07:48,840 --> 00:07:50,820
And so, you know, it feels
like you're kinda on a roll.

191
00:07:50,820 --> 00:07:52,290
The first one was true,
the second one was true.

192
00:07:52,290 --> 00:07:53,700
Oh, the third one might be true.

193
00:07:53,700 --> 00:07:55,590
But you really always wanna be looking out

194
00:07:55,590 --> 00:07:56,790
for those keywords.

195
00:07:56,790 --> 00:07:58,323
So we're gonna say false.

196
00:07:59,370 --> 00:08:01,890
And lastly, maintenance
hooks are designed to be used

197
00:08:01,890 --> 00:08:05,130
by programmers in the prod,
or production environment.

198
00:08:05,130 --> 00:08:06,720
True or false?

199
00:08:06,720 --> 00:08:09,780
Those maintenance hooks are
really designed to be used when?

200
00:08:09,780 --> 00:08:13,470
Not in prod, but in the
development environment.

201
00:08:13,470 --> 00:08:14,610
So we're gonna say false.

202
00:08:14,610 --> 00:08:17,760
So we have two true statements
and two false statements.

203
00:08:17,760 --> 00:08:18,870
You agree?

204
00:08:18,870 --> 00:08:19,953
Let's check it out.

205
00:08:21,450 --> 00:08:23,400
And those are correct.

206
00:08:23,400 --> 00:08:24,660
All right, that was great.

207
00:08:24,660 --> 00:08:25,500
Five questions.

208
00:08:25,500 --> 00:08:27,030
I bet you did really well on all of them.

209
00:08:27,030 --> 00:08:28,470
So congratulations.

210
00:08:28,470 --> 00:08:31,050
Up next, we're gonna go
right into lesson eight,

211
00:08:31,050 --> 00:08:35,340
given a scenario, analyze
indicators of malicious activity.

212
00:08:35,340 --> 00:08:36,290
I'll see you there.
