CISSP Exam Note (Domain 2: Telecommunications and Networking Security) – Classes of Network Abuse
Class A
- Unauthorized access through circumvention of security access controls
- Masquerading, logon abuse (primarily internal attacks)
Class B – non-business use of systems
Class C
- Eavesdropping
- Active: Tampering with a transmission to create a covert signaling channel or probing the network
- Passive – Covertly monitoring or listening to transmissions that is unauthorized
- Covert Channel – using a hidden unauthorized communication
- Tapping – refers to the physical interception of transmission medium (like splicing of cable) Read more
Join Me On Facebook
Entry Categories
- All Other Items (1)
- Biz Mgt & Dev (8)
- Blog-keeping (1)
- Bum-A-Post (3)
- Don's eBook Report (22)
- eBooks, etc… (9)
- eCommerce / eBiz (22)
- Entrepreneurship (21)
- Geek Mail (4)
- Information Security (49)
- Information Systems (46)
- Information Technology (34)
- InfoSec Docs (11)
- Internet Docs (3)
- Internet Marketing (44)
- IT Docs (4)
- Life Happens (22)
- Project Management (28)
- Random Stuff (13)
- The Demondaynizer (4)
- The Internet (75)
- Web Design / Development (34)
- Yeah Boy! Yah Suck! (5)
-
Recent Posts
- What we are up against…
- Why Information Security: D-UH!
- From the Geek Mail: Facebook Pushes the Privacy Envelope with Data Sharing
- From the Geek Mail: 2011 Top Tech Jobs
- Information Security Management in the Wild Wide Web
- Simple Math: Maybe the Difference in your Cert Exam Pass/Fail Chances
- IT from Cost Center to Revenue Generator
Follow Me on Twitter
Business Tech Press Releases- tw telecom Awarded South Carolina Contract to Offer State Government Telecommunication Services February 11, 2012
- Vidable Inc. Launches in Test Market February 10, 2012
- HostWire Merges into WRGL February 10, 2012
- Altera Announces Upcoming Schedule of Events With the Financial Community February 10, 2012
- Faruqi & Faruqi, LLP Announces Investigation of Powerwave Technologies, Inc. February 10, 2012
Archives
Tags
Book Building business CISSP CISSP Exam CISSP reviewer Development Dummies eBusiness Edition Engine Entrepreneurship Exam facebook From Google Guide Hardcover Information Information Security internet Joomla Maceo MAD MAC Management marketing Media Online Optimization Paperback PMP Exam Professional Project Search Secrets Security Social strategies Technology Trehb101 Tweets Twitter with Wordpress Your
Your Shopping Cart
Your cart is emptyCalendar
February 2012 M T W T F S S « Mar 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
From the National Vulnerability Database- CVE-2011-3958 (chrome) February 7, 2012Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document. […]nvd@nist.gov
- CVE-2012-1033 (bind) February 7, 2012The resolver in ISC BIND 9 through 9.8.1-P1 does not properly implement a cache update policy, which allows remote attackers to trigger continued resolvability of domain names that are no longer registered via an unspecified "Ghost Names exploit." […]nvd@nist.gov
- CVE-2011-3971 (chrome) February 7, 2012Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to mousemove events. […]nvd@nist.gov
- CVE-2011-3954 (chrome) February 7, 2012Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) via vectors that trigger a large amount of database usage. […]nvd@nist.gov
- CVE-2011-3970 (chrome, libxslt) February 7, 2012libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. […]nvd@nist.gov
- CVE-2012-0926 (realplayer, realplayer_sp) February 7, 2012The RV10 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle height and width values, which allows remote attackers to execute arbitrary code via a crafted RV10 RealVideo video stream. […]nvd@nist.gov
- CVE-2011-3969 (chrome) February 7, 2012Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout of SVG documents. […]nvd@nist.gov
- CVE-2011-3956 (chrome) February 7, 2012The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension. […]nvd@nist.gov
- CVE-2011-3968 (chrome) February 7, 2012Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving Cascading Style Sheets (CSS) token sequences. […]nvd@nist.gov
- CVE-2012-1035 (ada_web_services) February 7, 2012AdaCore Ada Web Services (AWS) before 2.10.2 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. […]nvd@nist.gov
- CVE-2011-3958 (chrome) February 7, 2012

