Passwords & Logins
Malware
Networks & Protocols
Cryptography
Famous Attacks & Threats
100

What does "MFA" stand for?

Multi-Factor Authentication

100

This malware locks or encrypts your files and demands payment to get them back.

Ransomware

100

This hardware or software filters network traffic coming in and going out based on a set of rules.

Firewall


100

Turning readable data into scrambled, unreadable data is called this.

Encryption

100

A fake email that pretends to come from a trusted source to trick you into clicking a link or giving up information.

Phishing

200

This attack tries every possible password combination until one works.

Brute-force attack

200

Named after a Greek myth, this malware pretends to be legitimate software.

Trojan (Trojan horse)

200

In "HTTPS," what does the "S" stand for?

Secure

200

Named after a Roman leader, this simple cipher shifts each letter by a fixed number of places.

Caesar cipher

200

Flooding a website with traffic from many machines at once to knock it offline.

DDoS (Distributed Denial of Service) attack

300

Attackers take username/password pairs leaked from one site and try them on other sites. What is this called?

Credential stuffing

300

Unlike a virus, this malware copies itself and spreads across networks without any user action.

Worm

300

What is the default port number for SSH?

Port 22

300

This type of encryption uses the same key to encrypt and decrypt.

Symmetric encryption

300

Phishing done through SMS text messages instead of email.

Smishing

400

This random value is added to a password before it's hashed, so identical passwords produce different hashes and rainbow tables stop working.

A salt

400

This stealthy malware hides deep in the operating system, often at kernel level, to conceal itself and other malware.

Rootkit

400

In this attack, someone secretly intercepts, and may alter, the communication between two parties.

Man-in-the-middle (MITM), also called an on-path attack

400

SHA-256 is an example of this one-way function that always produces a fixed-length output.

Hash function

400

This kind of attack uses a software flaw the vendor doesn't know about yet, so no patch exists.

Zero-day attack (zero-day exploit)

500

"Passkeys" are built on this set of standards for passwordless, public-key-based login.

FIDO2 / WebAuthn

500

This malware runs only in memory and uses built-in tools like PowerShell, so it leaves few or no files on disk.

Fileless malware (also called "living off the land")

500

This local-network attack sends fake messages linking the attacker's MAC address to another device's IP address.

ARP spoofing / ARP poisoning

500

Published in 1977 and named after its three inventors, this public-key algorithm relies on how hard it is to factor very large numbers.

RSA (Rivest–Shamir–Adleman)

500

Attackers sneak malicious scripts into a trusted website, and those scripts then run in other visitors' browsers.

Cross-site scripting (XSS)

M
e
n
u