Hackers and vulnerabilities: Injection attacks, changes in security settings, exposure of sensitive data, breach in authentication protocol

Attackers vulnerabilities exploit करते हैं, एक system में weaknesses, और common ones में injection attacks शामिल हैं जो queries में malicious input डालते हैं, insecure security settings, exposed छोड़ा गया sensitive data, और broken authentication जो attackers को login bypass करने देता है।

11 min read · 7 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

वे Weaknesses जो Attackers Exploit करते हैं

Attackers magic से break in नहीं करते; ये vulnerabilities exploit करते हैं, एक system में weaknesses। Common vulnerabilities जानना ही वह तरीका है जिससे defenders इन्हें बंद करते हैं attackers के इन्हें ढूँढने से पहले।

यह lesson frequent ones cover करता है: injection attacks, insecure security settings, sensitive data की exposure, और broken authentication। आप इनमें से कुछ से पहले ही मिल चुके हैं (databases और PHP में SQL injection; full-stack development में authentication); यहाँ इन्हें security vulnerabilities की तरह framed किया गया है। हर एक एक hole है जो एक attacker ढूँढता है, और हर एक का एक defence है जो इसे बंद करता है।

At a glance

VulnerabilityWeaknessDefence
Injection AttacksMalicious input एक command की तरह execute होता है (जैसे SQL injection)Input validate कीजिए; parameterised queries इस्तेमाल कीजिए
Insecure Security SettingsMisconfiguration, weak defaults, disabled protectionsSecure configuration; settings review कीजिए
Sensitive Data की ExposureData unencrypted या poorly protected है, तो यह leak होता हैData encrypt कीजिए; access restrict कीजिए
Broken AuthenticationWeak login attackers को इसे bypass या hijack करने देता हैStrong authentication; secure sessions

Theory

Injection और Insecure Settings

एक injection attack एक system में malicious input डालता है जो इसे गलती से एक command की तरह treat करता है। Classic है SQL injection: एक form में crafted text type करना तो database attacker का SQL run करे। आपने defence सीखी, parameterised queries और input validation, databases और PHP में; यहाँ इसे एक vulnerability class की तरह नाम दिया गया है।

Insecure security settings (misconfiguration) एक quieter danger है: weak default passwords जो unchanged छोड़े गए, unnecessary services enabled, protections switched off, या permissions बहुत loose। Attackers ऐसी misconfigurations के लिए scan करते हैं क्योंकि ये common और easy to exploit हैं। Defence careful, secure configuration और regular review है, doors को unlocked नहीं छोड़ना।

Theory

Data Exposure और Broken Authentication

Sensitive data की exposure तब होती है जब data properly protected नहीं है, बिना encryption के stored या sent, या ऐसे लोगों के लिए accessible जिन्हें इसे नहीं देखना चाहिए, तो यह leak होता है (एक breach में, या इसे देखने वाले किसी को भी)। Defence sensitive data को encrypt करना है (transit में SSL के साथ, और rest में) और इसका access restrict करना।

Broken (या breached) authentication मतलब login mechanism इतना weak है कि attackers इसे bypass या hijack कर सकें, weak passwords, poor session handling, या flawed login logic के through, इन्हें users impersonate करने देते हुए। Defence strong authentication (अच्छे passwords, two-factor) और secure session management है। साथ में, ये चार vulnerabilities, injection, misconfiguration, data exposure, और broken authentication, सबसे ज़्यादा exploited में से हैं, यही वजह है इन्हें बंद करना एक security priority है।

Quiz

एक attacker एक login form में crafted input type करता है तो database इनका own SQL command execute करे। यह कौन सी vulnerability है, और इसे कैसे prevent किया जाता है?

  1. Broken authentication; faster servers से prevented
  2. एक injection attack (SQL injection); input validate करके और parameterised queries इस्तेमाल करके prevented
  3. Data exposure; एक DDoS filter से prevented
  4. Insecure settings; अकेले encryption से prevented
Show the answer

एक injection attack (SQL injection); input validate करके और parameterised queries इस्तेमाल करके prevented

Malicious input डालना जिसे database गलती से एक command की तरह run करता है एक injection attack है, specifically SQL injection, और इसे input validate करके और, crucially, parameterised queries इस्तेमाल करके prevent किया जाता है (जो user input को data की तरह रखते हैं, कभी executable SQL की तरह नहीं)। Option A इसे galat नाम देता है: broken authentication weak login mechanisms के बारे में है, और server speed injection से irrelevant है। Option C इसे data exposure की तरह galat नाम देता है (जो unprotected data leak करने के बारे में है) और एक unrelated defence offer करता है (एक DDoS filter)। Option D इसे insecure settings की तरह galat नाम देता है और एक incomplete defence देता है; अच्छी configuration generally help करती है, पर injection का specific fix input validation और parameterised queries है। SQL injection recognise कीजिए और parameterised queries से defend कीजिए, exactly जैसा आपने databases में सीखा।

Think first

Ye Same Vulnerabilities इतने सारे Systems के across बार-बार क्यों Appear होती हैं?

Injection और broken authentication सालों से known हैं। ये अभी भी इतने common क्यों हैं? फिर tap कीजिए।

Show the answer

क्योंकि ये software कैसे build और configure किया जाता है इसमें recurring MISTAKES से arise होती हैं, exotic flaws से नहीं, और जब तक developers और administrators वे mistakes करते रहते हैं (अक्सर pressure में, या security training के बिना), same weaknesses system के बाद system में फिर से appear होती रहती हैं। Injection सोचिए: यह तब होता है जब code एक command build करता है (जैसे एक database query) user input को बिना properly data को instructions से अलग किए mix करके। यह एक easy, tempting shortcut है, strings को साथ glue करना काम करता है और testing में fine दिखता है, तो developers इसे करते हैं, especially अगर इन्हें कभी नहीं सिखाया गया यह dangerous क्यों है या ये ship करने के लिए rush कर रहे हैं। Correct habit (parameterised queries, input validation) well known है पर हर बार apply करना पड़ता है, और एक भूला हुआ spot काफ़ी है। Broken authentication similarly common shortcuts से stem करता है: weak password rules, flaws वाला reused code, poor session handling, two-factor skip करना, हर एक एक obscure bug की बजाय एक omission है। Insecure settings शायद सबसे human हैं: unchanged छोड़े गए default passwords, 'temporarily' disabled protections, time save करने के लिए बहुत loose set की गई permissions, तो misconfiguration rampant है simply क्योंकि secure setup care और knowledge लेता है। Data exposure encrypt न करने या access restrict न करने से follow करता है, फिर एक omission। Pattern यह है कि ये vulnerabilities predictable human और process failures का RESULT हैं, knowledge में gaps, time pressure, oversight, तो ये उन conditions के exist होने पर कहीं भी recur होती हैं, जो almost हर जगह है। यही वजह है ये year after year 'most common vulnerability' lists पर dominate करती हैं, और यही वजह है security education (इस lesson की तरह) matter करती है: classic weaknesses और इनके defences जानना ही वह तरीका है जिससे developers इन्हें repeat करना बंद करते हैं। Flaws persist करते हैं क्योंकि इन्हें cause करने वाली mistakes आसान हैं करना और overlook करना, यही exactly वजह है awareness और disciplined secure practices real fix हैं। Known weaknesses endure करती हैं क्योंकि known-good practices consistently apply नहीं होतीं।

Summary

Key takeaways

  • एक vulnerability एक system में एक weakness है जिसे एक attacker exploit कर सकता है; common ones जानना defenders को इन्हें बंद करने देता है।
  • Injection attacks malicious input डालते हैं जिसे system एक command की तरह run करता है (जैसे SQL injection); input validation और parameterised queries से prevented।
  • Insecure security settings (misconfiguration, weak defaults, disabled protections) common और easily exploited हैं; secure configuration और review से prevented।
  • Sensitive data की exposure तब होती है जब data unencrypted या poorly protected है, तो यह leak होता है; encryption और restricted access से prevented।
  • Broken authentication attackers को login bypass या hijack करने देता है; strong authentication और secure session management से prevented।
  • ये vulnerabilities systems के across recur होती हैं क्योंकि ये common, avoidable mistakes से stem करती हैं।
  • Memory hook: injection, misconfiguration, data exposure, broken authentication, हर एक को इसके matching defence से बंद कीजिए।

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from Cyber Security Fundamentals

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati

Hackers and vulnerabilities: Injection attacks, changes in security settings, exposure of sensitive data, breach in authentication protocol · E-Commerce and Cyber Security (Minor-6-01) · Gri-Learn