About this interactive
Every scenario in this set is answered by one question: what is the attacker actually doing? Listening, relaying, pretending, taking over, feeding in bad input, or reading clues the machine gives off without meaning to. The bins are the lesson's attacks, minus denial of service, which has its own classifier. Trust exploits are left out too, because nearly every attack in the lesson ends with somebody abusing trust, so as a bin it would swallow the others rather than sit beside them. The pair this activity is built around is sniffing and on-path, because the lesson goes out of its way to separate them. A sniffer copies traffic that is already passing by: the café laptop, the wiretap on the cable, Wireshark on a shared segment. The victims' packets never go through the attacker, so the attacker can read them but cannot touch them. An on-path attacker is different in kind, not degree. The traffic flows through their machine, which receives each message and forwards it on — and anything that forwards can also delay, drop or change. So the test is simple. If the scenario shows the attacker altering or holding traffic, or being the device the traffic passes through, it is on-path. If the attacker only ends up with a copy, it is sniffing. Reading alone does not tell you which, because an on-path attacker can read too. Spoofing and session hijacking are the second pair worth slowing down for. Both end with an attacker who looks like someone else, but they get there differently. Spoofing forges an identity: a MAC address copied from a printer, a source IP borrowed from a partner company, a From line that says CEO, an access point broadcasting the hotel's name. Session hijacking forges nothing. The real user logged in, the server handed them a token to keep the session alive, and the attacker steals that token — from a cookie, a shared browser, an app — and carries on where the user left off. The tell is that the login already happened. A hijacker never faces the front door. The evil twin deserves a note, because it is the item most likely to feel like two answers. Once guests join the fake access point, the attacker will usually sit in their path and read or change what they send. The lesson still files the evil twin under spoofing, and so does this set, because the act the scenario describes is imitation: broadcasting a name that belongs to someone else. What the attacker does next is a second attack, and a good habit is to classify what the scenario shows, not what might follow. Injection is the easiest bin to recognise once you know the shape. An application asks for data — a username, a comment, a hostname — and the attacker hands it code instead, which the application then runs. SQL injection sends database commands through a login box. Cross-site scripting stores a script in a forum post so it runs in every visitor's browser. Command injection tacks a system command onto an address. XSS is often used to steal session cookies, which is why it sits near hijacking, but the scenario here describes the injected script, and that is the attack. Side channel attacks are the lesson's strangest bin and the one that most rewards careful reading. The attacker never asks the device for its secret and never captures its traffic. Instead they measure something the device does anyway — how much power it draws, how long it takes to answer, what it sounds like, what it radiates — and work backwards to what it must have been doing. The keyboard-audio item is placed deliberately to test this against eavesdropping. It is listening, but eavesdropping means listening to the communication itself; the keyboard never sent the phone anything.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →