Attack surfaces, attack vectors, and vulnerabilities are foundational concepts in offensive security, defining where a target is exposed, how an attacker gains entry, and what weaknesses make that entry possible. This content covers a wide range of vulnerability categories across physical, technical, human, and procedural domains.
Attack Surface, Vectors & Vulnerabilities
As soon as we understand the attack surface, we can look for an attack vector, and we usually use vulnerabilities for that.
Let's say I'm physically attacking this building. How can I get into it? That's the attack surface right here. The attack surface may mean that I can come from underground into it. Maybe I can go through the door. Maybe I can go through a window. Maybe I can crush through a wall. Maybe somehow I can get to the roof. I'm going to analyze all of the different entry points, and the sum of all those entry points is that attack surface.
What I'm looking for is a vector. The attack vector is the route that I'm going to choose. Maybe the easiest way is just to walk through the front door, or break in through the front door perhaps. Maybe it is that I have access to the top roof, but because it's kind of not really thought of that much, there's an access up there that is not locked. And so now I have access through that unlocked door. Well, that's going to be my attack vector.
The way I'm going to identify my attack vector is going to probably be through some sort of vulnerability. I mentioned at the top roof an unlocked door — it's not really thought of too much, so that way I can climb the fire escape and get in through that unlocked door. Well, this is a vulnerability. They've left themselves open. But there could be other vulnerabilities as well. Maybe somebody leaves a window unlocked and it's a lower level that I can use a ladder to get into. Or maybe the front door has a really weak lock, so maybe I can just break it in. So I'm going to be looking for vulnerabilities. In other words, we analyze the attack surface and we're looking for vulnerabilities to find our attack vector.
Some vulnerabilities that I may be looking for might be something like a technology weakness. Maybe I know it's a weak lock or it's a faulty lock. Maybe there's some sort of misconfiguration — for instance, there's a camera, but it's pointing in the entirely wrong direction, so it's not going to capture anything. Maybe there's a guard and they're going to take breaks at a certain time. That is a process weakness: if they take the same break at the same time of day, then that becomes a vulnerability.
There are a lot of common vulnerabilities that we can access and that we can use as our attack vector, and I mentioned already physically breaking into a building is an example of that.
Perhaps there are some sort of hardware vulnerabilities that we can exploit. Here's a Cisco switch right here, and this Cisco switch is old and end of life. We could leverage a machine like this because it's not getting updates, it's not getting patched. So we know that any kind of security holes that come out after the last patch are going to still exist on these machines. That firmware is not getting updated anymore, and so we can leverage that to get into the system.
There's also weaknesses in software and services. People release software with bugs in it all the time, and those bugs can cause problems, and if they're not patched on a regular basis then we can utilize those to leverage to get into the system.
There are some vulnerabilities that come with virtualization and the cloud: if we have access to one machine, we might be able to gain access to another machine, and there are vulnerabilities that would allow us to do this.
Mobile devices is also another way that we can gain access. A lot of people do not keep secure mobile devices, and those are going in and out of companies all the time. So if we can get a hold of one of these mobile devices, digitally get a hold of it through a vulnerability, now we can maybe get access into a company.
There's also protocol weaknesses. There's a lot of different protocols that we use, and some of them are really old and really haven't been updated. They are sending clear text, or they just have these weaknesses involved in them. So we can leverage some of the weaknesses, the vulnerabilities of these protocols, in order to gain access.
There are also cryptographic vulnerabilities. For instance, at one point in time DES was considered to be secure, and then we hacked it. There are times when we got better and better at hacking it, so now it's something that's vulnerable. So if somebody has not upgraded to more recent cryptography, then that could be an issue with their network, a vulnerability of their network that we could leverage to attack that network.
There are also known vulnerabilities with certain data and certain files. For instance, there are macros that are built into Word documents or Excel documents that, if we can get into the system and trick somebody into launching those, will open up the rest of the system to us.
And then once again, those third-party / supply chains that sell equipment to businesses — there have been well-known attacks where, for instance, software that's been sold by a third party that's supposed to be security software has been found to have a vulnerability which has brought systems down and caused a lot of problems. So there's these third-party supply chain vulnerabilities that are out there that we could leverage as well.
One of the ways that we can really leverage to get into a company is through social engineering. When it comes to equipment, if it's being patched on a regular basis, then the idea is that there's going to be less vulnerabilities to it. But there's always going to be this human factor in it — whether it's because the machine didn't get patched in a timely manner because the human behind it is not patching it on a regular basis, or perhaps we're just tricking those humans to install things because they have admin access on those machines. So we can perform some sort of social engineering to gain access.
Often we can find misconfigurations — misconfigurations with software, with hardware, with machines on the network, with firewalls. We can find misconfigurations that allow us to gain access to a network.
Also, people are really bad about picking passwords. Unless you've been trained properly, we tend to pick really bad passwords. So the majority of the company that has passwords to access company resources don't have good passwords.
There are also weaknesses in processes. Businesses have processes, and if there's not the proper checks and balances or distribution of duties, then what we can do is we can leverage those vulnerabilities to attack a system.
And a relatively new player out there is AI, artificial intelligence. Although artificial intelligence has been around for a long time, there's a lot of end users that are using this for their daily work nowadays, and there are weaknesses with artificial intelligence as well.
So what we're going to be doing is we're going to be analyzing that attack surface, figure out what the vulnerabilities are, and start figuring out how we're going to leverage that to get into the system. Then we'll be developing an attack plan. We're going to use one of those attack vectors to get into the company.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →