ALL ABOUT VULNERABILITIES

🌐 Change Language / Ndrysho Gjuhën
What is a Vulnerability?

A cybersecurity vulnerability is a weakness in systems, networks, software, hardware, or human processes that can be exploited by an attacker. By taking advantage of a vulnerability, attackers can gain unauthorized access, run malicious code, steal or destroy data, cause system shutdowns, or bypass security controls.

📌 Why do vulnerabilities matter?

Because every organization depends on digital assets. A single vulnerability can cause:

• Data breaches • System shutdowns • Ransomware attacks • Identity theft • Large-scale financial loss • Loss of customer trust
When Does a Vulnerability Become Exploitable?

A vulnerability becomes exploitable when attackers have a working attack method (payload, exploit code, misconfiguration, or social engineering vector).

📌 Window of Vulnerability

This is the time between:

• When the vulnerability appears • When a patch is created and applied

Attackers actively use this window to compromise systems.

What is a Zero-Day Vulnerability?

A zero-day vulnerability is unknown to developers and security teams. Since there is no patch, attackers have full advantage.

Main Causes of Vulnerabilities
  • Complex systems → more flaws
  • Poor password management
  • Misconfigurations
  • Software bugs
  • Employees (social engineering)
  • Network exposure
  • Insecure defaults
  • Unvalidated user input (SQLi, XSS)
What is Vulnerability Management?

It’s the continuous process of identifying, scanning, classifying, fixing, and monitoring vulnerabilities.

Main Steps:
  • Vulnerability scanning
  • Penetration testing
  • Verification and prioritization
  • Mitigation and remediation
  • Continuous monitoring
Penetration Testing (Ethical Hacking)

Pen-testing simulates real cyberattacks to find weaknesses before criminals do.

Types include:
  • Black-box testing
  • White-box testing
  • Gray-box testing
  • Web app testing
  • Network testing
  • Social engineering testing

More content coming soon… 3rj0n1xx.ro0t

Çfarë është një Cenueshmëri?

sigurinë kibernetike, cenueshmëria është një dobësi në sistemet, rrjetet, pajisjet, programet apo proceset njerëzore që mund të shfrytëzohet nga një sulmues për të marrë akses të paautorizuar ose për të shkaktuar dëme.

📌 Pse janë të rrezikshme cenueshmëritë?

Sepse një dobësi e vetme mund të shkaktojë:

• Vjedhje të të dhënave • Sulme ransomware • Shkatërrim sistemesh • Humbje financiare • Komprometim rrjetesh • Humbje reputacioni
Kur bëhet një cenueshmëri e shfrytëzueshme?

Kur ekziston një metodë funksionale sulmi (exploit) që mund ta përdorë.

📌 Dritarja e Cenueshmërisë

Kjo periudhë përfshin kohën nga:

• momenti kur dobësia shfaqet • deri kur vendoset patch-i

Gjatë kësaj kohe, sulmuesit kanë epërsi maksimale.

Çfarë është një Zero-Day?

Një cenueshmëri që ende nuk njihet nga zhvilluesit dhe nuk ka patch. Shfrytëzohet në heshtje nga sulmuesit.

Shkaqet kryesore të cenueshmërive
  • Sisteme komplekse
  • Fjalëkalime të dobëta
  • Konfigurime të gabuara
  • Bug-e softuerike
  • Gabime njerëzore
  • Rrjete të pasigurta
  • Input i pakontrolluar (SQLi, XSS)
Çfarë është Menaxhimi i Cenueshmërisë?

Proces i vazhdueshëm që përfshin zbulim, skanim, analizë, zbutje dhe rregullim të të gjitha dobësive në një mjedis digjital.

Penetration Testing (Hacking Etik)

Një test real për të zbuluar dobësitë para se t’i gjejë një hacker i keq.

  • Testim black-box
  • Testim white-box
  • Testim gray-box
  • Testim të web aplikacioneve
  • Testim të rrjetit
  • Testim social engineering

Vazhdimi vjen shumë shpejt… 3rj0n1xx.ro0t