Lazo Lab Sign up

Guides

Common attacks, and how to stop them

Beginner 路 8 min read

Phishing, malware, ransomware, brute force and more, each with the defence that beats it.

Phishing

Fake messages that trick you into giving up a password or opening a bad file. They create urgency: your account is locked, your parcel is stuck, your boss needs this now.

Defence: slow down. Check the real sender address, hover over links before clicking, and log in by typing the site's address yourself. Two-factor login stops most stolen passwords from being useful.

Malware and ransomware

Malware is any harmful software. Ransomware encrypts your files and demands payment to unlock them. It usually arrives through phishing attachments, cracked software, or unpatched systems.

Defence: keep systems updated, only install software from trusted sources, and keep backups that aren't permanently connected to the computer.

Brute force and credential stuffing

Brute force means guessing passwords over and over. Credential stuffing means trying passwords leaked from one site on other sites, which works because people reuse passwords.

Defence: a unique password for every site (a password manager makes this easy), two-factor login, and on servers, limiting login attempts with tools like fail2ban.

Man-in-the-middle

An attacker secretly sits between you and a website, reading or changing traffic. It's most common on open public Wi-Fi.

Defence: HTTPS everywhere, never ignore certificate warnings, and use a VPN on networks you don't trust.

SQL injection

When a website builds database queries by gluing user input into text, an attacker can type database commands into a form and run them.

Defence: always use parameterised queries, where user input is passed separately from the command.

# Unsafe: input becomes part of the command
db.execute(f"SELECT * FROM users WHERE name = '{name}'")

# Safe: input is passed separately
db.execute("SELECT * FROM users WHERE name = ?", (name,))

Denial of service

Flooding a service with traffic until real users can't reach it. Large attacks (DDoS) use thousands of hijacked devices at once.

Defence: services like Cloudflare absorb floods, and rate limits stop one source from hogging everything.