LX5 SECURITY · LEARN THE LANGUAGE

Cybersecurity Glossary

A practical reference for 47 security and Internet terms, from algorithms and encryption to malware and network traffic.

Some slang terms are included to help readers recognize them. Labels such as “black hat,” “grey hat,” and “script kiddie” are informal and do not replace the question of whether an activity is authorized.

47 terms

Algorithm

A series of steps specifying which actions to take and in what order.

ANSI Bomb

A legacy term for malicious ANSI escape or key-remapping sequences that could affect certain old terminal setups. Modern terminals vary in how they handle escape sequences.

Back Door

A hidden or unauthorized way to regain access to a system later. The term can also describe a deliberately built-in bypass.

Binary

A numbering system with two possible values for each digit: 0 and 1.

Black Hat

A person who uses hacking skills for unauthorized or harmful activity.

Blue Hat

A context-dependent term, sometimes used for an outside security tester invited to find bugs before launch. Microsoft also uses BlueHat for security events.

Bot

An automated program. In malware discussions, it often means an infected device that receives commands from an operator.

Botnet

A network of compromised devices controlled to perform tasks such as spam, fraud, or distributed denial-of-service attacks.

Buffer Overflow

A programming error in which more data is written to a memory buffer than it can hold. In some cases, attackers can exploit it to change program behaviour.

Cracker

An older, context-dependent term for someone who breaks software protections or attempts to recover passwords. “Password cracker” can also refer to an auditing tool.

DDoS

Distributed denial of service: many sources overwhelm a service or its supporting resources so legitimate users cannot access it.

Deface

To change a website or page without authorization, often replacing its visible content.

Dictionary Attack

A password-guessing method that tries entries from a prepared wordlist. Rate limits, multifactor authentication, and strong unique passwords help defend against it.

DOX

To publish or expose someone’s personal information online, often without consent and with an intent to harass or intimidate.

E-Whore

Derogatory slang from some online communities for a scam that uses a false persona or stolen images to obtain money. The term is best avoided outside discussion of that scam.

Encryption

A cryptographic process that transforms plaintext into ciphertext using an algorithm and key. Decryption with the appropriate key restores the readable data.

Exploit

A method or code that takes advantage of a vulnerability. Security teams may use controlled exploits to validate a finding with authorization.

FUD

Slang for “fully undetectable,” often used to market malware or obfuscation. It is a claim, not a guarantee that software will evade detection.

Grey Hat

An informal label for someone whose security activity does not fit neatly into “black hat” or “white hat.” Authorization still matters.

Hacktivist

A person or group that uses hacking or digital disruption to promote a political or social cause. Methods and legality vary.

IP Address

A numerical address used to identify a network interface and route traffic. An IP address does not always identify one person or a precise physical location.

IP Grabber

A link or service intended to record the IP address of a visitor. Websites normally see a connecting IP address; the term often implies a deceptive link.

Keylogger

Hardware or software that records keystrokes. It can be used with consent for administration or misused as spyware.

Leech

Slang in file-sharing communities for someone who downloads much more than they contribute.

LOIC / HOIC

Names of tools associated with traffic-flooding attacks. Sending disruptive traffic to systems without authorization can be illegal.

Malware

Software designed to compromise a device or data, including spyware, ransomware, worms, and Trojans.

Neophyte / Newbie

Someone new to a technical subject. “n00b” is informal slang and may be used dismissively.

OldFag

Offensive legacy forum slang for a long-time member. Avoid using the label for people.

Packet

A formatted unit of data transmitted across a network. Data may be split into packets and reconstructed by the receiving system.

Phreak

A person interested in exploring or manipulating telephone systems; a term associated with phone-network history.

Phreaking

The exploration or manipulation of telephone networks, sometimes involving unauthorized access or toll fraud.

Proxy

An intermediary that receives a client request and forwards it to another service, then returns the response.

Rainbow Table

A precomputed table used to speed up recovery of some password hashes. Unique salts make precomputed tables far less useful.

Remote Administration Tool (RAT)

Software used to control another machine remotely. Legitimate remote support tools require authorization; malware can provide the same capability covertly.

Resolver

A program or service that translates a name into an address, such as a DNS resolver. In some forums, it may refer to a tool that tries to discover a person’s IP address.

Reverse Engineering

Studying a program or device to understand how it works, often for compatibility, security research, or vulnerability analysis.

Root

The superuser account or privilege level on Unix-like systems, with broad authority over the machine.

Rootkit

Software designed to maintain privileged access and hide its presence. User-mode and kernel-mode rootkits exist; removal depends on the specific infection.

Script Kiddie

Derogatory slang for someone who uses tools or scripts made by others without understanding them.

Shell

A command interpreter that lets a user run commands. A web shell is a script that provides command execution through a web application, sometimes after compromise.

Smith

Informal community slang for a newcomer; its meaning varies by forum and it is not a standard security term.

Social Engineering

Manipulating people rather than software to obtain information, access, or action. Phishing is one common example.

Spoof

To falsify an identity or technical attribute, such as an email sender, caller ID, or source IP address, depending on the context.

SQL Injection

A vulnerability in which untrusted input changes a database query. Parameterized queries are a primary defense.

Trojan

Malware presented as a legitimate or useful program to persuade someone to install or run it.

VPS

Virtual private server: a virtual machine provided by a hosting service with allocated computing resources and administrative control.

Warez

Slang for software distributed without authorization, often in violation of copyright or license terms.

Further reference

Definitions were reviewed against the NIST CSRC Glossary ↗ and CISA/NICCS Glossary ↗. Informal slang may vary by community.