If you have read about historical battles, you will know that no two enemies are the same. However, common techniques are always used that have proven over time to be effective and bring the desired results. In the same way, when a hacker tries to break into an organization, he does not have to reinvent the wheel. Instead, he will use common hacking techniques that are known for their high probability of success, such as malware, phishing, cross site scripting (XSS), and others. Below are the most common hacking techniques that you can encounter today.

Malware
Malware is a type of malicious software, such as viruses and ransomware. Once a system is infected with malware, it can wreak havoc. Malware can destroy files, take control of the computer, install keyloggers, or even steal personal files that the user keeps on their computer.
Phishing
In a phishing attack, attackers send emails pretending to be people you trust, such as your boss, the company you work for, Facebook , or someone else. They usually inform you of an urgent need, such as that your account has been stolen or that someone is trying to access your bank account from abroad. Phishing emails contain either a malicious link or an attached file that is ready to install malware on your computer.
SQL Injection Attack
SQL from databases. Many servers that hold large amounts of data use SQL. A SQL injection attack targets these servers, and uses special code to obtain results that the SQL database would not normally produce. This is particularly bad, especially if the database holds personal customer information or billing information.
Cross-Site Scripting (XSS)
In an SQL attack, the hacker targets a website and the files it holds. If the hacker were targeting the website's users, the attack would be called cross site scripting, or XSS. Similar to an SQL attack where the hacker injects code, with XSS the hacker injects malicious code into the website, which is executed in the users' browsers.
Denial of Service (DoS)
Imagine that there is a small road for the residents of a village to travel. Under normal circumstances, there should be no traffic on this road. Now imagine that a big concert is being organized, and those who will attend have to pass through this small road. So the residents of the village are forced to wait in long traffic queues, as the road is not designed for such a large volume of vehicles. This is how a DOS. A malicious user sends hundreds of thousands of packets per second to a server, and thus site visitors are forced to wait long periods of time for pages to load or even worse, they may never load, as the server may crash.
Session Hijacking and Man-in-the-Middle Attacks
When you are on the internet, your computer exchanges many packets with the servers it communicates with. This is how it creates so-called sessions where necessary to avoid many repeated packets. When you create a session, you also create its unique ID, which is known only to the two systems that communicate with each other (pc and server). However, if someone can see the session ID, they can have access to critical information, just like a normal user. There are many techniques with which this can be achieved, and the hacking process is called session hijacking. In addition, the attacker can become an intermediary between the pc and the server, having the ability to see but also to configure all the data they transmit. The hacking technique is called Man In The Middle Attack.
Credential Reuse
Many people use the same password across multiple online services. So, when a breach occurs on one service, hackers can use the same email and password combination on other services. If the same email and password are used across all services, then hackers will definitely be able to gain access to several of your accounts.
