Showing posts with label Cracking. Show all posts
Showing posts with label Cracking. Show all posts

Thursday, August 21, 2008

Computer Hacking

| Hack Ethics | Hactivisme | White Hat | Black Hat | Grey Hat | Blue Hat | Hack Methods | Script Kiddie | Computer Hack |

In a security context, a hacker is someone involved in computer security/insecurity, specializing in the discovery of exploits in systems (for exploitation or prevention), or in obtaining or preventing unauthorized access to systems through skills, tactics and detailed knowledge. In the most common general form of this usage, "hacker" refers to a black-hat hacker (a malicious or criminal hacker). There are also ethical hackers (more commonly referred to as white hats), and those more ethically ambiguous (grey hats). To disambiguate the term hacker, often cracker is used instead, referring either to computer security hacker culture as a whole to demarcate it from the academic hacker culture (such as by Eric S. Raymond[1]) or specifically to make a distinction within the computer security context between black-hat hackers and the more ethically positive hackers (commonly known as the white-hat hackers). The context of computer security hacking forms a subculture which is often referred to as the network hacker subculture or simply the computer underground. According to its adherents, cultural values center around the idea of creative and extraordinary computer usage. Proponents claim to be motivated by artistic and political ends, but are often unconcerned about the use of criminal means to achieve them.

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

Source:Wikipedia

Common Methods

There are several recurring tools of the trade and techniques used by computer criminals and security experts:

Security exploit

A security exploit is a prepared application that takes advantage of a known weakness.

Vulnerability scanner

A vulnerability scanner is a tool used to quickly check computers on a network for known weaknesses. Hackers also commonly use port scanners. These check to see which ports on a specified computer are "open" or available to access the computer, and sometimes will detect what program or service is listening on that port, and its version number. (Note that firewalls defend computers from intruders by limiting access to ports/machines both inbound and outbound, but can still be circumvented.)

Packet Sniffer

A packet sniffer is an application that captures TCP/IP data packets, which can maliciously be used to capture passwords and other data while it is in transit either within the computer or over the network.

Spoofing attack

A spoofing attack is a situation in which one person or program successfully masquerades as another by falsifying data and thereby gaining illegitimate access.

Rootkit

A rootkit is a toolkit for hiding the fact that a computer's security has been compromised, is a general description of a set of programs which work to subvert control of an operating system from its legitimate (in accordance with established rules) operators. Usually, a rootkit will obscure its installation and attempt to prevent its removal through a subversion of standard system security. Root kits may include replacements for system binaries so that it becomes impossible for the legitimate user to detect the presence of the intruder on the system by looking at process tables.

Social engineering

Social Engineering is simply the art of getting unsuspecting persons to reveal sensitive information about a system. This is usually done by impersonating someone or by convincing people to believe you have permissions to obtain such information. A typical example would be eavesdropping on or discussing company security details at a café. A more subtle method would be via impersonation: requesting promotional material or technical reference material regarding a company's systems while pretending to be co-worker or contractor working under pressure or within unseen limitations.

Trojan horse

A Trojan horse is a program designed as to seem to being or be doing one thing, such as a legitimate software, but actually being or doing another. They are not necessarily malicious programs but can be. A trojan horse can be used to set up a back door in a computer system so that the intruder can return later and gain access. Viruses that fool a user into downloading and/or executing them by pretending to be useful applications are also sometimes called trojan horses. (The name refers to the horse from the Trojan War, with conceptually similar function of deceiving defenders into bringing an intruder inside.) See also Dialer.

Virus

A virus is a self-replicating program that spreads by inserting copies of itself into other executable code or documents. Thus, a computer virus behaves in a way similar to a biological virus, which spreads by inserting itself into living cells.

Worm

Like a virus, a worm is also a self-replicating program. The difference between a virus and a worm is that a worm does not create copies of itself on one system: it propagates through computer networks. After the comparison between computer viruses and biological viruses, the obvious comparison here is to a bacterium. Many people conflate the terms "virus" and "worm", using them both to describe any self-propagating program. It is possible for a program to have the blunt characteristics of both a worm and a virus.

Key loggers

A keylogger is a software program designed to record ('log') every keystroke on the machine on which it runs. Often uses virus-, trojan-, and rootkit-like methods to remain active and hidden from the victim (and possibly self-replicate). The log is later transferred to the 'owner' of the keylogger. Hardware-assisted and hardware-based keyloggers also exist

Hacktivisme

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

A hacktivist is a hacker who utilizes technology to announce a political message. Web vandalism is not necessarily hacktivism.

Hacktivism (a portmanteau of hack and activism) is "the nonviolent use of illegal or legally ambiguous digital tools in pursuit of political ends. These tools include web site defacements, redirects, denial-of-service attacks, information theft, web site parodies, virtual sit-ins, virtual sabotage, and software development."[1] It is often understood as the writing of code to promote political ideology - promoting expressive politics, free speech, human rights, or information ethics. Acts of hacktivism are carried out in the belief that proper use of code will have leveraged effects similar to regular activism or civil disobedience. Fewer people can write code, but code affects more people.

Hacktivist activities span many political ideals and issues. Freenet is a prime example of translating political thought (anyone should be able to speak) into code. Hacktivismo is an offshoot of CULT OF THE DEAD COW; its beliefs include access to information as a basic human right. The loose network of programmers, artists and radical militants 1984 network liberty alliance is more concerned with issues of free speech, surveillance and privacy in an era of increased technological surveillance.

Hacktivism is a controversial term. Some argue it was coined to describe how electronic direct action might work toward social change by combining programming skills with critical thinking. Others use it as practically synonymous with malicious, destructive acts that undermine the security of the Internet as a technical, economic, and political platform.

Essentially, the controversy reflects two divergent philosophical strands within the hacktivist movement. One strand thinks that malicious cyber-attacks are an acceptable form of direct action. The other strand thinks that all protest should be peaceful, refraining from destruction.

Controversy

Some people describing themselves as hacktivists have taken to defacing websites for political reasons, such as attacking and defacing government websites as well as web sites of groups who oppose their ideology. Others, such as Oxblood Ruffin (the "foreign affairs minister" of Hacktivismo), have argued forcefully against definitions of hacktivism that include web defacements or denial-of-service attacks.[2]

Critics suggest that DoS attacks are an attack on free speech; that they have unintended consequences; that they waste resources; and that they could lead to a "DoS war" which nobody will win. In 2006, Blue Security attempted to automate a DoS attack against spammers; this led to a massive DoS attack against Blue Security which knocked them, their old ISP and their DNS provider off the internet, destroying their business.[3]

Depending on who is using the term, hacktivism can be a politically constructive form of anarchist civil disobedience or an undefined anti-systemical gesture; it can signal anticapitalist or political protest; it can denote anti-spam activists, security experts, or open source advocates. Critics of hacktivism fear that the lack of a clear agenda makes it a politically immature gesture, while those given to conspiracy theory hope to see in hacktivism an attempt to precipitate a crisis situation online.

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

Script Kiddie

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

In hacker culture, a script kiddie (as opposed to "speed kiddie", occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar) is a derogatory term used for an inexperienced malicious hacker who uses programs developed by others to attack computer systems, and deface websites. It is generally assumed that script kiddies are kids who lack the ability to write sophisticated hacking programs on their own,[1] and that their objective is to try to impress their friends or gain credit in underground hacker communities.

Script kiddies are often able to exploit vulnerable systems and strike with great success. The most famous examples include:

  • Michael Calce (aka Mafiaboy), from Montreal Canada, was arrested in 2000 for using downloaded tools to launch DoS attacks against high-profile websites such as Yahoo, Dell, eBay, and CNN. He was 15 years old at the time. The financial damages were estimated at roughly $7.5 million. He pleaded guilty to 56 criminal charges. On September 12, 2001, Mafiaboy appeared before the Montreal Youth Court in Canada and was sentenced to eight months “open custody,” one year probation, and restricted use of the Internet.[2]
  • In 1999, NetBus was used to discredit a law student named Magnus Eriksson studying at the Lund University. Child pornography was downloaded onto his computer from an unidentified location. He was later acquitted of charges in 2004 when it was discovered that NetBus had been used to control his computer.
  • Jeffrey Lee Parson, an 18-year-old high school student from Minnesota was responsible for using the B variant of the infamous Blaster worm. The program was part of a DoS attack against computers using the Microsoft Windows operating system. The attack took the form of a SYN flood which caused only minimal damage. He was sentenced to 18 months in prison in 2005.
| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

Blue Hat

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

Blue Hat is a term used to refer to outside computer security consulting firms that are employed to bug test a system prior to its launch, looking for exploits so they can be closed.

An event that is intended to open communication between Microsoft engineers and hackers is called Blue Hat Microsoft Hacker Conference. The event has led to both mutual understanding as well as the occasional confrontation. Microsoft developers were visibly uncomfortable when Metasploit was demonstrated.

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

Grey Hat

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |
A grey hat, in the hacking community, refers to a skilled hacker who sometimes acts legally, sometimes in good will, and sometimes not. They are a hybrid between white and black hat hackers. They usually do not hack for personal gain or have malicious intentions, but may or may not occasionally commit crimes during the course of their technological exploits.

Disambiguation

One reason a grey hat might consider himself to be grey is to disambiguate from the other two extremes: black and white. It might be a little misleading to say that grey hat hackers do not hack for personal gain. While they do not necessarily hack for malicious purposes, grey hats do hack for a reason, a reason which more often than not remains undisclosed. A grey hat will not necessarily notify the system admin of a penetrated system of their penetration. A grey hat will prefer anonymity at almost all cost, carrying out their penetration undetected and then leaving undetected. Consequently, grey hat penetrations of systems tend to be far more passive activities such as testing, monitoring, or less destructive forms of data transfer and retrieval.

A person who breaks into a computer system and simply puts their name there whilst doing no damage (such as in wargaming - see) can also be classified as a grey hat. A person who hacks for comedic value, may also be classified as a grey hat. However, he would have found his own security flaw, rather than using someone else's. See Script Kiddie for details.

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

Black Hat

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

A black hat is the villain or bad guy, especially in a western movie in which such a character would wear a black hat in contrast to the hero's white hat. The phrase is often used figuratively, especially in computing slang, where it refers to a hacker that breaks into networks or computers, or creates computer viruses.[1]

Notable black hat villains in movies

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

White Hat

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

A white hat is the hero or good guy, especially in computing slang, where it refers to an ethical hacker that focuses on securing and protecting IT systems.[1] Such people are employed by computer security companies where these professionals are sometimes called sneakers.[citation needed] Groups of these people are often called tiger teams.[2][citation needed]

Other examples would be a western movie in which such a character would wear a white hat in contrast to the villain's black hat. Examples of such characters are Red Ryder, Tom Mix and The Lone Ranger.

In the Scottish Rite of Freemasonry a white hat signifies an honorable degree which has been bestowed upon a member. It is also known as the 33rd degree.

In recent years the terms white hat and black hat have been applied to the Search Engine Optimization (SEO) industry. Black hat SEO tactics, also called spamdexing, attempt to redirect search results to particular target pages in a fashion that is against the search engines' terms of service, whereas white hat methods are generally approved by the search engines.[citation needed]

In "The Wish," the ninth episode of season 3 on Buffy the Vampire Slayer, Cordelia Chase is saved by the "White Hats," a group of human vampire-fighters led by Giles and including Oz and Larry.

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

The Hacker Ethics

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |

As Levy stated in the preface of Hackers: Heroes of the Computer Revolution,[1] the general tenets or principles of hacker ethic include:

  • Sharing
  • Openness
  • Decentralization
  • Free access to computers
  • World Improvement

In addition to those principles listed above, Levy also described more specific hacker ethics and beliefs in chapter 2, The Hacker Ethic.[2] The ethics he described in chapter 2 are quoted here.

  • Access to computers—and anything which might teach you something about the way the world works—should be unlimited and total. Always yield to the Hands-On Imperative!
  • All information should be free.
  • Mistrust Authority—Promote Decentralization.
  • Hackers should be judged by their hacking, not bogus criteria such as degrees, age, race, or position.
  • You can create art and beauty on a computer.
  • Computers can change your life for the better.

Sharing

According to Levy's account, sharing was the norm and expected within the non-corporate hacker culture. The principle of sharing stemmed from the atmosphere and resources at MIT. During the early days of computers and programming (when computers were the size of whole rooms), the hackers at MIT would develop a program and share it.

If the hack was particularly good, then the program might be posted on a board somewhere near one of the computers. Other programs that could be built upon and improved were saved to tapes and added to a drawer of programs - readily accessible to all the other hackers. At any time, a fellow hacker might reach into the drawer, pick out the program, and begin adding to it or "bumming" it to make it better (bumming refers to the process of making the code more concise so that more can be done in fewer instructions).

In the second generation of hackers, sharing was about sharing with the general public in addition to sharing with other hackers. A particular organization of hackers that was concerned with sharing computers with the general public was a group called Community Memory. This group of hackers and idealists put computers in public places for anyone to use. The first community computer was placed outside of Leopold's Records in Berkeley, California.

Another sharing of resources occurred when Bob Albrecht provided considerable resources for a non-profit organization called People's Computer Company (PCC). PCC opened a computer center where anyone could use the computers there for fifty cents an hour.

It was also the sharing of this second generation that resulted in some of the battles over free and open software. In fact, when Bill Gates' version of BASIC for the Altair was 'shared' among the hacker community, Gates lost a considerable sum of money because no one was paying for the software. As a result, Gates wrote an Open Letter to Hobbyists.[3][4] This letter was published by several computer magazines and newsletters - most notably that of the Homebrew Computer Club where much of the sharing occurred.

Hands-On Imperative

Many of the principles and tenets of Hacker Ethic contribute to a common goal - the Hands-On Imperative. As Levy described in chapter 2, "Hackers believe that essential lessons can be learned about the systems—about the world—from taking things apart, seeing how they work, and using this knowledge to create new and more interesting things."[5]

Employing the Hands-On Imperative requires free access, open information, and the sharing of knowledge. To a true hacker, if the Hands-On Imperative is restricted, then the ends justify the means to make it unrestricted so that improvements can be made. When these principles are not present, hackers tend to work around them. For example, when the computers at MIT were protected either by physical locks or login programs, the hackers there systematically worked around them in order to have access to the machines.

It is important to note that this behavior was not malicious in nature - the MIT hackers did not seek to harm the systems or their users (although, every now and then, some practical jokes were played using the computer systems). This deeply contrasts with the modern, media-encouraged image of hackers who crack secure systems in order to steal information or complete an act of cybervandalism.

Community and Collaboration

Throughout writings about hackers and their work processes, a common value of community and collaboration is present. For example, in Levy's Hackers, each generation of hackers had geographically-based communities where collaboration and sharing occurred. For the hackers at MIT, it was the labs where the computers were running. For the hardware hackers (second generation) and the game hackers (third generation) the geographic area was centered in Silicon Valley where the Homebrew Computer Club and the People's Computer Company helped hackers network, collaborate, and share their work.

The concept of community and collaboration is still relevant today, although hackers are no longer limited to collaboration in geographic regions. Now collaboration takes place via the Internet. Eric S. Raymond identifies and explains this concept shift in The Cathedral and the Bazaar.

Before cheap Internet, there were some geographically compact communities where the culture encouraged Weinberg's egoless programming, and a developer could easily attract a lot of skilled kibitzers and co-developers. Bell Labs, the MIT AI and LCS labs, UC Berkeley—these became the home of innovations that are legendary and still potent.[6]

Raymond also points-out that the success of Linux coincided with the wide-availability of the world wide web. No doubt the collaboration and development community fostered by the web was key to the successful development of Linux. The value of community is still in high practice and use today.

| Ethics | Hactivisme | White | Black | Grey | Blue | Methods | Script Kiddie | Computer |