In Computer Security , refers to a type of computer Hacker who is involved in Programming and Computer Insecurity and is able to exploit systems or gain unauthorized access through skills, tactics and detailed knowledge.
Most commonly, hacker refers to a Black-hat Hacker (a malicious or criminal hacker). There are also Ethical Hackers ( White Hat s), and Grey Hat s, although some of these terms are not universally accepted.
Similar, synonymous and related terms, which are not mutually exclusive, or universally accepted:
- : An ethical hacker who breaks security but who does so for altruistic or at least non-malicious reasons. White hats generally have a clearly defined code of ethics, and will often attempt to work with a manufacturer or owner to improve discovered security weaknesses, although many reserve the implicit or explicit threat of public disclosure after a "reasonable" time as a prod to ensure timely response from a corporate entity. The term is also used to describe hackers who work to deliberately design and code more secure systems. To White Hats, the darker the hat, the more the ethics of the activity can be considered dubious. Conversely, blackhats may claim the lighter the hat, the more the ethics of the activity are lost.
- : A hacker of ambiguous ethics and/or borderline legality, often frankly admitted.
- : Refers to outside computer security consulting firms that are used to bug test a system prior to its launch, looking for exploits so they can be closed.
- :
- # A Black Hat Hacker . Often used to differentiate black hat hackers and the general (positive) sense of Hacker . The use of the term began to spread around 1983, probably introduced both due to similar phonetic sound and as construction from the historical slang of Safe Cracker . Also theorized by some to be a Portmanteau of the words ''criminal'' and ''hacker''.
- # A Security Hacker who uses Password Cracking or Brute Force Attack s. Related to the term Safe Cracker .
- # A Software Cracker . A person specialized in working around copy protection mechanisms in software. Note that software crackers are not involved in exploiting networks, but copy protected software.
- : A computer intruder with little or no skill; a person who simply follows directions or uses a cook-book approach without fully understanding the meaning of the steps they are performing. Pejorative.
- is a hacker who utilizes technology to announce a political message. Web vandalism is not necessarily hacktivism.
There are several recurring tools of the trade used by computer criminals and security experts:
- .
- ). Thus, a computer virus behaves in a way similar to a Biological Virus , which spreads by inserting itself into living cells.
- Worm — Like a virus, a worm is also a self-replicating program. The difference between a virus and a worm is that a worm does not create multiple copies of itself on one system and that it propagates itself through computer networks. After the comparison between computer viruses and biological viruses, the obvious comparison here is to a Bacterium . Many people conflate the terms "virus" and "worm", using them both to describe any self-propagating program. It is possible for a program to have the blunt characteristics of both a worm and a virus.
- Vulnerability Scanner — A tool used to quickly check computers on a network for known weaknesses. Hackers also use Port Scanner s. These check to see which ports on a specified computer are "open" or available to access the computer. (Note that Firewalls defend computers from intruders by limiting access to ports/machines both inbound and outbound.)
- Sniffer — An application that captures password and other data while it is in transit either within the computer or over the network.
- Exploit — A prepared application that takes advantage of a known weakness.
- Social Engineering — Using manipulation skills in order to obtain some form of information. An example would be asking someone for their password or account possibly over a beer or by posing as someone else.
- Root Kit — A toolkit for hiding the fact that a computer's security has been compromised. Root kits may include replacements for system binaries so that it becomes impossible for the legitimate user to detect the presence of the intruder on the system by looking at Process Table s.
- Firewall (networking) In computing, a firewall is a piece of hardware and/or software which functions in a networked environment to prevent some communications forbidden by the security policy, analogous to the function of firewalls in building construction.
- Intrusion Detection System (or IDS), generally detects unwanted manipulations to systems. There are many different types of IDS, some of them are described here. The manipulations may take the form of attacks by skilled malicious hackers, or Script kiddies using automated tools.
- Anti-virus software consists of computer programs that attempt to identify, thwart and eliminate computer viruses and other malicious software (malware).
- Encryption is used to protect your message from the eyes of others. It can be done in several ways by switching the characters around, replacing characters with others, and even removing characters from the message. These have to be used in combination to make the encryption secure enough, that is to say, sufficiently difficult to crack.
- Authorization restricts access to a computer to group of users through the use of authentication systems. These systems can protect either the whole computer - such as through an interactive logon screen - or individual services, such as an FTP server.
Note that many of these have since turned to fully legal hacking.
- Jonathan James (a.k.a. comrade) was most notably recognized for the theft of software which controlled the International Space Station 's life sustaining elements, as well as intercepting dozens of electronic messages relating to U.S. nuclear activies from the Department Of Defense
- Mark Abene (a.k.a. Phiber Optik ) — Inspired thousands of teenagers around the country to "study" the internal workings of the United States phone system. One of the founders of the Masters Of Deception group.
- Dark Avenger — Bulgarian virus writer that invented Polymorphic Code in 1992 as a mean to circumvent the type of pattern recognition used by Anti-virus Software , and nowadays also Intrusion Detection System s.
- John Draper (a.k.a. "Captain Crunch") — Draper is widely credited with evangelizing the use of the 2600 hertz tone generated by whistles distributed in Captain Crunch cereal boxes in the 1970's, and sometimes inaccurately credited with discovering their use. Draper served time in prison for his work, and is believed to have introduced Steve Wozniak to phone Phreaking through the 2600hz tone. Draper now develops anti-spam and security software.
- Markus Hess — A West German , he hacked into United States Military sites and collected information for the KGB ; he was eventually tracked down by Clifford Stoll .
- Adrian Lamo — Lamo surrendered to federal authorities in 2003 after a brief manhunt, and was charged with nontechnical but surprisingly successful intrusions into computer systems at Microsoft , The New York Times , Lexis-Nexis , MCI WorldCom , SBC , Yahoo! , and others. His methods were controversial, and his full-disclosure-by-media practices led some to assert that he was publicity-motivated.
- Vladimir Levin — This mathematician allegedly masterminded the Russian hacker gang that tricked Citibank 's computers into spitting out $10 million. To this day, the method used is unknown.
- Kevin Mitnick — Held in jail without bail for a long period of time. Inspired the Free Kevin Movement . Once "the most wanted man in cyberspace," Mitnick went on to be a prolific public speaker, author, and media personality. Mitnick Security Consulting, LLC is a full-service information security consulting firm. Founded by Kevin Mitnick, Mitnick Security Consulting offers a comprehensive range of services to help businesses protect their valuable assets.
- Robert Tappan Morris — In 1988 while a graduate student at Cornell University , Morris was the creator of the first Worm , Morris Worm , which used buffer overflows to propagate. He is the son of Robert Morris, the former chief scientist at the National Computer Security Center, a division of the National Security Agency (NSA).
- Nahshon Even-Chaim (a.k.a. Phoenix ) — Leading member of Australian hacking group The Realm. Targeted US defence and nuclear research computer systems in late 1980s until his capture by Australian Federal Police in 1990. He, and fellow Realm members Richard Jones (a.k.a. Electron ) and David Woodcock (a.k.a. Nom ) were the world's first computer intruders prosecuted based on evidence gathered from remote computer intercept.
- Kevin Poulsen — In 1990 Poulsen took over all telephone lines going into Los Angeles area radio station KIIS-FM to win an automobile in a call-in contest. Poulsen went on to a career in journalism, including several years as editorial director at SecurityFocus .
- David L. Smith — In 1999 Smith launched the Melissa Worm , causing $80 million dollars worth of damage to businesses. Originally sentenced to 40 years, he eventually served only 20 months when he agreed to work undercover for the FBI .
- Craig Neidorf — In 1990, Neidorf (a co-founder of Phrack ) was prosecuted for stealing the E911 document from BellSouth and publicly distributing it online. BellSouth claimed that the document was worth $80,000; they dropped the charges after it was revealed that copies of the document could simply be ordered for a miniscule $13.
Hacker Cons have drawn more and more people every year including SummerCon (Summer), DEF CON , HoHoCon (Christmas), PumpCon (Halloween), H.O.P.E. (Hackers on Planet Earth) and HEU (Hacking at the End of the Universe).
- "2600: The Hacker Quarterly"
- "Hakin9"
- "Binary Revolution Magazine 2006"
|