All the information on this page is for educational purposes only. The owner of the blog, nor Blogger, nor anyone associated with this blog can be held liable for illegal activities brought by this blog
Showing posts with label Black Hat. Show all posts
Showing posts with label Black Hat. Show all posts

Monday, October 17, 2011

Questions people have always wanted to ask, but didn't know who to ask



The answer to the age-old question: What is the difference between a hacker and a cracker?

A hacker is a person intensely interested in the arcane and recondite workings of any computer operating system. Most often, hackers are programmers. As such, hackers obtain advanced knowledge of operating systems and programming languages. They may know of holes within systems and the reasons for such holes. Hackers constantly seek further knowledge, freely share what they have discovered, and never, ever intentionally damage data.

A cracker is a person who breaks into or otherwise violates the system integrity of remote machines, with malicious intent. Crackers, having gained unauthorized access, destroy vital data, deny legitimate users service, or basically cause problems for their targets. Crackers can easily be identified because their actions are malicious.
(Special thanks to http://newdata.box.sk/bx/hacker/ch03/ch03.htm for the definitions)

Different types of hackers:

Black Hat:
Black hat is used to describe a hacker (or, if you prefer, cracker) who breaks into a computer system or network with malicious intent. Unlike a white hat hacker, the black hat hacker takes advantage of the break-in, perhaps destroying files or stealing data for some future purpose. The black hat hacker may also make the exploit known to other hackers and/or the public without notifying the victim. This gives others the opportunity to exploit the vulnerability before the organization is able to secure it.
The term comes from old Western movies, where heroes often wore white hats and the "bad guys" wore black hats.

White Hat:
White hat describes a hacker (or, if you prefer, cracker) who identifies a security weakness in a computer system or network but, instead of taking malicious advantage of it, exposes the weakness in a way that will allow the system's owners to fix the breach before it can be taken advantage by others (such as black hat hackers.) Methods of telling the owners about it range from a simple phone call through sending an e-mail note to a Webmaster or administrator all the way to leaving an electronic "calling card" in the system that makes it obvious that security has been breached.
While white hat hacking is a hobby for some, others provide their services for a fee. Thus, a white hat hacker may work as a consultant or be a permanent employee on a company's payroll. A good many white hat hackers are former black hat hackers.
The term comes from old Western movies, where heros often wore white hats and the "bad guys" wore black hats.

Grey Hat:
Gray hat describes a cracker (or, if you prefer, hacker) who exploits a security weakness in a computer system or product in order to bring the weakness to the attention of the owners. Unlike a black hat, a gray hat acts without malicious intent. The goal of a gray hat is to improve system and network security. However, by publicizing a vulnerability, the gray hat may give other crackers the opportunity to exploit it. This differs from the white hat who alerts system owners and vendors of a vulnerability without actually exploiting it in public.
(Special thanks to http://www.whatis.com )

Famous Hackers:

Black Hats:
  • Jonathan James
  • Adrian Lamo
  • Kevin Mitnick
  • Kevin Poulsen
  • Robert Tappan Morris
  • Vladimir Levin
  • Donald Lloyd
  • David Smith
  • Michael Calce
  • Mark Abene
White Hats:
  • Stephen Wozniak
  • Tim Berners-Lee
  • Linus Torvalds
  • Richard Stallman
  • Tsutomu Shimomura
That's all for now

Hope you enjoyed today's blog

Techno Master

    Sunday, October 16, 2011

    A brief overview of hacking - Part 2

    Ok, so let's begin the second part of our hacking overview. There are many different methods of hacking, many different people who hack and many different reasons for the hacks. We are firstly going to look at common methods of hacking.

    First, there are many different ways to hack and get access to secure information, some may be simpler than others, but generally, they can all be just as successful and useful as all the others, about 99.999999999% of the time you will HAVE to combine more than one of these methods during a hacking session to successfully complete the hack.

    • SQL Attacks
    An SQL attack is the method where a hacker will breach the login form by accessing the data in the SQL database of the website, and searching through row and column names, will eventually discover a user password, preferably an Admin password. This method is more commonly used with the Information_Schema command, but it all depends how the webmaster has the set up his login site.

    • LFI / RFI
    An LFI or RFI (Local File Intrusion / Remote File Intrusion) is when a hacker locally or remotely adds a dangerous script into a server, website, etc and therefore gains control to login info, sensitive info, access to all files, etc.

    • Social Engineering
    Social Engineering is all about making other people give you the information you need, normally, a hacker will phone in posing as a employee who has forgotten his login details or needing confidential information  immediately, he then gets the other person to give him the information, allowing the hacker access on to the system. Social engineering has become increasingly popular as it saves time and resources.

    • Brute-Force
    Brute force is a method of password cracking, when a hacker does a brute force attack, he runs a program that tests multiple passwords and encryption types until the password has been cracked. The problem with brute force is the amount of combinations available and the amount of time it can potentially require to crack the encryption.

    • Rainbow Cracking
    Rainbow cracking uses rainbow tables to crack passwords, rainbow tables are lists of code with every available combination of a certain encryption, rainbow cracking is much quicker and effective, although creating your own tables is very time consuming and rainbow table files are very large files. You can purchase rainbow tables online as well.

    • Dictionary Crack
    Dictionary crack is used when the hacker at least knows that the password is an actual existing word, the hacker then runs a program which tests a whole list of words in reference to the password, if the password is an actual word, this is a very quick and effective method.

    There are many many more methods and I will go into most of them in more detail in later blogs, but here are a few common methods.

    Another quick add-in before I end off today's post is anonymity, anonymity is making sure nobody knows who you are, this is very important in the hacking world as hacking is illegal, if you are an expert, you can build scripts to delete the log files, but there are multiple problems to this approach, the best method is to not even be logged on the site, to stay anonymous, you can hack through a proxy server, hiding your actual IP, this method works great if you understand which proxy servers you should be using. The next best thing is to use the TOR web browser, TOR is an anonymous web browser, which disguises your true IP address and also does not allow sites to store cookies or other personal information.

    To get TOR visit:
    https://www.torproject.org/download/download-easy.html.en

    Thanks.

    Techno Master

    Monday, June 27, 2011

    A brief overview of hacking - Part 1

    So to start off I will start by giving an overview of what hacking is, the oxford dictionary defines a hacker as: ' a person who uses computers to gain unauthorized access to data. informal - an enthusiastic and skillful computer programmer or user.'  The rest of the world probably has a total different thought about the subject, but do people actually realise all the good hackers do for the rest of humanity...No, the world just looks at the 'evils' of hackers, although most hackers have never done a single malicious hack. A hacker is just a person who has found a world where he/she can just be themselves, hackers respect each other irrespective of race, gender, status, nationality, etc. we are all equals, and will all help one another when we are struggling.

    Lets look at all the good hackers have done for the rest of humankind:
    • Hackers debug software before other internet users download it, therefore creating a more stable computing environment
    • Hackers delete companies' spam lists, stopping even more spam swamping your inbox
    • Hackers also help stop viruses from swarming the internet
    • Hackers also help debug most of your favourite websites
    Infact most of the sites you visit daily were created by a hacker or a group of hackers, Facebook was developed by a very talented hacker named Mark Zuckerberg, Google was created by 2 hackers named Sergey Brin and Larry Page, there are many more - you can go and research them if you would like.

    So there is the end of part 1, part 2 soon to follow.


    Peace Out

    Techno Master
     
    Back To Top