Hackers
Author
Discussion

DAVE BRENNAND

Original Poster:

220 posts

306 months

Friday 18th March 2005
quotequote all
Hackers,

Do they realy exist in the normal world or are they one in a million?
I would imagine that they must be pretty rare as the whole of Microsoft spend years writing software and de-bugging it only for someone to find a way in soon after.
They cant all be 15 year old geeks sat in their bedrooms eating Pizza and buggering up the internet for fun ... can they?

meeja

8,290 posts

278 months

Friday 18th March 2005
quotequote all
DAVE BRENNAND said:

Do they realy exist in the normal world or are they one in a million?


Oh, they exist alright!

DAVE BRENNAND said:

They cant all be 15 year old geeks sat in their bedrooms eating Pizza and buggering up the internet for fun ... can they?


I'm sure plenty of them are, but organised crime is in on the act these days as well.....

judas

6,238 posts

289 months

Friday 18th March 2005
quotequote all
Hackers =

And yes, most of them are socially retarded teenage scriptkiddies - like the one that hacked our web server after our ISP screwed our firewall. But like most cocky kids he couldn't keep his mouth shut and got caught

JonRB

80,067 posts

302 months

Friday 18th March 2005
quotequote all
If you're going to use a word, understand what it means.

wikipedia said:

Categories of hacker

The hacker community (the set of people who would describe themselves as hackers, or who would be described by others as hackers) falls into at least three partially overlapping categories.

Hacker: Brilliant programmer

The positive usage of hacker. One who knows a (sometimes specified) set of programming interfaces well enough to write software rapidly and expertly. This type of hacker is well-respected, although the term still carries some of the meaning of hack, developing programs without adequate planning. This zugzwang gives freedom and the ability to be creative against methodical careful progress.

At their best, hackers can be very productive. The downside of hacker productivity is often in maintainability, documentation, and completion. Very talented hackers may become bored with a project once they have figured out all of the hard parts, and be unwilling to finish off the "details". This attitude can cause friction in environments where other programmers are expected to pick up the half finished work, decipher the structures and ideas, and bullet-proof the code. In other cases, where a hacker is willing to maintain their own code, a company may be unable to find anyone else who is capable or willing to dig through code to maintain the program if the original programmer moves on to a new job.

Types of hackers in this sense are gurus and wizards. "Guru" implies age and experience, and "wizard" often implies particular expertise in a specific topic, and an almost magical ability to perform hacks no one else understands.


Hacker: Intruder and criminal

The most common usage of "hacker" in the popular press is to describe those who subvert computer security without authorization or indeed, anyone who has been accused of using technology(usually a computer or the internet) for terrorism, vandalism, credit card fraud, identity theft, intellectual property theft, and many other forms of crime. This can mean taking control of a remote computer through a network, or software cracking. This is the pejorative sense of hacker, also called cracker or black-hat hacker or simply "criminal" in order to preserve unambiguity.

There are several recurring tools of the trade used by computer criminals:

* Trojan horse -- These are malicious programs that are disguised as legitimate software. A trojan horse can be used to set up a back door in a computer system so that the criminal can return later and gain access. Viruses that fool a user into downloading and/or executing them by pretending to be useful applications are also sometimes called trojan horses. See also: Dialer.
* Virus -- A virus is a self-replicating program that spreads by inserting copies of itself into other executable code or documents (for a complete definition: see the article about computer viruses). Thus, a computer virus behaves in a way similar to a biological virus, which spreads by inserting itself into living cells.
* Worm -- Like a virus, a worm is also a self-replicating program. The difference between a virus and a worm is that a worm does not attach itself to other code. After the comparison between computer viruses and biological viruses, the obvious comparison here is to a bacterium. Many people conflate the terms "virus" and "worm", using them both to describe any self-propagating program.
* Vulnerability scanner -- A tool used to quickly check computers on a network for known weaknesses. Hackers also use port scanners. These check to see which ports on a specified computer are "open" or available to access the computer. (Note that firewalls defend computers from intruders by limiting access to ports/machines both inbound and outbound.)
* Sniffer -- An application that captures password and other data while it is in transit either within the computer or over the network
* Exploit -- A prepared application that takes advantage of a known weakness.
* Social engineering -- Using manipulation skills in order to obtain some form of information. An example would be asking someone for their password or account possibly over a beer or by posing as someone else.
* Root kit -- A toolkit for hiding the fact that a computer's security has been compromised. Root kits may include replacements for system binaries so that it becomes impossible for the legitimate user to detect the presence of the intruder on the system by looking at process tables.
* Leet -- An English pidgin that helps to obscure hacker discussions and web sites, and paradoxically simplifies the location of resources in public search engines for those who know the language. This is arguably more of a social phenomenon than anything very useful for breaking security, however. To more effectively keep conversations private, encryption can be used.

Those who consider themselves hackers in this sense but who don't write their own programs, and who generally don't really understand the inner workings of the computers they gain access to, are known as script kiddies. The term originates from the idea that no one is born with knowledge of these things, and everyone must at some point use "scripts" to learn. To some however the term expresses considerable contempt, being meant to indicate that they are immature (or unable to realize the equality lesson contained in the somewhat loaded term), and only use "scripts" and programs created by other people, in what is merely simple vandalism (if not outright theft).


Hacker: Security expert

There is a third meaning which is a kind of fusion of the positive and pejorative senses of hacker. The term white hat hacker is often used to describe those who attempt to break into systems or networks in order to help the owners of the system by making them aware of security flaws, or to perform some other altruistic activity. Many such people are employed by computer security companies (such professionals are sometimes called sneakers). Collections of these people are often called Tiger Teams.

White hat hackers often overlap with black hat depending on your perspective. The primary difference is that a white hat hacker claims to observe the hacker ethic. Like black hats, white hats are often intimately familiar with the internal details of security systems, and can delve into obscure machine code when needed to find a solution to a tricky problem without requiring support from a system manufacturer.

An example of a hack: Microsoft Windows ships with the ability to use cryptographic libraries built into the operating system. When shipped overseas this feature becomes nearly useless as the operating system will refuse to load cryptographic libraries that haven't been signed by Microsoft, and Microsoft will not sign a library unless the US Government authorizes it for export. This allows the US Government to maintain some perceived level of control over the use of strong cryptography beyond its borders.

While hunting through the symbol table of a beta release of Windows, a couple of overseas hackers managed to find a second signing key in the Microsoft binaries. That is, without disabling the libraries that are included with Windows (even overseas), these individuals learned of a way to trick the operating system into loading a library that hadn't been signed by Microsoft, thus enabling the functionality which had been lost to non-US users.

Whether this is good or bad may depend on whether you respect the letter of the law, but is considered by some in the computing community to be a white hat type of activity. Some use the term grey hat to describe someone on the borderline between black and white.


(Full article here)

_DeeJay_

5,057 posts

284 months

Friday 18th March 2005
quotequote all
All true. However, the majority of people who compromise computer system security are just 'standing on the shoulders of giants'. i.e. they use scripts and vunerabilities identified by others and just apply them to live systems. These lot are often technically incapable of actually doing anything on their own.

The remaining black and white hats are far less common and generally work for security companies, as been stated previously.

meeja

8,290 posts

278 months

Friday 18th March 2005
quotequote all
judas said:

And yes, most of them are socially retarded teenage scriptkiddies - like the one that hacked our web server after our ISP screwed our firewall. But like most cocky kids he couldn't keep his mouth shut and got caught


Yes, I remember the thread...... has anything further happened on this?

nd75596

109 posts

271 months

Friday 18th March 2005
quotequote all
A company I worked for employed a group of Professional Hackers to test the software (security) they were paid a lot of money. Always struck me a being a bit strange as these people then know all the customers who used the software and any potential security risks in the software.....

bga

8,134 posts

281 months

Friday 18th March 2005
quotequote all
JonRB said:
If you're going to use a word, understand what it means.


wikipedia said:

Hacker: Security expert



This week i is mainly doing this.
Hacking ERP systems, surprisingly easy if you know what you are doing. Even worse if you know what to do when you are in there.

Monkeying about with mail servers 'vs' diverting treasury dept loan sums to your own account

ErnestM

11,621 posts

297 months

Friday 18th March 2005
quotequote all
Forgot:

Hackers: People with high golf handicaps and terrible skills but insist on playing the game.

Hackers: Old gits that smoked too much and insist on coughing after every second word.


ErnestM

judas

6,238 posts

289 months

Friday 18th March 2005
quotequote all
meeja said:

judas said:

And yes, most of them are socially retarded teenage scriptkiddies - like the one that hacked our web server after our ISP screwed our firewall. But like most cocky kids he couldn't keep his mouth shut and got caught



Yes, I remember the thread...... has anything further happened on this?

The kid got suspended for two weeks. We're still waiting to 'interview' him...