Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 39 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Teach me hacking?
EH-Net
May 24, 2013, 08:19:25 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Teach me hacking?  (Read 9734 times)
0 Members and 1 Guest are viewing this topic.
Kev
Sr. Member
****
Offline Offline

Posts: 428


View Profile
« on: October 27, 2007, 10:06:59 PM »

I get asked all the time what is hacking and how do you do it. To someone new it seems so mysterious. Its not really. Think of it this way, we are trying to connect or network with another computer in a new way. A way out of the ordinary. That’s what hacking is all about. Doesn’t matter whether it’s hardware or software. We are taking something beyond what its intended. We are making it do what we want.  We shake it , squeeze it, bend it, whatever it takes to make it happen and we have the ability to  hang in there as long as it takes. We take advantage of over worked and pressured coders that rush a little too fast. Not their faults. They have to or lose their jobs. It’s a rush to the market and they always feel they can patch at another time. Should there be a law that forces coders to write safe and good code?  I hate more restrictions on our freedom, but I also hate getting my identity stolen or my paypal account ripped also because some company was rushing to the market to make a fast buck! 

  If you already know how to network with other boxes you are half way there. Now think outside the box. How can you connect?  How can you force a connection?  Exploit?  Crack password?  Is there something in the network open? Most pen testers like me go for looking for the simple first. Did the admin get lazy? Is there something open?  If not is there something not patched?  Hmm, I cant still get in! Now its time for some creative social engineering.  That’s where most networks fail actually.   People are the weak link. Until we fix that we are all vulnerable.
« Last Edit: October 28, 2007, 10:42:54 AM by Kev » Logged
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 385



View Profile WWW
« Reply #1 on: October 28, 2007, 09:02:02 AM »

Kev I fully agree with this and this is possibly the best explanation of hacking I have heard. Explained in its truest form.

Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
n00b@hacking
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #2 on: October 29, 2007, 01:56:11 AM »

Hey i'm a noob already had the concept of hacking though... i study Computer Science and just started hacking and studying about security about a week ago.

I'm trying to test the security of the webpage of the company where a relative works to start but since i'm a noob i can only use tools Tongue can you tell me where I can get .pm's or exploits for metasploit?? it doesn't have many for linux and i scanned the webpage and it's running apache 2.0.51 over FEDORA so... also it has the unfiltered port for mysql running an old insecure version (according ton nessus Tongue) can you guide me??
Logged
LK
Newbie
*
Offline Offline

Posts: 29


View Profile
« Reply #3 on: October 29, 2007, 02:31:05 AM »

Welcome to Ethical Hacker Network Forum.

What you are trying to do is not just unethical, but it's illegal too.
So if you expect to get some help in doing something unethical, this is not the place to do it.

Maybe you should start over your process of learning how to hack, with the laws you have to obey in order to not get yourself in trouble.

The next step will be setting up a virtual lab and practice there.

« Last Edit: October 29, 2007, 02:37:43 AM by LK » Logged

Security+, OSCP, CISM, CISSP
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #4 on: October 29, 2007, 08:42:50 AM »

Also, depending on what type of security is setup on this web server they may have already seen you and are watching out for you now since you ran a Nessus scan... (lots of traffic).
Logged
sedated
Newbie
*
Offline Offline

Posts: 37



View Profile
« Reply #5 on: October 29, 2007, 09:22:24 AM »

Hey i'm a noob already had the concept of hacking though... i study Computer Science and just started hacking and studying about security about a week ago.

I'm trying to test the security of the webpage of the company where a relative works to start but since i'm a noob i can only use tools Tongue can you tell me where I can get .pm's or exploits for metasploit?? it doesn't have many for linux and i scanned the webpage and it's running apache 2.0.51 over FEDORA so... also it has the unfiltered port for mysql running an old insecure version (according ton nessus Tongue) can you guide me??
   I wouldnt recomend actually pen testing untill you have a solid ethicall foundation.You dont want to get  charged with a computer crime that could possibly harm youre future career as a ethical hacker.Start bye reading everything you can on networks and hacking and then practice at home on a home network. Smiley
Logged
n00b@hacking
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #6 on: October 30, 2007, 04:36:05 PM »

Whoa! you guys really misunderstood me, i am no cracker, my mom is the equivalent of a CIO of the enterprise, there's no one above her in charge of information, data processing etc.  I'm simply trying to see if there are wholes and prove they can be exploited, i've already got the wholes, just don't know what to do with them, i hardly think she'll press charges, think of it as a security assessment... anyways regarding the nessus thing i found a server that keeps no log and has the 8080 port open so i think i did all that analysis anonymously... my question was more about who can guide me in the becoming a hacker process, i've already hacked computers in lan me and a couple of friends are learning the arts of hacking together, this is just an experiment.   
Logged
LK
Newbie
*
Offline Offline

Posts: 29


View Profile
« Reply #7 on: October 30, 2007, 05:36:11 PM »

It's a good thing that you are trying to learn how to hack, but my advice is to do this in a test/virtual environment or in a LAN that is just for testing purposes (of course, that LAN has to be yours or you should have the written approval of the owner).

Messing up with production servers is a dangerous thing, as you said, you are still learning, you don't know what's the impact of your scans to the server.

On the other hand, even if your mother is the CEO of the company, you still shouldn't make a security assessment without having a signed agreement between you and the company - so called Get out of jail card.

Is the Security Officer / IT Manager informed about this? If your mother is the only person that knows about this ... it's just not right, you know?
Do you think that in case that server is compromised while you are doing your assessment, and a forensic analysis is performed, it will be easy for her/you to explain your actions?

Try to keep the learning process in a controlled environment and you will be just fine.

And now to answer your question: try searching this forum, I'm sure that you would find some great books that describe the process of ethical hacking step by step.
Logged

Security+, OSCP, CISM, CISSP
matthiasfan
Newbie
*
Offline Offline

Posts: 25


View Profile
« Reply #8 on: October 31, 2007, 05:53:07 AM »

Yeah, just because your mother is high up, doesn't mean that other people will not get offended for having someone try to hack their system.  If there are IT guys, get with them and create a virtual machine to run at your house to try to hack.  This way no data is corrupted and nothing bad can happen.  Before you start any of this though, make sure you know how a network actually works.  This sounds very "noobish" info, but you should know how it works inside and out.  Once you learn that inside and out, then you can see the security flaws.  Such as when you start understanding about handshakes between computers, you can know how to make them do what YOU want them to.  Do a lot more reading before anything though.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.086 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.