Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 31 guests and 1 member online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
The Mindset of a Cracker
EH-Net
May 25, 2013, 02:17:22 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
The Mindset of a Cracker
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: The Mindset of a Cracker (Read 4630 times)
0 Members and 1 Guest are viewing this topic.
SVXX
Newbie
Offline
Posts: 8
The Mindset of a Cracker
«
on:
December 20, 2011, 02:17:22 AM »
Hello all, this is my first post on the venerated Ethical Hacker network forums. I have loads of questions regarding my future career in security, but I'll research people's posts more and save those for a later time.
I'll get straight to the point. A friend of mine is researching hacking and cracking for a book they're writing, which involves a "tech savvy young boy" (twat, I'd say..) who pulls off one of the biggest financial scams in history....through the help of cracking. I'll directly quote from the email I received -:
"From a basic story point of view the protagonist steals confidential data of high profile clients of a bank and launders money into a third party account by hacking (read : cracking) into the bank accounts of these clients. We have many questions about how he will carry out this crime, what information and expertise will he need etc. Following are some basic questions for you to get an idea of what kind of help we are seeking.
1. Is it possible for anybody to be in a small town far away from the city where the crime is being committed and still pull it off successfully?
2. What is the information that he will need from his accomplice working in that bank?
3. How will he carry out the scam by making sure he is not traced and at the worst his accomplice is accused of the crime?
4. What are the various processes of basic hacking of personal accounts and official accounts of larger consequence?
5. What kind of hardware/software will have to be installed in the bank for them to get the required information?
6. What position will the accomplice hold in the bank to be able to retrieve confidential information for the scam?"
As ridiculous as these questions may sound, I even questioned them whether they're preparing to pull off a financial scam themselves! Jokes apart, I would love to have the views of those experienced in professional security.
PS : Pardon any posting violations that I may have done, 'coz I couldn't think of a suitable forum to post this in. Plus if you think this whole topic is weird, I'm not at fault! Had nowhere else to go to ask.
Logged
3xban
Hero Member
Offline
Posts: 608
Re: The Mindset of a Cracker
«
Reply #1 on:
December 20, 2011, 07:54:40 AM »
There are lots of questions and there are a number of possible answers. I would have your friend research Social Engineering and Phishing. But here is the question, why are you researching and not yoru friend? For a book such as this to be successful, he would best partner up with a security pro who may specialize in financial security environments.
Sorry I can't be more help.
Logged
Certs: GCWN
(@)Dewser
SVXX
Newbie
Offline
Posts: 8
Re: The Mindset of a Cracker
«
Reply #2 on:
December 20, 2011, 08:09:58 AM »
Ah, that is perfectly fine, and I came here looking for security pros!
Actually the whole situation is this - my dad's friend is working on the book, and dad wanted me to participate in this survey of questions but I'd refused....he said, what if I provide you the questions online, can you research for us? And so here I am.
Logged
ajohnson
Recruiters
Hero Member
Offline
Posts: 1060
aka dynamik
Re: The Mindset of a Cracker
«
Reply #3 on:
December 20, 2011, 10:01:01 AM »
I'd tell them to read these at a minimum:
http://www.amazon.com/Art-Deception-Controlling-Element-Security/dp/076454280X/ref=sr_1_2?ie=UTF8&qid=1324396072&sr=8-2
http://www.amazon.com/Art-Intrusion-Exploits-Intruders-Deceivers/dp/0471782661/ref=sr_1_3?ie=UTF8&qid=1324396072&sr=8-3
He has a relatively new book out, but I haven't had a chance to read it yet.
That's going to answer a lot of those questions. I don't think they're in a place to understand anything more technical. If they do, they should check out the Stealing the Network series:
http://www.amazon.com/Stealing-Network-Complete-Collectors-Chapter/dp/159749299X/ref=sr_1_2?s=books&ie=UTF8&qid=1324396407&sr=1-2
It really depends on how technically accurate they want to be. Things like CSI can be extremely popular but are nowhere near technically accurate. The general public doesn't know any better, so how amount of effort they want to invest in this really depends on their market and personal goals. When in doubt, just say the attackers, "buffer-overflowed the server's firewall," and 99.9% of the public would be impressed.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
SVXX
Newbie
Offline
Posts: 8
Re: The Mindset of a Cracker
«
Reply #4 on:
December 20, 2011, 10:42:02 AM »
Thanks a lot dynamik. All this definitely helps
I will pass on this information to dad. If anyone else has their own views, they can still post! Thanks a bunch.
Logged
xXxKrisxXx
Hero Member
Offline
Posts: 512
Re: The Mindset of a Cracker
«
Reply #5 on:
December 20, 2011, 12:56:42 PM »
Hey Svxx,
Welcome aboard. I'll try to offer some light in having a take at the questions! Though I'm not offering all solutions here I want to throw out a few the bad guys would use here in the real world.
1) Definitely possible. Attacks happen all the time anywhere. It all comes down to your targets' security they have implemented but even then, the attackers will always find a way in.
2) Assuming there's an insider, this can contribute a lot to pulling off a successful attack. The insider could provide a listing of the software they run on the banks machines, which could possibly aid in Client-Side Attacks. He could gather up other inside information on employees if needed, he would be able to map out the Network Topology, and this insider could even be used to pull off physical attacks.
3) Being good guys and being given permission to perform audits, I'm not too sure how many of us focus on being, 'untraceable' as much as we try to go un-noticed by IDS/IPS solutions out there. We don't want to send up a red flag. To carry out this type of a scam and attempt to try to be untraceable, an attacker could attempt to compromise a list of target machines and utilize those to pull off the attack. Of course, attacking from a public wifi spot or breaking into a protected network and hacking from that are what bad guys do also. Proxies and proxy-chaining are also useful here. I would imagine these put into use big time when carrying out illegal activity.
4) The attacker could get a hold of the local password hashes on the banking systems and take them offline and attempt to crack them with 3rd party tools. 3xban mentioned phishing, which is another common route attackers use to harvest passwords. These all play a big role. The common process mainly depends on if your doing offline/online password cracking. Will the attacker be attempting a dictionary attack on the ssh or ftp service? A valid username will need to be known. The accomplice could assist in gathering valid usernames of the target infrastructure. If it's offline password cracking, 3rd party tools could be used as mentioned.
5) Hardware key loggers definitely come to mind here. Especially when dealing with obtaining passwords and all sorts of other juicy information. As far as software goes, that could be risky depending on the environment - policies are put in place to attempt to not allow employees from installing software, etc. If the accomplice was able to get a backdoor onto his workstation and let the attacker in and this was discovered, it could be suspected that the accomplice was involved. The accomplice serving as an insider role in the organization could leverage it to the attackers end if an e-mail containing a link to pull off a client-side attack, and the accomplice would be the one to click it to get the attacker on to the network. Of course there's alternatives here.
6) I would say just being an employee would be enough. Of course if the accomplice is one of the IT guys and had more access than the standard employee this would help.
The books dynamik provided will help out. Be sure to give them a read! Good luck with the book.
Logged
eCPPT, GCIH, OSCP, OSWP
3xban
Hero Member
Offline
Posts: 608
Re: The Mindset of a Cracker
«
Reply #6 on:
December 20, 2011, 01:28:09 PM »
Back to my social engineering reference, take a peak at:
http://www.amazon.com/Social-Engineering-Art-Human-Hacking/dp/0470639539/ref=sr_1_1?ie=UTF8&qid=1324408786&sr=8-1
and a story from CSO Online:
http://www.csoonline.com/article/692551/how-to-rob-a-bank-a-social-engineering-walkthrough
I haven't read Human Hacking but it is on my own list of reads and I got to listen to the author speak at a small conference last year in Delaware.
Also a +1 to Dynamik's reading list, all great books to weed through.
Interesting movies to also watch:
Sneakers (out of date but still a good reference, be it fictional)
Firewall - reasoning the big bank keeps its most secure system air gapped from the rest of the environment. So there is something like that to keep in mind.
Also your friend might want to make sure they don't rip off other authors. So its good to know what has already been written.
Logged
Certs: GCWN
(@)Dewser
SVXX
Newbie
Offline
Posts: 8
Re: The Mindset of a Cracker
«
Reply #7 on:
December 21, 2011, 08:32:37 AM »
Thanks a lot y'all. Mailing all this....keep firing if there's more!
@Kris : That deluge of information was extremely helpful! Thanks.
@3xban : Good old phishing and social engineering, plus movies on hacking and caution not to rip other authors off - check! Thanks.
«
Last Edit: December 21, 2011, 08:38:26 AM by SVXX
»
Logged
HDCautism
Newbie
Offline
Posts: 20
Re: The Mindset of a Cracker
«
Reply #8 on:
December 21, 2011, 08:38:31 AM »
wow. this is like the 5th time I've read that subject. Today though, I read it as cracker = snack food. which left a very weird visual image in my mind. I think I need more sleep..
Logged
SVXX
Newbie
Offline
Posts: 8
Re: The Mindset of a Cracker
«
Reply #9 on:
December 21, 2011, 08:47:30 AM »
Herp and derp
xD
Logged
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: The Mindset of a Cracker
«
Reply #10 on:
December 21, 2011, 11:06:48 AM »
You should read "Why Cryptosystems Fail" by Ross Anderson. The article is accessible (not technical) and explains real-world failures in bank security.
Logged
BS in IT, CISSP, MS in IS Management (in progress)
unicityd
Full Member
Offline
Posts: 156
Bored IT Manager, Crypto Nerd
Re: The Mindset of a Cracker
«
Reply #11 on:
December 21, 2011, 01:22:21 PM »
Ross Anderson also wrote about banking security in his book Security Engineering. The banking chapter is available online:
http://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c10.pdf
Logged
BS in IT, CISSP, MS in IS Management (in progress)
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.