eccouncil : 312-50v8 - certified ethical hacker v8

28
ETHICAL HACKING

Upload: shamoon

Post on 30-Dec-2015

54 views

Category:

Documents


1 download

DESCRIPTION

Get all the program details for EC-Council's Certified Ethical Hacking program.http://www.passiteasy.com/eccouncil/312-50v8-exam-quesions-dumps.html - PowerPoint PPT Presentation

TRANSCRIPT

ETHICAL HACKING

HACKER

CONTENT

Overview of Hacking Why do hackers hack? Types of Hacker Level of Hackers Hackers language Ethical Hacking – Process How can protect the system? What should do after hacked? Final words

OVERVIEW OF HACKING

It is Legal

Permission is obtained from the target

Ethical hackers possesses same skills, mindset and tools of a hacker but the attacks are done in a non-destructive manner

Also Called – Attack & Penetration Testing.

HACKING VS CRACKING

Hacker The person who hack

Cracker System intruder/destroyer

HACKING WITH MALICIOUS INTENTION IS CRACKING

The basic difference is hackers do not do anything disastrous.

Cracking yield more devastating results. Cracking is crime. Cyber crime are the results of cracking ,not hacking

THE GREAT HACKER WAR

Kevin Mitnick The most famous, and undoubtedly most gifted hacker in history, made a name for himself in 1981 at the tender age of 17 by getting into a phone exchange, which allowed him to redirect subscriber calls in any way he wanted. In 1983, he achieved his first major coup - and also his first arrest - when he accessed a Pentagon computer. It was his repeated offenses that made him a target of the FBI. He was sentenced to five years in prison in the 1990s, but today he is a security consultant and owns his own company: Mitnick Security.

John Draper known as "Cap'n Crunch", Draper was one of the first hackers in history. This moniker comes from the cereal of the same name, inside of which he once discovered a toy whistle (provided as a gift to entice children to ask parents for the cereal). He discovered that he could use the whistle to hack a telephone line and get free phone calls - all that was necessary was to produce a precise tone in the receiver for the method to work. He was arrested in 1976 and sentenced to two months in prison.

Kevin Poulsen :-The current editor-in-chief of Wired was formerly known for rather different activities. In 1983, when he too was only 17 years old, he made his first intrusions into different networks, resulting in a few run-ins with the US legal system. He continued with his illegal activities until his arrest by the FBI in April 1991. In 1994 he was sentenced to four years in prison.

Adrian Lamo Lamo has certainly driven the highest number of network administrators insane. From Microsoft to Yahoo!, going through Sun Microsystems, MacDonald's, Cingular, AOL or even the New York Times, he is credited with all types of intrusions and corporate security system violations. He has bypassed protections with disconcerting simplicity: during a broadcast of the NBC Nightly News, the host asked him to prove his talents in front of the camera, and he responded by gaining access to the company's internal network in less than five minutes. Today he is an expert in security and enjoys full freedom of movement, after being under the surveillance of US authorities for many years.

WHY DO PEOPLE HACK??

To make security stronger ( Ethical Hacking )

Just for fun

Show off

Hack other systems secretly & Steal important information

WHAT ARE THE VARIOUS QUALITIES A HACKER

SHOULD POSSES

Good coder

well knowledgeable person both hard ware as well as soft ware

Should have knowledge on security system

Trusted person

TYPES OF HACKER

BLACK HAT

HACKER

WHITE HAT

HACKER

GRAYHAT

HACKER

LABEL OF HACKER

CODER

ADMIN

SCRIPT KIDDIN

G

HACKERS LANGUAGE

1 -> i or l

3 -> e

4 -> a

7 -> t

9 -> g

0 -> o

$ -> s

| -> i or

|\| -> n

|\/| -> m

s -> z

z -> s

f -> ph

ph -> f

x -> ck

ck -> x

HACKERS LANGUAGE TRANSLATION

EXAMPLE:- Hacking is good

H4ck||\|g 1$ 900d

HACKING - PROCESS

Foot Printing

Scanning

Gaining Access

Maintaining Access

FOOT PRINTING

Whois Lookup

NS lookup

IP Lookup

SCANNING

Port scanning

Network scanning

Finger Printing

Fire walking

SCANNING

GAINING ACCESS

Password Attacks

Social Engineering

Viruses

MAINTAINING ACCESS

Os BackDoors

Trojans

Clearing tracks

ADVANTAGES & DISADVANTAGES

Advantages Provides security to banking and financial

establishments Prevents website defacements An evolving technique To catch a thief you have to think like a thiefDisadvantages All depends upon the trustworthiness of the

ethical hacker Hiring professionals is expensive.

HOW CAN WE PROTECT THE SYSTEM?

Patch security hole oftenEncrypt important data

Ex) pgp, sshDo not run unused daemonRemove unused programSetup loghost• Backup the system oftenSetup firewallSetup IDS

Ex) snort

WHAT SHOULD DO AFTER HACKED?

Shutdown the system Or turn off the system

Separate the system from network Restore the system with the backup

Or reinstall all programs Connect the system to the network

H4CKING PRONE AREAS

HACKING GROWTH RATE

It is clear from the graph it is increasing day by day.

PLEASE GIVE YOUR SUGGESTIONS AND FEEDBACKS

ANY QUESTION ?

THANK YOU