Thursday, August 12, 2004

Hacking in our modern age

Wow, I read a few spooky articles about a tool called the Metasploit Project which was recently demoed at a Black Hat Security conference. This tool makes it a whole lot easier for someone to exploit remote security holes on a number of different types of platforms at the click of a mouse. A tool like this is very useful to system administrators who want to test the security of their own networks, but also makes it much easier for people to hack into remote systems without knowing very much about the complexities of hacking at all. It doesn't expose new vulnerabilities, but does make known ones much easier to exploit. The adventurous should try it on their own systems.
As a side note, computer hacker types are generally grouped into two or sometimes three categories. Black hat hackers are a bit more devious, and probably do things they shouldn't. If they find vulnerabilities in systems they generally keep them quiet and only tell others in the black-hat community. White hat hackers are generally professionals who engage in hacking sort of activities as part of their job (sometimes I fall into this category). Upon finding vulnerabilities they alert the software manufacturer first, and the security community after a certain period of time. Then there are the gray hats, who are somewhere between the two. They announce vulnerabilities to the general public (black-hats, white-hats, and manufacturers) and probably do questionable things from time to time.

2 comments:

davegkugler said...

Cool post, I'll check it out on my machine at home. They'd probably get a little miffed if I tried it here at work. Thanks!

Sam said...

Yeah, no doubt... just don't hack me ;) My firewall will probably keep most things out though....