Many people fear them, but most hackers are no more than simple point and click operators (the basic script kiddie) that are incapable of anything but using tools created by others.
Like any other software developer, those who do create the tools being used by the script kiddies are not immune to coding errors and poor development practices. In a presentation at RSA 2008 by BitSec researcher Joel Eriksson, demonstrated a practical example where a 'white hat' hacker was able to utilise weaknesses in a 'black hat' tool in order to counter-hack the attacker's system. Even with updates to the hacker's tool, there were significant weaknesses that remained which allowed Eriksson to continue to access the systems of those who were using the tool actively.
This concept is one that is beginning to gain traction amongst researchers, with a number of Web security experts looking at different methods to identify and potentially attack the system that is launching an attack against a site or local system.
As the techniques in use are not overly complex (they are a lateral application of existing, logical functionality), it will only be a matter of time before there are tools readily available to automate the process of 'reverse-hacking'.
Introducing the ability to identify the source system, even through a network of proxies and local networks, when the attack is underway, is an opportunity that will be extremely valuable for later reconstruction, forensic analysis, and possible prosecution -- once the tools are designed and built.
While the techniques that are being discussed at the moment are focussing on the enumeration and discovery of where and what is launching an attack, it doesn't take much to theorise an active defensive system that neutralises the attack platform.
Although this process is bound to be fraught with legal uncertainty and danger, it poses an ethical problem for the white hat -- do they take the opportunity to neutralise the problem when it is first identified, given that they are now reaching beyond their network perimeter and directly affecting another system (bound to be illegal in most jurisdictions), or do they ignore the capability that they have recently developed, and the attacker continues on without fear of reciprocation?
Even if most researchers do not implement the capability to attack, there will be those who do write tools with such capability and they will be readily available for those who want them.
The techniques being described at the moment are dependent on the attacker's system providing the default responses to queries being made of it. With increased knowledge that reverse probing and attack is possible, the arms race will continue and there will be greater use of response customisation by skilled attackers to redirect attention to innocent systems.
As with most crime, the skilled and careful attacker will continue to evade detection and capture. What is now being looked at is another set of tools to identify and capture the lesser skilled.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Cutting Through the Spin of Recent Vulnerability Disclosures 13 October, 2008 10:53:00
The FUD surrounding the ClickJacking and TCP/IP vulnerabilities has the world seemingly frozen in fear. But once you cut through the spin, the vulnerabilities aren't all that they were made out to be.There are a few highly publicised vulnerabilities at the moment which haven't completely been disclosed and which, it is claimed, could threaten the whole Internet as-we-know-it. Only, when the vulnerabilities are finally disclosed, it seems that the whole incident has been somewhat Chicken Little. - +
PCI app security: Who's guarding the data bank? 13 October, 2008 11:09:00
Compliance strategies for PCI's new application security requirementsWhile Willy Sutton never really said it, the truth is that people rob banks because that is where the money is. Today's criminals don't walk into banks with loaded guns and get-away drivers. Rather they connect from a remote location using a browser and are armed with hacking tools and spyware. - +
Data-center security tools to not overlook 10 October, 2008 11:37:00
With the rise of security suites, it's time to consider some emerging security tools and rethink othersProtecting a corporate data center is like trying to keep an elephant safe from a swarm of flies. Despite your best efforts, bites happen. As the staples of security -- such as firewalls, antivirus software, spam and spyware filters -- come together in suites of products that allow for sophisticated management, there are other security tools either emerging or worth a rethink. - +
IBM, Secret Service, others study identity/cybercrime issues 09 October, 2008 10:09:00
Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking. - +
Strange account management at Amazon 09 October, 2008 09:51:00
A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past.
Sound Alliance Group expands with acquisition of Mess+Noise 14 October, 2008 08:48:00
Sterling Commerce Introduces New Managed File Transfer Capabilities That Cuts Server Change Management Time in Half 14 October, 2008 08:41:00
Acronis True Image 2009 makes protecting home computers easier than ever 13 October, 2008 14:10:00
NetStar Networks Calls Brisbane Home 13 October, 2008 12:01:00
New Verizon Business Managed Service Makes Collaboration Easier 13 October, 2008 10:06:00
|
||
|
||
|
|
||
|
Enterprise Wireless WLAN Security
Learn more about the security challenges to be faced when defining and implementing security mechanisms within diverse wired and wireless network environments. Download this must-read guide to plan your wireless data protection strategy now.














