Session:1
(1)Ethical Hacking
Introduction to Ethical hacking

1:1 Information security overview:


Content
Introduction
Ethical hacking
Hacker's
Types of hacker's
Hacking process
Why do we need ethical hacking
Required skills of an ethical hacker
What do hackers do after hacking
Advantage's
Disadvantage's
Future Enhancements
Conclusion

1.Introduction:
Ethical hacking also known as penetration testing (or) white-hat hacking,involves the same tool,tricks and techniques
that hackers use,but with one major deference that ethical hacking is legal.

2.Ethical hacking:
=>independent computer security                      professional breaking into the                          computer system.

=>Neither damage the target systems                  nor  steal information.


=>Evaluate targets systems security and            report back to owners about the                      vulnerabilities found.

3.Hacker's:
=>A person who uses computers to gain            unauthorized access to data.

=>a person who uses computers to gain            unauthorized access to data.

=>A person who enjoys learning details            about of a programming language's or          systems.

=>A person who enjoys actually doing the        programming rather then just theorizing      about it.

=>A person capable of appreciating some          one else's hacking.


=>A person who pick up programming              quickly.

4.Types of hacking:

*Black-hat hacker's
*White-hat hacker's
*Grey-hat hacker's

1-Black-hat hacker's:
=>A black-hat hacker's or crackers                      individuals with extraordinary                        computing skills,resorting to malicious          or destructive activities.


=>That is black-hat hacker's use their                  knowledge and skill for their own                  personal gains probably  by hurting                others.

2-White-hat hacker's:
=>A white-hat hacker's are those                          individuals professing hacker skills and        using them for defensive purposes.


=>This means that is white-hat hacker's use      their knowledge and skill for the good of      other and for the common good.

3-Grey-hat hacker's:

=>These are individuals who work both            offensively and defensively at various            times.

=>We cannot predict their behavior.


=>Sometimes they use their skills for the          common good while in some other times      he used  them for  their personal gains.

5.Hacking process:

*Foot printing
*Scanning
*Gaining access
*Maintaining access


1-Foot printing:

*Whois lookup
*NS lookup
*IP Lookup

2-Scanning:

*Port scanning
*Network scanning
*Finger printing
*Fire walking

3-Gaining access:

*Password attacks
*Social engineering
*Viruses

4-Maintaining access:

*OS backdoors
*Trojans
*Clear tracks

6.Why do we need ethical hacking:

Protection  from  possible external attacks

*Social engineering
*Automated attacks
*Denial of service (DOS)
*Viruses,Trojan horses and worm's
*Accidental breaches in security
*Organization attacks

7.Required skills of an ethical hacker:

Microsoft: Skills in operation,configuration and management.


Linux: Knowledge of Linux/Unix: Security 
Setting,configurations and services.

Firewalls:configurations,and operation of intrusion detection systems.


8.Required skills of an ethical hacker:

Routers:knowledge of routers routing protocols and access control lists.

Mainframes.

Network protocols:TCP/IP;how they function and can be manipulated.

Project management:leading, 
planning,organizing and controlling a penetration testing team.

9.What do hackers do after hacking:


=>Patch security hole.

***The other hacker's can't intrude***



=>Clear logs and hide themselves.

=>Install root kit (backdoor).

***The hacker who hacked the system can          use the system later***

***It contains Trojan's and virus so on***

=>Install irc related program.
***Identd,irc,bitchx,eggdrop,bnc***

10.What do hackers do after hacking:



=>Install scanner program

***mscan,sscan and nmap***



=>Install exploit program.

=>Install denial of service program.

=>Use all of installed programs silently.

11.Advantage's:

=>"To catch a thief you have to think like a         thief"

=>Helps in closing the open holes in the            systems network.

=>Provides security to banking and                    financial establishments.
=>Prevents website defacement.

=>An evolving technique.

12.Disadvantage's:

=>All depends upon the trustworthiness of      the ethical hacker.

=>Hiring professional is expensive.

13.Future Enhancements:

=>As it an evolving branch the scope of              enhancements in technology is immense.

=>No ethical hacker can ensure the system      security by using the technique                        repeatedly.

=>More enhanced softwares should be              used  for optimum protection.

14.Conclusion:




=>In the preceding section we saw the                methodology of hacking,why should we        aware of hacking and some tools which a      hacker may use.



=>Now we can see what can we do against        hacking or to protect ourselves from              hacking.

=>The first thing we should do is to keep            ourselves updated about those softwares      we and using for official and reliable              sources.

=>Educate the employees and the users            against black-hat hacking.

Write in by MANOJKUMAR

All The Best

By Cyber Ninja
꧁UNDER SCOPE꧂
       -----------------------
Previous
Next Post »