lunes, 22 de mayo de 2017

How to beat hackers: hire one | MercatorNet | May 22, 2017 |

How to beat hackers: hire one

| MercatorNet | May 22, 2017 |







How to beat hackers: hire one

Some hackers wear white hats.
Georg Thomas | May 22 2017 | comment 



The recent spate of cyber attacks on computer systems across the world shows how some organisations are not doing enough to protect their systems against malicious hackers. The Conversation
But if organisations had engaged the services of an ethical hacker then many of the vulnerabilities on their systems could have been found and fixed, rather than exploited.
There are many instances in which ethical hacking has successfully prevented a potential attack, but because of the sensitive nature of such information, few cases are made public. This anonymised example highlights the type of issues that can be uncovered by an ethical hacker, which can then be addressed by the client.
Putting on your hacker hat
There are typically three types of hacker: “black hat”, “grey hat” and “white hat”.
Three types of hacker: Black hat, grey hat and white hat. Shutterstock/MatiasDelCarmine
Black hat hackers are typically malicious; they operate illegally and attempt to breach or bypass security controls. Their motivation can be for personal, political or financial gain, or simply to cause havoc.
Grey hat hackers also try to find vulnerabilities in an organisation, and may then alert the organisation or publish the vulnerability.
Grey hats can sometimes sell the vulnerabilities to government or law-enforcement agencies, who may use them for questionable means in conflict or enforcement. The activities of a grey hat are not only questionable, but also seen as illegal because they are not given permission to conduct their operations.
White hat hackers use the same tools and techniques as their black and grey hat counterparts, but they are engaged and paid by organisations to find vulnerabilities. That’s why they are known as ethical hackers.
A contract and non-disclosure agreement (NDA) is usually signed between the ethical hacker and the organisation. This ensures that what they are doing is legal and that both parties are protected.
The ethical hack-attack
Ethical hackers will typically follow a phased approach to conducting their tests. Depending on their methods, this will usually begin with a reconnaissance phase in which information is gathered and potential target systems are identified.
From there the computer network will be scanned (externally, internally or both, depending on the engagement) to examine it in more depth so as to identify any known vulnerabilities.
If vulnerabilities are found, an attempt to exploit them may follow, and ultimately access may be gained. An ethical hacker would also attempt to break into system that don’t necessarily have a known vulnerability, but are simply exposed.
Ethical hackers will then document their work and capture evidence to report back to the client. Hopefully they will find any vulnerabilities first, before they are exploited by others with less beneficent aims.
Becoming an ethical hacker
Ethical hackers gain their skills mainly through experience.
There are also many courses and certifications that teach ethical hacking, including the CREST Certified TesterEC-Councils Certified Ethical HackerGIAC Penetration Tester and Offensive Security Certified Professional
But these courses can’t teach everything. Organisations can differ vastly from one another, and the way to penetration-test each organisation is different and by no means prescriptive.
A good ethical hacker requires a great deal of skill and experience, not just the ability to blindly run a tool or script (also known as “script kiddie”).
Ethical hackers, like any other hacker, may also venture into the dark web to gain intelligence and learn about new exploits.
Asking for trouble
One of the frustrations over this month’s ransomware attack on Microsoft’s Windows systems is that the software giant had already issued a patch in March, to protect PCs from this type of attack.
Despite the warnings, several organisations had not installed the patch, and others were running old Windows XP systems that Microsoft stopped supporting back in 2014. Windows 2003 systems were also vulnerable, having been unsupported since 2015.
This left these systems open to attack by ransomware known by a variety of names, including WannaCrypt and WannaCry. It encrypts files on infected systems, requiring a ransom for their unencryption.
Wana Decrypt0r 2.0 Ransomware Screen. Avast
Another attack
It has now been revealed that the same vulnerabilities that allowed this ransomware to infect systems has allowed the spread of a new threat, the Adylkuzz Cryptocurrency Mining Malware.
This ransomware is thought to have gone largely undetected until now because it isn’t destructive. Instead, it mines a cryptocurrency called Monero, which can generate income for the attackers.
Both outbreaks highlight the importance of practising diligent security and making sure that unsupported systems are upgraded or decommissioned.
The majority of advice so far has focused on appropriate defences such as the Australian Signals Directorate’s Essential Eight. This covers issues such as patching, application white-listing, appropriate firewall configuration, and using vendor-supported platforms.
But having a vigilant IT department that follows such guidance may not be enough.
Some focus should be given to how an ethical hacker can be used to help protect organisations against malicious attacks.
More than just an IT check
This approach to using an ethical hacker differs from the traditional internal IT team approach, as the focus is shifted from a defensive to an offensive mindset.
While the importance of solid defences can’t be understated, augmenting this with ethical hacking can greatly increase the resilience of an organisation’s networks. This approach tests the effectiveness of the controls in place and may identify previously unknown exposures.
But this approach is fairly limited to organisations. Engaging the services of an ethical hacker can cost tens of thousands of dollars, depending on the size of the job.
A typical home user would not have the resources to hire such help. In that case, adequate security controls and awareness would still be the best way to stop many attacks.
Microsoft’s Windows 10, for example, installs updates automatically, which can’t be deferred like previous versions. Windows 8 and 10 also come with Windows Defender pre-installed.
People should also make sure not to open suspicious emails, including those from unknown recipients. This will go a long way towards preventing infection.
The future of hack attacks
Telstra’s latest security report says that 59.6% of future potential attacks in Asia and 52.6% in Australia will be due to external hackers. These attackers will use vulnerabilities (known or unknown) to carry out their attacks.
So there is merit in further research to determine how an ethical hacker can help organisations prevent attacks and infections from unknown vulnerabilities. The ability for a penetration test to identify vulnerabilities in advance before software vendors are aware and can release any patches would be invaluable.
But there are certain ethical issues that need to be considered, given that an ethical hacker often needs to use questionable means, such as through the dark web. There is a fine line between what constitutes an ethical approach and an unethical one.
Georg Thomas, PhD candidate in information technology, Charles Sturt University. This article was originally published on The Conversation. Read the original article.
- See more at: https://www.mercatornet.com/connecting/view/how-to-beat-hackers-hire-one/19834#sthash.ynkyNPlB.dpuf



MercatorNet

May 22, 2017

Our Deputy Editor, Carolyn Moynihan, is not an “I told you so” sort of person, even when the back end of our website malfunctions, which happens, always at the worst time.
But it is uncanny that on Friday she highlighted two feminist philosophers from Norway and Sweden who argue that the one-mum-one-dad-and-kids model of the family deserves no special credit, recognition or social support. They want to split the nuclear family into atomic individuals.
This sounds like the sort of loopy theory that comes from living indoors too long during the winter.
Today Carolyn refrains from crowing “I told you so”, but she has every right to. She reports on a family group in New Zealand which has had to go to court to prove that the family does deserve a special moral status. A government agency is arguing that lobbying for the “traditional family” is of no benefit to society. Nordic loopiness has crossed the equator and swum very far south. It’s a very interesting read


Michael Cook 
Editor 
MERCATORNET



Could ‘flushing’ fallopian tubes displace IVF?
By Michael Cook
A new study of a century-old technique shows that it might be more effective than IVF
Read the full article
 
Trump dramatically expands defunding of abortion abroad
By Jonathan Abbamonte
'Protecting Life in Global Health Assistance' does exactly what it says.
Read the full article
 
Promoting the traditional family is ‘not charitable,’ NZ group told
By Carolyn Moynihan
A government appointed board pursues its own agenda.
Read the full article
 
How to beat hackers: hire one
By Georg Thomas
Some hackers wear white hats.
Read the full article
 
Do suicides increase where euthanasia is legal?
By Margaret Somerville
The statistics suggest that the answer is yes
Read the full article
 
Canada: different, yet similar
By Marcus Roberts
Its demographic trends mirror those elsewhere in the Western world.
Read the full article
 
Are we making the family too special for our own good?
By Carolyn Moynihan
Two women philosophers think so, despite evidence to the contrary.
Read the full article
 
Doctors will have to lie on euthanasia death certificates
By Paul Russell
A bill for assisted suicide and euthanasia is evolving in the Australian state of Victoria
Read the full article
 
Scrounging for money: how the world’s great writers made a living
By Camilla Nelson
Suffering for their art.
Read the full article
 
Pluralism: to differ without deferring
By Andrew Bennett
“Democracy has many merits, but it does not determine the truth.”
Read the full article
 
The embryo orphanage: a cautionary tale
By Ana Maria Dumitru
Orphan farming for the Greater Good.
Read the full article
 
Cultivating a sense of wonder in children
By Helena Adeloju
Parents can do a lot through the events of daily life.
Read the full article



MERCATORNET | New Media Foundation 
Suite 12A, Level 2, 5 George Street, North Strathfied NSW 2137, Australia 

Designed by elleston

No hay comentarios: