I feel guilty for people who make fun of
Hacking by saying "I can hack you're
facebook, Now bow before
me!" (Seriously?? )
2) I feel bad for people who can't
differentiate between Hacking and
Cracking
3) I feel hatred for people who can't tell
the difference between a Hacker and a
Penetration Tester
4) Last but not the least, I feel awful for
people who call themselves "Certified/
Professional Ethical or Black hat Hacker"
after hacking a Facebook account, A weak
WEP Key and atlast opening a Blog with the
title "An Ethical Hackers Blog"
Here's something for the people I
mentioned above:
Spoiler Click to Hide
These are just the few of my large list of
reasons due to which I created this post but
before I continue please keep in mind that I
will be writing some stuff that might seem
offending to you but it isn't because this
thread is for awareness.
Here's what we are going to discuss:
1) Who is a " Hacker" ?
2) List of things that are "NOT " Hacking
3) Difference between Hacking and Cracking
4) Actual and Real time Hacking
5) Difference between an Hacker and a
Penetration Tester
6) Challenge
1) Who is a Hacker and What is
Hacking??
A Hacker is a person who specializes in
computer security, Discovers and Exploits
the vulnerabilities found using his own set
of particular skill, tools and knowledge. A
hacker might do such thing for his own
purpose or for money or even as a
challenge. In this era of technology and
cybernet, Many people especially the
government think of Hackers as so called
Criminals . Well the thing that you should
remember is that not all Hackers are
criminals. Hackers have types like Black
Hats, White Hats and Grey Hats. Out of
them Black Hats are considered to be
criminals but in this era people take
Hackers as a potential threat. Well we are
not here to discuss about threat but we are
here to discuss the true meaning of a
Hacker and Hacking.
There are many meanings of a Hacker like
this one from wikipedia:
Code:
A hacker is someone who seeks and
exploits weaknesses in a computer
system or computer network.
Hackers may be motivated by a
multitude of reasons, such as
profit, protest, or challenge.
For us the true definition if a Hacker would
be:
Code:
A person having security analysis
and exploitation skills, able to
exploit vulnerabilities on a
target system by using his own
set of Tools and Exploits
Taking the above definition in view, it
clearly states that a Hacker uses Tools that
he codes and makes Himself . This also
indicates that this person has significant
knowledge in Programming using which he
is able to code his own required tools.
Exploitation itself is not easy as it requires
constant observation for detecting
vulnerabilities and coding an exploit for
them which too requires programming as
well.
The inverse of a Hacker is a Script Kiddie,
uses tools made by others to exploit
vulnerabilities.
Point to Ponder?
Now my question is that "Are you a
Hacker?" Keep thinking about it and you
will figure out
More Deep Stuff
You've noticed that we use tools like Havij,
SQLmap, SQLdumper, Hydra, Orphcrack,
Metasploit etc to Exploit, Crack and Hack
but these tools are built by others. How
come we are Hackers when we use tools
built by others? We should be called Script
Kiddies instead. This is the part where most
of the arguments are carried out, We can't
stop using the word Hacker for ourselves
even if we aren't one. This is not our fault,
this is because the meaning of Hacking is
being taken in the wrong way and off
course the beginners who are eager to do
learn hacking in just a blink of an eye. No!
Thats not even fucking possible! Just as
programming you can't call your self a
professional programmer no matter how
much you do! Same goes with Hacking.Each
and Every day something new gets made
and it is designed in such a manner as to
provide a 99% possibility of being secure.
For that Hackers have to go deep and
study more about it.
We hear news that a Bank got Hacked and
some vicious amount of money was stolen.
It may seem to be easy for n00bies but if
you ask the Hackers who have done it you
will be amazed by the amount of deep work
they had done before carrying out the
attack, They had to find out the main bank
server, tackle their security protocols,
firewalls, IDS etc and for that they had to
find out which type of system they were
using. Then to study deep about that
system, find out a way to tackle it. After
getting pass it, now how to get access to
the main server and stuff like that. And the
most import of the thing is How they stay
Anonymous?
Hahaha, Now after reading the above
paragraph now think again, "Am I a
Hacker?"
Script Kiddie, The wrong part
Now days one can easily be tempted to
anger by saying "You are a Script Kiddie!"
and there goes the fight and argument! The
problem is the same, The meaning of script
kiddie is being a person who has no
knowledge of anything related to the
relevant field. If you read the definition of
Script Kiddie:
Code:
A script kiddie (also known as a
skid or skiddie) is a non-expert
who breaks into computer systems
by using pre-packaged automated
tools written by others, usually
with little understanding of the
underlying concept—hence the term
script (i.e. a prearranged plan
or set of activities) kiddie
(i.e. kid, child—an individual
lacking knowledge and experience,
It states that a Script Kiddie is a non expert
but that doesn't mean he/she has not
knowledge or skill, A script Kiddie has
concepts and knowledge and more of it
than that of a newbie or a n00b . People
sometime get angry when one blames over
knowledge, No one knows anything to a
100% extent so why can't be admit we are
scrip kiddies, I don't see any point or a bad
thing in it because:
1) You know your stuff about hacking,
exploiting etc (N00b's don't)
2) You can use tools (N00bs can't)
3) You have potential (N00bs don't)
4) You have skills to use them (N00bs
don't)
5) You are gaining more knowledge about
your relevant field (N00bs are lazy at this
point and not you)
and so more!
The point was, Don't be angry when called
upon a Script Kiddie, A SK knows much
about his real shit rather than a n00b who
want to learn the damn shit which are done
in years or maybe lifetime, in days. So yeah
there's a 101% difference between a N00b
and a Script Kiddie and remember
Script Kiddie is not a N00b
2) List of things that are NOT Hacking or
even a part of it
People have been merging wrong fields with
Hacking as a part of it. Let me tell you one
thing that Hacking is way out of your
League and by this I mean it's not easy and
it takes a lifetime to become an expert in
this field but n00bs have taken a wrong
turn. They have been considering things on
their own as a part of Hacking. Let me list
some stuff here for your own explanation:
1) Hacking Facebook, Twitter etc accounts,
this is what usually n00bs say but it's
actually Cracking so it isn't Hacking. I will
discuss the difference between Hacking and
Cracking in the next topic
2) Cracking Wifi Passwords is not hacking.
3) Infecting with RAT and get credentials is
not Hacking
4) Gaining access to a target OS using
already made exploits, tools etc is not
Hacking, If you have a problem with this
statement. Read the Hacking definition
again and don't argue as it's the bare truth
and down deep inside you know it
5) Reverse Engineering is not Hacking, It's
Cracking
Add more if you want
3) Difference Between Cracking and
Hacking
Cracking Hacking
Illegal side of
Hacking
Not Illegal but
depends upon in
which manner the
people use it in
Mainly associated
in stealing,
breaking
passwords,
bruteforce
accounts, reverse
engineering
Mainly focuses on
exploiting
vulnerabilities on
target system and
gaining access
Crackers do stuff
for popularity
mainly
Hackers do stuff for
their own purpose
like White Hat's
Black Hats and Grey
Hats
Cracking is true
crime because we
are not taking
permissions here
Ethical Hacking is
legal as it involves
taking permission
on the first basis
4) Real And Actual Hacking Events
One of my favourite hackers from the past
is Kevin Mitnick, they are legendary and
their work is almost perfection. Unless you
read some real time encounter of these
hacker you won't be able to get the true
spirit of hacking and how it's done. Read
this book written my Kevin Mitnick http://
deathmule.nullfile.com/documents/taoi.pdf
You'll be amazed at the end of the book!
5) Difference Between Hacker and
Penetration Tester
I couldn't describe it much easier than this
explanation I found on Wiki:
Code:
According to the EC-Council's
Certified Ethical Hacker course
documentation the two can be
defined as follows;
Penetration Testing:
A goal-oriented project of which
the goal is the trophy and
includes gaining privileged
access by pre-conditional means.
Challenge
If you think you are the greatest Hacker of
all time, then make your computer Hack
Proof!