Showing posts with label ethical hacker. Show all posts
Showing posts with label ethical hacker. Show all posts

Friday, 4 April 2008

The Myth of the Ethical Hacker?

Brand Killer Robots reveal::

A hacker is a hacker is a hacker.
If you are a good hacker, then you know more
If you are a bad hacker, then you know less
If you are a loving hacker, then you will empower
If you are a selfish hacker, then you will disrupt
If you are a happy hacker, you swing one way
If you are an unhappy hacker, you swing another
If you are young and naive, you feel this
If you are older and mature, you feel that

When your emotions take hold of you - you begin to hack!

What state of mind will you be in at that time?
What life circumstances will you be in at that time?
What opponent will you be facing?

That will determine your state of ethicality!

How are executives really going to test the ethicality of their hackers?

The Myth of the Ethical Hacker?

Ethical Hacker - or Undercover Spy?

Brand Killer Robots reveal::
Mike owns a penetration testing company. Mike agreed to meet us on condition we discuss our work at one of the countries largest media companies.

So we met him at the pub.

He turned up and he began to enquire about the company we worked for.
He wanted to know which other suppliers we dealt with for penetration testing and whether we had any test reports to show him.

We said nothing - and he left.

We never heard from him again.

Does he sound like an ethical hacker?

Or perhaps, he was just an undercover spy?

Thursday, 31 January 2008

The Competitor Intelligence Counter Threat

Brand Killer Robots reveal::
Hiring hackers to take out a threat from other hackers is nothing new, but what is new is the motivation of the particular hackers in question. From a recent investigation we understand that there are a new breed of computer scientist on the block who deplore the acts of the many criminals, conmen and voyeurs that characterise themselves as international computer hackers. In fact, they despise them so much that they are actively forming companies to defend global corporations from attacks against their infrastructure and their brand.

We recall one particular story where a global consumer brand suffered a multiple attack by hackers hell bent on disrupting the launch of a new pharmaceutical product, on behalf of a foreign competitor (who shall remain nameless).Using a highly targeted series of sophisticated attacks, hackers seized harddisks, laptop computers and encoded transmissions.

Ordinarily, those who have ownership of the systems containing the data are usually the ones empowered by that information.

Thankfully, none of the forementioned was of any use to the competitor company, given the devices had been designed by white hats to be completely useless in the hands of anyone but their true owners. Worse still for the foreign competitor was that they were left with the realisation that the target could defend itself, even when certain confidential assets fell into the hands of others.

This for them, was a new and unwelcome phenomenon and one that they would have to contend with in the future.

Needless to say, it saved the pharmaceutical company from losing many millions of dollars and their R&D data being traded on the black market.

The Competitor Intelligence Counter Threat

Saturday, 26 January 2008

Why have Ethical Hacker Training companies got it so wrong?

Brand Killer Robots reveal::
We ask, just who are the people that you are sending on Ethical hacker training courses and why are you sending them?

Firstly, lets look at what Ethical hacking is all about.

First and foremost Ethical Hacking is about the good guys outsmarting the bad guys, in order to protect your company's computing assets from taking a hit. In other words, the white hats, outhinking the black hats, in order to forsee and/or repel against attacks by criminals.

So lets first look at the white hats.
Profile: Computer Science graduate working in corporate IT for about 5 years say, or network engineer or manager who has been treading the boards for about 10 years.

Ok, now lets look at the black hats.
Profile: Yuan Lopez, 33 from Paraiba, Brazil. (convicted 3 times for purgery, forgery and counterfeiting). Ex bank worker and trader. 2 ex wives, 10 kids and likes a little bit of the white snorty, snorty stuff every now and again.

Ok now, lets look at the Ethical Hacker trainer.
Profile: Ex Network Guru, Programmer, with an arm load of IT security certificates, from here to Amsterdam. Tony also worked for the BBC where he is used to working in high security IT environments (lol). His forte is social engineering, where he tells loads of cool stories about intrusion and deception attacks (as presumeably made up by Kevin Mitnick) and how they are common place and how through analogy you will learn many of the most frequent attack patterns. Of course this analogy is based on limited content, so not particularly creative.

Ok, get the setting?
What we have here are a bunch of IT guys, who are going to protect your company from a corporate desparado, who would just as soon shoot his mother in the head, than go back to prison. This guy has no concept of IT departments, CISSP certificates or brightly coloured ethical hacking training manuals. Once he has a motive and a target, there is absolutely no stopping him and he has a spectrum of villanous alternatives to choose from in order to carry out his attack.

Do you really think that Tony the IT engineer has a cat in hells chance of repelling an attack from a sophisticated, finance-savvy bandit like Mr Juan Lopez. Just how many angles are there to an attack vector anyway? Can you really cover them all?

As we have said in the past, the only reason why your company has never sustained a really serious attack is because you have never really become a targeted.

Until business leaders realise that security is a brand-level, multi-disciplinary, multi-faceted, multi-functional issue of intelligence that needs to be integrated effectively, ethical hacking (as it is called), will remain in the Dark Ages?

What is required are executive-level 'ethical hackers' who have IT, business and real-life experience and who can properly watch the backs of the CEO and the company of the day.

We ask - Why have Ethical Hacker Training companies got it so wrong?