how you can become a hacker with no security experience

17
How You Can Become a Hacker With No Security Experience Andrei Avădănei President at CCSIR contact@ccsir.org

Upload: avadanei-andrei

Post on 09-Jun-2015

521 views

Category:

Documents


10 download

TRANSCRIPT

Page 1: How you can become a hacker with no security experience

How You Can Become a Hacker With No Security Experience

Andrei Avădănei President at [email protected]

Page 2: How you can become a hacker with no security experience

Summary

● Short Bio● What is a Cyber Hacker● White Hat vs Black Hat Briefly● Examples of Security Bypasses by 1337 Hackers● Why They Matter? ● Are YOU Safe?● Questions & Conclusions

Page 3: How you can become a hacker with no security experience

Short Bio

● President at CCSIR● Founder & Coordinator of DefCamp● Coordinator of Sparks● Ambassador of Talks by Softbinator● Blogger @worldit.info

Page 4: How you can become a hacker with no security experience

What is a Cyber Hacker

● seeks and exploits weaknesses in IT infrastructures● motivated by profit, protest, or challenge● computer programmers argues that they should be called

crackers● security culture is often referred to underground hacking

Page 5: How you can become a hacker with no security experience

White Hat vs Black Hat

● white-hat breaks security for non-malicious reasons

● black-hat violate computer security for personal benefits BUT

- no phishing/spam/credit card stealling ... ● grey-hat may surf the net in order to find and report bugs

● 1337 hackers use various tools to steal or destroy

Page 6: How you can become a hacker with no security experience

#1 Password Reset Services

● What is Your Mother's Name?

● Where is Your Birthday Place?

● Your Favorite Movie?

● Your Loved One?

Yeah, this still works. Don't believe me?

Page 7: How you can become a hacker with no security experience

But Now?

Page 8: How you can become a hacker with no security experience

#2 Phishing & Scams

Page 9: How you can become a hacker with no security experience

#3 Malware

● Tons of Malware Kits free or cheap● Tons of FUD Crypters for AV bypass● Tons of Spreading Methods● Citadel, Zeus, Blackhole Means Something?● 1337++

Page 10: How you can become a hacker with no security experience
Page 11: How you can become a hacker with no security experience

#4 Wifi Sniffing

● Be The MAN (in the Middle)● Session Hijacking● Credentials Sniffing● Traffic Alteration● Aircrack-ng sounds friendly to you?● 1338++

Page 12: How you can become a hacker with no security experience
Page 13: How you can become a hacker with no security experience

#5 Hacking Websites

● Free & Easy to use Applications Scanners

● Nmap – old school (but awesome) port scanner

● SQLMap, Havij, Nessus, Acunetix, w3af for web security

● Metasploit – the Honey for Exploitation

● Many more third parties apps based on those above

● + Tons of Others That You Can Discover

● 1339++

Page 14: How you can become a hacker with no security experience

#6 - The Insiders

● Do You Trust Your Gf/Bf? You shouldn't! :-) 1339.1++

Page 15: How you can become a hacker with no security experience

Why They Matter

● these are really simple examples

● most of the „hackers“ of this kind are 14-20

● they are irresponsible, destructive

● you will see private conversation leaked

● if you have a website they will probably deface it

● if somebody is MitM you might have the chance to see some porn

● if your password is guessed you might loose your accounts (Fb, Y!, GM, Tw, Ppl)

● PLEASE TRY THIS AT HOME, NOT ON YOUR „FRIENDS“!

Page 16: How you can become a hacker with no security experience

Are You Safe?

● #1 – Hard to Guess and unrelated answers

● #2 – Don't click on any suspicious stuff

● #3 – Use an AV licensed and updated + forgot Windows

● #4 – VPN Tunnels

● #5 – Firewalls, Code Review, Pentest, Audit

● #6 – Trust nobody, even you + LastPass or others

Page 17: How you can become a hacker with no security experience

Questions?