Friday, 24 July 2009

Group 7 Task 2: Hacking

Group 7:
UMADURGA KALVAKOLANU
BABU ALAPATI
DHARMENDRA BOGIREDDI
VENUMADHAV DUSA
PREETHI ADDLA
SUNITHA RAVI


HACKERS
“Hacker is a term used by some to mean "a clever programmer" and by others,
especially those in popular media, to mean "someone who tries to break into
computer systems.”

The term “hacker” tends to carry a mystique about it that ranges in definition
from anti-social computer genius to malicious virus writer. Thus, modern
hackers as defined in media stories tend to attack networks for identity theft,
to steal credit cards, extort banks , or launch denial-of -service attacks.
Brief definition of hackers A hacker is someone who gains unauthorized access to
a computer system. Many hackers just like the challenge of breaking through a
computer security system but not all hackers are harmless. It must also be said
that not all hackers are bad. Government and huge companies use hackers to
maintain their security systems. People normally confuse hackers with crackers.
While hackers crack the code of passwords to hack into a security system,
crackers crack the code of software to bypass its security mechanisms like
copyright protection etc. Hacking and cracking are two different methods, but
hackers normally possess cracking skills and crackers, hackings skills. Also
note that not all hackers are humans. You also get computerized hackers, but
they are developed by humans of course.
There are basically three types of hackers: Coders, Admins, and
script kiddies. This characterization is based upon overall competence and
ability to compromise computer technology, networks, protocols, and systems.

CODERS
Coders are programmers who have the ability to find unique vulnerabilities in
existing software and to create working exploit codes. These hackers, as a
whole, are not seeking publicity and are rarely part of front-page news
stories. As a result, they are known only to the security community for the
programs they write and the exploits they have uncovered.

Coders are individuals with a deep understanding of the OSI model and the TCP
stack. Coding is more than just a hobby, and they dedicate a great deal of time
and energy to it. They are committed to keeping their technical knowledge and
skills current. Not all coders are malicious. In fact, some are actively
involved in developing technologies that can be used to improve overall network
security, such as hackers from the ISS X-force, the Bind view Razor Team, and
the AXENT SWAT team.

Coders can work independently or through a network of hacking teams that run
exploits from a variety of locations, making it difficult to trace the
activities back to their source. These teams can be developed in Internet Relay
Chat (IRC) channels, in conferences such as DefCon, or in small groups of
computer savvy friends. Often coders create the programs and other members of
the team run them against target networks. This creates a reputation for the
group rather than a single individual.

ADMINS
Admins are far more common than Coders and may have experience with several
operating systems, understand TCP/IP, and know how to exploit several
vulnerabilities. They generally have less depth of knowledge but possibly
greater breadth than Coders. This level of hacker would be part of a security
team in a large organization. Some level of programming or scripting ability is
required. For example, they should be able to port a tool form on flavour of
Unix to another.

A majority of security consultants fall into this group. Admins have worked with
computers for most of their computer careers and understand how they work. They
have an extensive collection of tools, a reliable methodology, and ability, but
they generally rely on other people to identify and code most exploits due t
lack of time to specialize in a particular technology.

Admins like to play with new tools as soon as they come out and are often
beta-testers and part-time developers for freeware and open-source security
tools. They also found as regular contributors to security mailing lists or
post news articles online.

SCRIPT KIDDIES
The lowest and most populated part of the hacker pyramid is the Script kiddie.
Their name comes from the fact that members of this group generally rely on
previously coded scripts and pre-packaged hacking tools downloaded from the
Internet to do their hacking. Script kiddies are usually individuals who are
intrigued by the notion of gaining unauthorized access and a reopen to using
untested pieces of code, especially while others (target networks and users)
are at risk.

For this reason, script kiddies get the least respect but are often the most
annoying and dangerous. Script kiddies can cause big problems against networks
without truly understanding what the scripts do and what the consequences may
be. This combination of irresponsible experimentation and incomplete knowledge
often leads to disaster, such as the unintended loss of information.

Script kiddies do not necessarily have computer related professions. In fact,
given that they are often younger people on the Internet, they may still be in
high school. They run the code they find on the Internet on their office, home,
or school network. Script kiddies are generally precipitants of security mailing
lists, though they may not be regular contributors, and are often vocal in
hacker IRC channels. They spend most of their time surfing the Internet in
search of the latest and greatest automated hacker tools. Curiosity about how
the tools work and what information might be obtained leads to an unauthorized
security breech.

Sunday, 19 July 2009

Group 19 Task 2: Hacking

Group No: 19
Salikuti Sandeepkumar Reddy
Nanada Kishore Sirugumalle
Murali Bhooma


Hacking:
Unauthorised use of computers and network resources is known as hacking. Gaining access to a computer or computer network without legal authorization. The goal of attacker would be complete system control. Firstly hacker attacks easy target and then by hiding his/her traces launches attacks on more secure sites and brings or gains complete control of the system. Hacker gains access to super-user account which allows availability to hide and also maximum access by which we can edit, install, delete or can execute any file in user’s directory.

The term” hacker” originally means a very gifted performer and hacking is defined as one who is proficient in programming a computer or using it; a computer buff. But in recent years by gaining easier access to multiple systems it now has negative implications which mean crackers which mean "One who uses programming skills to gain illegal access to a computer network or file."

There is lot of difference between hackers and crackers. Hackers are people who try to make things and crackers are a person who breaks things. Internet which is today is made by hackers who program or develop websites and they don’t harm them and work others done. But in today’s society hacker is popular in use as a cracker in thought and are using both hacking and cracking as methods of cracking. Hacking is a skill and not a very simple sequence of commands or either a simple operation. Approach of hackers must be changed and adopted depending on obstacles which come across. By harming people, their websites and work crackers get kick but real hackers get kick out of programming, helping and improving web. Crackers break software in order to distribute them for free. They do this to prove that they can do it.

There are different types of hacking:
1. Hacking hidden or password protected pages in a website.
2. Hacking other people's computers while they are online.
3. Hacking company servers to distribute viruses or read important information.

In all the above types in hacking least serious and easy thing is hacking hidden or password protected pages in a website. Although it is illegal some areas are legal. Many tools are available on internet which encourages this practice. When we create our own website the section protect your website will be of our own interest.

Hacking is illegal in most of the countries because it leads to piracy and damage. Damage can be either manually or through viruses. Computer can be made useless by deleting specific files. There are few counties which consider hacking as another advance in computer technology. Even where hacking is considered as legal the company, website or individual is based in country must abide the international rules.

Hackers spread viruses and destroy companies’ computers just for enjoyment. There is no reason for their spreading of viruses and they do merely because to show that they can do. Around the world there are many hacking tournaments every year. During tournaments companies monitor the systems 24 hours. There was a hacker’s challenge recently which lasted for 6 hours. It is easier to hack windows than Linux. And it is easier to hack with Linux as it is designed such that it allows users to issue any commands they want to. Companies’ installs virus filters and firewalls to prevent hackers from breaking into company files.

Saturday, 18 July 2009

Group 13 Task 2: Hacking

Group 13
Anil Kumar Bheema
Venkata Ramana Chennoju


Computer Misuse
The Computer Misuse Act 1990 was designed to deter hackers -- see Ayres (1999).
There are several types of offence covered by this act, including:
• Hacking- breaking into computer systems without authorization
• Cracking- breaking or removing copy-protection on software
• Phreaking- exploring communications (telephone) networks to gain free access, calls or information. But with all computer misuse, the general rule is that prevention is better than cure--secure computer systems, passwords and cryptography provide a better solution than after-the-event laws and punishments, which should be considered only as a last resort.

Computer Crime and Legislation
Where the Internet is concerned, legislation is often the weakest form of protection. Since international boundaries are relatively meaningless, there are difficulties in defining the jurisdiction of courts.

What is Hacking?
Hacking is unauthorized use of computer and network resources. Hacking is a felony in the United States and most other countries. When it is done by request and under a contract between an ethical hacker and an organization, it's OK. The key difference is that the ethical hacker has authorization to probe the target.

According to the Computer Crime Research Center, They said we work with IBM Consulting and its customers to design and execute thorough evaluations of their computer and network security. Depending on the evaluation they request which ranges from Web server probes to all-out attacks, we gather as much information as they can about the target from publicly available sources. As we learn more about the target, its subsidiaries and network connectivity, we begin to probe for weaknesses.

Examples of weaknesses:
Includes poor configuration of Web servers, old or unpatched software, disabled security controls, and poorly chosen or default passwords. As we find and exploit vulnerabilities, we document if and how we gained access, as well as if anyone at the organization noticed. In nearly all the cases, the Information Systems department is not informed of these planned attacks. Then we work with the customer to address the issues we've discovered.

The number of really gifted hackers in the world is very small, but there are lots of wannabes.... When we do an ethical hack, we could be holding the keys to that company once we gain access. It's too great a risk for our customers to be put in a compromising position. With access to so many systems and so much information, the temptation for a former hacker could be too great -- like a kid in an unattended candy store.

Types of Hacking

• Inside Jobs - Most security breaches originate inside the network that is under attack. Inside jobs include stealing passwords which hackers then use or sell, performing industrial espionage, causing harm as disgruntled employees, or committing simple misuse. Sound policy enforcement and observant employees who guard their passwords and PCs can thwart many of these security breaches.
• Rogue Access Points - Rogue access points (APs) are unsecured wireless access points that outsiders can easily breech. Local hackers often advertise rogue APs to each other. Rogue APs are most often connected by well-meaning but ignorant employees.
• Back Doors - Hackers can gain access to a network by exploiting back doors administrative shortcuts, configuration errors, easily deciphered passwords, and unsecured dial-ups. With the aid of computerized searchers (bots), hackers can probably find any weakness in your network.
• Viruses and Worms - Viruses and worms are self-replicating programs or code fragments that attach themselves to other programs (viruses) or machines (worms). Both viruses and worms attempt to shut down networks by flooding them with massive amounts of bogus traffic, usually through e-mail.
• Trojan Horses - Trojan horses, which are attached to other programs, are the leading cause of all break-ins. When a user downloads and activates a Trojan horse, the hacked software (SW) kicks off a virus, password gobbler, or remote-control SW that gives the hacker control of the PC.
• Denial of Service - DoS attacks give hackers a way to bring down a network without gaining internal access. DoS attacks work by flooding the access routers with bogus traffic (which can be e-mail or Transmission Control Protocol, TCP, packets).
Distributed DoSs (DDoS5) is coordinated DoS attacks from multiple sources. A DDoS is more difficult to block because it uses multiple, changing, source IP addresses.
• Anarchists, Crackers, and Kiddies - Who are these people, and why are they attacking network?
- Anarchists are people who just like to break stuff. They usually exploit any target of opportunity.
- Crackers are hobbyists or professionals who break passwords and develop Trojan horses or other SW (called warez). They either use the SW themselves (for bragging rights) or sell it for profit.
- Script kiddies are hacker wannabes. They have no real hacker skills, so they buy or download warez, which they launch.
Other attackers include disgruntled employees, terrorists, political operatives, or anyone else who feels slighted, exploited, ripped off, or unloved.
• Sniffing and Spoofing - Sniffing refers to the act of intercepting TCP packets. This interception can happen through simple eavesdropping or something more sinister. Spoofing is the act of sending an illegitimate packet with an expected acknowledgment (ACK), which a hacker can guess, predict, or obtain by snooping.

Hacker?
The term “hacker” can also mean just someone who programs in a particular way, or who just enjoys tinkering with computers; in some circles I'd describe myself as a hacker, though I don't attempt to break into computer systems (except my own!). Many hackers have campaigned for the term “cracker” to be used universally for anyone involved in illegitimate activity involving computers. I list the terms as above since that's how the Computer Misuse Act defined them.
There are three types of hackers
- White hat
- Grey hat
- Black hat
White hat hacker:
It finds a fault in a security system i.e. a website then they will inform the owner immediately.
Grey hat hacker:
It finds a fault he will do what he feels like at the time i.e. exploiting the site OR informing the owner.
Black hat hacker:
If they find a fault will immediately exploit the site for their own beneficial gain i.e. advertising and infecting other computers with "viruses" to gain access to more sites.
So a hacker can be many things from protecting systems by informing the owners or Exploiting and stealing data. The most common name for the destructive type of "hacker" is a "cracker" I always tries to refer to a bad hacker as a cracker to avoid confusion.

Ethical Issues of the Internet Revolution:
Society currently understands hacking to be a form of unlawful behavior and a medium for creative innovation. Hacking has become an activity that holds two positions and is therefore both solemnized for its insightful inventiveness and defamed for its devious acts.

The ethics behind hacking and the actions taken by hackers constitute a philosophical manifest that transcends our understanding of this art. Hackers argue that actions promote a means for tighter security by way of detecting flaws and patches for systems and software. However, these very actions are viewed as violations of rights to privacy and security for both individuals and organizations. Consequently, this establishes a cautionary attitude toward ethical issues such as, privacy, security and the future of the World Wide Web.

In order to comprehend the ethical and the moral principles underling the meaning of hacking one has to understand has t the roof f hacking. In hackers the heroes of the computer revolution, Steven levy traces the root of hacking to MIT in the late 1950s, where students devoted much time and effort to building and programming MIT’s early mainframes. These programmers, who later became known as “Hackers” produced and debugged computer code at an astonishing rate.

They developed hardware and software for existing computer functions and invented novel applications and algorithms that were later incorporated into subsequent generations of computers. The code written by hackers came to symbolize their freedom and their love for programming, which was distributed freely across bulletin board systems(BBS) and cross the unconquered terrain of the internet. Eventually, this freedom of code gave rise to the concept that software should be free.

Another argument supported by the hacker ethic s that break-ins elucidate security problems to those who can do something about them. Hacker instructions into systems surpass the traditional systems surpass the traditional understanding of violating the laws of trespassing. Hacking involves the exploitation, or as discussed by members of the computer hacker underground, the manipulation of a bug, or a backdoor that is inherently present within the system. Emmanuel Goldstein, editor of 2600, a magazine recognized as the "Hacker's quarterly," states, "Hackers have become scapegoats. We discover the gaping holes in the system and then get blamed for the flaws". This statement suggests that cracking down on hacking activity is simply a way of putting blame on the messenger. In this view, hacking is not a threat against the integrity of the system being exploited, but instead is a means of implementing corrections and enforcing tighter security.

The ethical stand supporting hacker activities are proven by this discussion to be mainly unethical. Even though hacking undoubtedly has led to productive improvement in computers and software security, it has in effect created many disruptive problems online and offline. Hacking is an activity that introduces a method of analysis that targets and works on various components. Hacking has the potential to cause harm and to violate legitimate privacy and property rights. By ethical standards hacking does introduce crucial security fixes, but does so at the expense of violating privacy and the security of individuals. Furthermore, hacking activities lead to disruptive and dangerous problems for society, which tend to be difficult to eradicate.

Friday, 17 July 2009

Group 29 Task 2: Hacking

Group 29:
Kishore Kumar Motapothula
Suresh Krishna Bandi


Computer hacking is the practice of modifying computer hardware and software to accomplish a goal outside of the creators original purpose. People who engage in computer hacking activities are often called hackers. A hacker who breaks into systems primarily to steal is not regarded as computer expert.

A hacker within the professional world of computing is regarded as a professional computing world, a hacker can be computer and network security expert. A hacker can also be a highly skilled software programmer or a hardware modifier. Computer hacking is most common among teenagers and young adults. Many hackers are true technology buffs who enjoy learning more about how computers work and consider computer hacking an art form. They often enjoy programming and have expert-level skills in one particular program. For these individuals, computer hacking is a real life application of their problem solving skills. A large number of hackers are self-taught prodigies; even some corporations actually employ computer hackers as part of their technical support staff. These individuals use their skills to find flaws in the company's security system so that they can be repaired quickly.

Wednesday, 15 July 2009

Group 10 Task 2: Hacking

Group 10:
VENU SALLA
KIRANKUMAR YAMA
VISHALMURTHY PILLI
PAVANKUMAR ANUPA
BRAMHANANDASWAMY MINUMALA



DEFINITION:
HACKING: Hacker is an expression which has the specified degree of importance. A clever programmer who attempts to break in to computer systems, a person who
may be expert or any in computer programmer who having the ability to create
complex software and hardware.

DESCRIPTION:
Unlike most other computer crime areas which are clear cut in term of acts and
legalities. Computer hacking involves some of the degree of violation on the
privacy of other or damage to computer based property such as files, WebPages
or software. The impact of computer hacking varies from simply being enveloping
bothersome to illegal.

Example: Ways to minimize potential for Hacking in schools:
There are a number of ways for schools to minimize potential for hacking.

1. Schools need to clearly establish good enough use policies and explain
appropriate and inappropriate actions to both students and staff.
2. Students and staff need to instructed regarding hacking, the mentality
associated with it, the consequences of various hacking actions and possible
consequences of interacting and forming online relationships with anonymous
individuals who claim to be proficient in invading others' privacy.
3. The use of filters may be considered in reducing access to unauthorized
software serial numbers and hacking-related materials, newsgroups, chat rooms
and hacking organizations.
4. Teachers need to be aware of student activities in the computer labs and pay
special attention to things they hear in terms of hacking behavior.


Types of Hacking:

There are different types of hackers named differently according to names
given by the hackers own slang (also known as jargon). Generally hackers can be
divided in to three classes such as groups or even schools.

1. Black hat hackers.

2. Grey or brown hat hackers.

3. White hat hackers.

1. Black-hat hackers (also known as crackers) are the ones who write virus,
destroy data, and deface websites along with other illegal activity. This type
of hacker will not end up at a very good job due to a bad reputation, and
usually ends up in jail for a long period of time. This kind of hacker is not
welcome at HDNL.


2. Grey-hat hackers are borderline white/black hats. They sometimes prank
unsuspecting users and cause general mayhem. While they think this kind of
activity is harmless, they may face long periods of jail time, and rejection
from the hacker community. We do not approve of this kind of hacker at HDNL.


3. White-hat hackers are the Jedi-knights of hacking, using their knowledge for
good, and usually end up working as high-paid network administration,
programmers, and security consultants. When a software bug is found, the
white-hat community will work together to solve the problem. This kind of
hacker is the most respected in the internet community, and this type of hacker
is welcome at HDNL.

Hacker ethic principles:

The general view or principles of hacker ethic include:

1. Sharing.
2. Openness.
3. Decentralization.
4. Free access to computers.
5. World Improvement.

Hacking examples:
1. New York Times: pornographic material together with this message placed on
their web server

2. Raphael Gray, teenage hacker from Wales
– Broke into several online stores
– Stole thousands of credit card numbers
– Alleged to have: Published the numbers on the Internet
- Despatched a shipment of Viagra to Bill Gates using one of the stolen
card numbers.


Issues:
A number of issues arise in considering hacking from the educator perspective.
First, we need to consider the fact that the public perception of hackers is
mixed, and that "hacking" and "being considered a hacker" can be quite
appealing to students who are going through developmental periods in which they
are defining themselves, as well as challenging authority and rules. There is
often a 'Robin Hood' mentality to early actions, though it is unclear exactly who
"the poor" are, and how they are "being compensated". Second, the anonymity of
actions which hackers perform against others often enhances the severity of
actions. For example, an adolescent who would never consider picking someone's
pocket or physically damaging someone else's property or home, might be quite
willing to steal people's credit card numbers or destroy poorly protected
business or government files, since files and credit card numbers are not
tangible entities, and the damage is done anonymously.

Sunday, 12 July 2009

Task 3: Downloading Music

In your groups discuss and reflect on the Ethical issues surounding 'Storing Copyrighted Music' - see the scenario below...


The Issue

Do you store copyrighted music on your PC or work’s server? Do you 'share' music files using your work’s facilities? If you do, then, watch out! Your work could be in some real legal hot water! Plenty of unwanted negative publicity too!

People and File Sharing
We all like music. Retail music is a multi-billion pound/dollar industry. Do you think for a minute that a recording company is going to give its product away? Not likely. Yet that's the essence of the music file sharing craze. People can download their favorite songs from thousands of sites on the Web. Are the copies which they are downloading stolen? Most people don't care.

Task discussion...What are your thoughts on downloading music?
What are the illegal implications connected with doing so?
What ethical issues arise from doing this?

Group 8 Task 2: Hacking

Group 8Kapil Giri
Naveen Reddy
Gurumurthy Batharaju
Muninder Adavelly
Vishnu Chitta
Mohammad Hussain


Hacking is defined in various ways associated with Information Technology.
1. Hacking is an act of access to the computer and network with out the endorsement supposed to be seeked.
2. Always there is a human tendency of learning new things, as part of this a person tries to gain the hidden knowledge without authorisation.

The person who performs the act of hacking is called a ‘Hacker’. The methods hackers use to attack your machine or network are fairly simple. A hacker scans for vulnerable systems by using a demon dialer (which will redial a number repeatedly until a connection is made) or a wardialer (an application that uses a modem to dial thousands of random phone numbers to find another modem connected to a computer).

Another approach used to target computers with persistent connections, such as DSL or cable connections, employs a scanner program that sequentially "pings" IP addresses of networked systems to see if the system is up and running. Where can a hacker find such tools? On the Internet, of course. Sites containing dozens of free, relatively easy-to-use hacking tools available for download are easy to find on the Net. While understanding how these tools work is not always easy, many files include home grown documentation written in hacker shoptalk.

Among the programs available are scanning utilities that reveal the vulnerabilities on a computer or network and sniffing programs that let hackers spy on data passing between machines.

Hackers also use the Net to share lists of vulnerable IP addresses--the unique location of Internet-connected computers with unpatched security holes. Addresses of computers that have already been loaded with a Trojan horse are available for anyone to exploit (in many cases without the owner of the computer knowing).
Once the hacker finds a machine, he uses a hacker tool such as Whisker to identify in less than a second what operating system the machine is using and whether any unpatched holes exist in it. Whisker, one of a handful of legitimate tools used by system administrators to test the security of their systems, also provides a list of exploits the hacker can use to take advantage of these holes.

It is true that Hacking is a great skill with lot of knowledge and commitment put behind it. Ethically if it is used for a good cause with possible acceptances, it can be useful for the future for new innovations and prevent possible vulnerabilities.