Live data from Hacker News

How to Hack and Not Get Caught

blog.spiderlabs.com

1–10 of 19 posts

Re: How to Hack and Not Get Caught

#3
Step 1: Don't post to Hackernews that you hack into places

.. Tongue in cheek commentary aside, the title comes off more like the content would be on par with the grugq's presentation on Opsec for hackers (http://www.slideshare.net/grugq/opsec-for-hackers).

The argument to never modify anything only holds true for pentesting, for a slightly more nefarious attacker it's not unheard of to actually do some system maintenance & configuration fixing to close holes behind them to prevent other attackers from gaining access through the same entry point. Increasing the system stability has a tendency to make people look the other way, it's far less likely that someone would say "Hey, that server has been performing better, let's see if it's been compromised."

Re: How to Hack and Not Get Caught

#4

Step 1: Don't post to Hackernews that you hack into places .. Tongue in cheek commentary aside, the title comes off more like the content would be on par with the grugq's presentation on Opsec for hackers ( http://www.slideshare.net/grugq/opsec-for-hackers ). The argument to never modify anything only holds true for pentesting, for a slightly more nefarious attacker it's not unheard of to actually do some system main…

This seems to written for penetration testers who are actually paid to "hack into places" and have the consent of the system owner therefor are not breaking the law.

Re: How to Hack and Not Get Caught

#5
I'm don't get paid to do this sort of thing very often, but when I have been paid, the client has always asked for noisy generic scans that can be integrated as part of a periodic review process (for internal or external parties). Explaining that the bad guys won't be so nice as to light up your IDS with an internal portscan or try to brute force some random database was met with complete indifference.

I guess as someone who would be responsible for their network's general well-being, I'd probably rather have some checked boxes saying nothing on my internal network was listening with trivially exploitable (i.e. non-patched or badly configured) services and my passwords are at least a certain complexity and not variations of the 1000 most common as of $SOMEDATE.

That said, it should be pretty easy to setup the usual suspects for scan tools to be performed in a scoped manner to satisfy the need for checked boxes after an operator spends some time getting up close and personal with the target system. Those type of attacks are going to reveal more information about user training (looking at Joe User with important\ passwords.docx in My\ Documents) than simple network scans are likely to.

I wonder what the qualifications are these days for a pen tester at a commerical company...

Re: How to Hack and Not Get Caught

#7
For external interfaces I don't see a need to avoid portscans - they're popular enough on the open internet that it's not going to attract attention or deviate much from standard traffic.

Re: How to Hack and Not Get Caught

#8

Step 1: Don't post to Hackernews that you hack into places .. Tongue in cheek commentary aside, the title comes off more like the content would be on par with the grugq's presentation on Opsec for hackers ( http://www.slideshare.net/grugq/opsec-for-hackers ). The argument to never modify anything only holds true for pentesting, for a slightly more nefarious attacker it's not unheard of to actually do some system main…

This seems to written for penetration testers who are actually paid to "hack into places" and have the consent of the system owner therefor are not breaking the law.

I'm sure he didn't even read the article.

Re: How to Hack and Not Get Caught

#10

Earlier quoted context omitted.

This seems to written for penetration testers who are actually paid to "hack into places" and have the consent of the system owner therefor are not breaking the law.

I'm sure he didn't even read the article.

I'm sure I did, but couldn't resist being a smartass
Post reply on HN