How to Think Like a Hacker如何看待像一個黑客

A hacker’s main objective is to compromise the targeted computer, network, or application.黑客的主要目標是妥協的目標計算機,網絡,或申請。 The hacker starts off with little information and ends up with a detailed map into the system.黑客啟動了很少的信息和最後一份詳細的地圖進入系統。 There are five steps which hackers follow to hack into a system:有五個步驟,後續黑客攻破成一個系統:
上行, hacker.jpg

Reconnaissance 偵察
The target of this investigation stage is to gather info about domain names, IP address ranges, business partners, phone numbers, type of software and operating systems in use and existing network defence mechanisms.的目標,這一調查階段是收集資訊域名, IP地址範圍,業務合作夥伴,電話號碼,輸入的軟件和操作系統的使用和現有的網絡防禦機制。

First, hackers must identify the domain names of the target such as xxxx.com.首先,黑客必須確定域名的目標,如xxxx.com 。 Then they gather as much information as possible through public channels.然後,他們收集盡可能多的信息通過公共渠道。 One good source is through newsgroups.一個良好的來源是通過新聞。 Information Technology (IT) staff often divulge too much information about their configurations and applications when approached for assistance.信息技術( IT )工作人員往往透露太多了解他們的配置和應用時,接觸,尋求協助。 Job announcements also provide vital information about the company’s computer systems, operating systems and applications.招聘公告還提供重要信息公司的計算機系統,操作系統和應用程序。 If the job advertises for an information-security position, the type of network defense of the target can easily be identified.如果宣傳工作的一個信息安全的立場,類型的網絡防禦的目標可以很容易地確定。

The hacker can then visit the Internet Archive’Web site (archive.org) to check for information about the target that may go back for years.黑客就可以訪問Internet Archive'Web網站( archive.org )檢查有關的目標,可能回去了多年。 The Securities and Exchange Commision’s website (www.sec.gov) can reveal information about impending company merges – this means that the IT defenses for both companies will be significantly lowered to merge resources and ensure a smooth transition.美國證券交易Commision的網站的( www.sec.gov )可以揭示有關公司即將合併-這意味著防禦系統的I T企業都將顯著降低合併資源和確保平穩過渡。 When the enemy’s defences are down, it’s time to attack.當敵人的部隊正在下降,現在正是時候攻擊。

Hackers can also use social engineering to gather facts.黑客還可以使用社會工程來收集的事實。 The human element is oftentimes the weakest link in the system.人的因素往往是最薄弱的環節在系統中。 For example, if you have the trust of an employee who is authorised to access the network, you can pretend to have an urgent problem that appeals to the natural helpfulness of the person.例如,如果您有信任的一名僱員誰有權訪問網絡,你可以假裝有一個迫切的問題,呼籲自然樂於助人的人。

Scanning and Enumeration 掃描和枚舉
Next, hackers will scan servers and resources on the target network using the software from any “Warez” websites for free.下一步,黑客將掃描服務器和資源的目標網絡,利用該軟件從任何“ Warez ”網站是免費的。 Once a hacker gets detailed info about the target operating systems or application via scanning, it only takes a little talent and substantial patience to identify weaknesses in the system.一旦黑客獲得詳細信息,對目標的作業系統或應用程序通過掃描,但只需要很少的人才和大量的耐心找出不足,該系統。 A visit to any hacking tool website will give the beginner hacker a push in the right direction.訪問任何黑客工具的網站將給予初學者黑客推動方向是正確的。 Sometimes a computer system will even offer information about password length or bypass the need for a password if the hacker asks the computer a suitably formatted question.有時候,一個計算機系統,甚至會提供的信息密碼長度或繞行需要一個密碼,如果黑客要求計算機有適當格式化的問題。 Once past the firewall, internal security is usually slack.在過去的防火牆,內部安全通常是疲弱。

Gaining Access 獲得
After scanning for the relevant information, the hacker now has free access to the system or network.掃描後的有關資料,現在黑客自由出入系統或網絡。 They will have a free run of the place with complete administrative access and can change any information or play havoc to the system.他們將有一個自由運行的地方完整的管理權限,並可以改變的任何信息或發揮破壞的系統。 A tip: an easy way to do this is a call to the company help desk and impersonate the manager to get a password reset if an email sent to the manager earlier triggers an automatic ‘I’m on leave’ message.小費:一種簡單的方法來做到這一點是要求該公司服務台和假冒的經理獲得密碼重置,如果一封電子郵件發送到早先的經理觸發自動'我離開'的訊息。

Perfect 完善
If the hacker still has difficulty getting administrative access into the system, a Trojan disguised as a service pack or system update can be sent to company staff.如果該黑客還難以進入行政系統,一個木馬程序偽裝成一個服務包或系統更新時可以發送到公司的工作人員。 This can be sent from the System Administrator’s email account (obtained from a newsgroup message in the reconnaissance phase) –The Trojan appears harmless but will install a key-logger program in the background when run by employees.這可以被從系統管理員的電子郵件帳戶(獲得新聞信息的偵察階段) ,該木馬似乎無害,但會安裝一個關鍵記錄器程序在後台運行時的員工。 When the employees key in their user-IDs and passwords throughout the day, the program will automatically forward these to the hacker.當員工的關鍵在其用戶ID和密碼在一天內,該程序會自動將這些給黑客。

Maintaining Access 保持訪問
Once the hacker has access to critical computer systems, the password file or the Security Account Manager (SAM) is easily obtainable.一旦黑客已經進入關鍵的計算機系統,密碼文件或安全帳戶管理器( SAM )是容易獲得。 This contains the user-IDs and passwords for all the system users.這包含了用戶的ID和密碼的所有系統用戶。 From here, they can hack into other systems.從這裡,他們可以破解到其他系統。 Hackers also install backdoor programs on all compromised systems so that they will continue to have access even when the passwords are changed.黑客還安裝後門程序的所有計算機系統,以便他們將繼續有機會,即使密碼更改。 Furthermore, this will be totally overlooked by even experienced IT staff as normal network traffic.此外,這將是完全忽略了即使是有經驗的IT人員作為正常的網絡流量。 The perfect crime!完美的犯罪!

IMPORTANT : This is a machine translated page which is provided "as is" without warranty. 重要說明:這是一台機器翻譯網頁這是“原樣”提供,無保修。 Machine translation may be difficult to understand.機器翻譯可能很難理解。 Please refer to請參閱 original English article英文原文的文章 whenever possible.只要有可能。

Share and contribute or get technical support and help at共享和貢獻或獲得技術支持和幫助 My Digital Life Forums 我的數字生活論壇 .



3 Responses to “How to Think Like a Hacker”三答复“如何思考像一個黑客”

  1. it2051229
    May 22nd, 2007 08:27 2007年5月22日08:27
    1

    Ohh lol… then i guess i must be a hacker which i think not..lol Ohh上海...然後我想我必須有一個黑客,我認為不..上海

  2. ohnoes
    May 29th, 2007 19:58 07年5月29日19:58
    2

    explaining uplink - nothin else … lol解釋上行-n othin別人. ..上海

  3. Aein
    November 18th, 2007 03:39 2007年十一月18號3點39分
    3

    Interesting.有趣的。 However, i think there are many ways how to defense ours systems including personal data… I will not write about thi at this moment, but think about但是,我認為有很多方式如何防衛我們的系統,包括個人資料...我不會寫的詩在這一時刻,但想想

Leave a Reply留下一個回复

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> 您可以使用這些標籤: href="" title="">的<a <abbr title=""> <acronym title="">的<b> <blockquote cite=""> <cite>的<code> “刪除日期時間= “ ” “的<em> <i> <q cite=""> <strike>的<strong>

Subscribe without commenting訂閱沒有評論


Custom Search

New Articles新文章

Incoming Search Terms for the Article收到的搜索字詞的文章

how to hack bebo accounts 如何破解Bebo則稱帳戶 - - hack bebos 黑客bebos - - bebo password hacker Bebo則稱黑客密碼 - - hack bebo accounts 黑客Bebo則稱帳戶 - - bebo hackers Bebo則稱黑客 - - bebo passwords Bebo則稱密碼 - - bebo account hack beta v1 Bebo則稱帳戶黑客測試V1導聯 - - how to hack into peoples bebo 如何破解到人民Bebo則稱 - - hacking bebo accounts 黑客Bebo則稱帳戶 - - how to hack a bebo account 如何破解一Bebo則稱帳戶 - - how to hack peoples bebos 如何破解人民bebos - - Bebo password hacks Bebo則稱密碼破解 - - computer hakker 計算機hakker - - bebo account hack Bebo則稱帳戶破解 - - hacking bebos 黑客bebos - - hack into bebo 黑客到Bebo則稱 - - how to hack bebo 如何破解Bebo則稱 - - download Bebo Account Hack BETA V1 Bebo則稱下載到破解V1導聯測試 - - how to hack bebo account 如何破解Bebo則稱帳戶 - - hacking bebo password 黑客Bebo則稱密碼 - - how to hack into other peoples bebo 如何破解到其他國家的人民Bebo則稱 - - how to hack into bebo 如何破解到Bebo則稱 - - how to hack bebos 如何破解bebos - - how to hack into bebo accounts 如何破解到Bebo則稱帳戶 - - Bebo Account Hack BETA V1- With Download Bebo則稱帳戶哈克測試V1導聯,與下載 - - bebo hacker Bebo則稱黑客 - - hacker 黑客 - - hacking bebo 黑客Bebo則稱 - - hack bebo 黑客Bebo則稱 - - download bebo hacker 黑客下載Bebo則稱 - - BEBO HACK BETA VERSION 1 Bebo則稱破解測試第1版 - - how to think like a hacker 如何覺得像一個黑客 - - bebo account hack beta Bebo則稱帳戶黑客測試 - - hacker ip 黑客的IP - - bebo account hack v1 Bebo則稱帳戶破解V1導聯 - - bebo hack password Bebo則稱破解密碼 - - hack peoples bebos 黑客人民bebos - - hack bebo account 黑客Bebo則稱帳戶 - - how to hack in to bebo accounts 如何破解到Bebo則稱帳戶 - - how to hack a pearl website 如何破解珍珠網站 - - bebo hack v1 Bebo則稱破解V1導聯 - - hacking a bebo 黑客一Bebo則稱 - - bebo account hack beta v1 download Bebo則稱帳戶破解下載試用版V1導聯 - - BEBO HACK BETA VERSION 1 download Bebo則稱破解試用版第1版下載 - - hacker bebo 黑客Bebo則稱 - - bebo hacking programme Bebo則稱黑客方案 - - bebo password hackers Bebo則稱黑客密碼 - - hack into bebo account 黑客到Bebo則稱帳戶 - - how too hack into a bebo account 如何破解也成為Bebo則稱帳戶 - - download hacker for bebo 下載黑客的Bebo則稱 - -