HZGN.COM
welcome to my space
X
Welcome to:hzgn.com
Search:  
Feng Shui | Graphic Design | Cosmetics | Causes and Organizations | Regulatory Compliance | Gadgets and Gizmos | Computer Forensics | Tools and Equipment | Related articles
NAVIGATION - HOME

An Hour with Kevin Mitnick, Part 2

Published by: wktd 2008-12-01

This is part two of my conversation with Kevin Mitnick. Part one can be found here.

A Hacker's Point of View

Kevin Mitnick: The hacker mindset doesn't actually see what happens on the other side, to the victim. As a hacker you think "Well, they were kind of naive, they picked easy passwords, I got in, I installed an SSHD Trojan, and when they figure it out all they've got to do is fix the Trojan and change a couple of passwords, so what's that going to take - ten minutes?"

That's how a hacker thinks, but on the other side, now that I work as a security specialist, it's more like "Oh my God! Who is this? What are they trying to do? We have to reload everything, we have to check every system on the network for integrity issues." Now it's a question of integrity — can we really trust our information? So now you're seeing man hours build into tens of thousands of dollars worth of loss in time and productivity. As a hacker you don't think about that.

There's also a question of ethics. As a young boy, I was taught in high school that hacking was cool. My first program was supposed to be written in basic and was supposed to find the first thousand Fibonacci numbers, but I decided I was going to write a program that was a log-in simulator so that when the teacher would go up to the computer and sign us in, it would snarf his password and log him in.

He would never know. Then I would tell him his password all the time. It was like a cat and mouse game with the teacher. When he finally figured it out and I told him about the program — I also told him that I didn't have enough time to do his assignment — he still gave me an "A".

Today, I'd be expelled, hauled off by the police, and my Mom would be picking me up from the police. Back in the seventies it was more like "this guy's smart, he's gifted, he's a whiz-kid," and I was actually patted on the back for this type of conduct. So the ethic I was taught in school resulted in the path I chose in my life following school.

Social Engineering Fundamentals, Part I: Hacker Tactics::
Stay tuned for Part II: Combat Strategies, which will look at ways of Mitnick, Kevin: “My first RSA Conference,” SecurityFocus, April 30, 2001
http://www.securityfocus.com/infocus/1527
HOME
Four Corners - 15/08/2005: Transcript::
KEVIN MITNICK: Stealing identities in America is the fastest growing crime of the . scammer maybe an hour or two to actually develop this type of scam.
http://www.abc.net.au/4corners/content/2005/s1438338.htm
HOME
Q: Do you think either approach is right? The seventies' approach or today's approach?

KM: I think equating hacking with a sort of cyber-terrorism is a bit of overkill, for example there's a new law that says that if you use a computer and cause serious bodily injury or death to a victim you get life without the possibility of parole — because there's no parole in the Federal system — but if you take a hammer or a motorcycle and you kill someone or seriously injure them it's not nearly as punitive. So, why? If the computer is the tool, why is the punishment so harsh? We should punish the person based on the harm they caused, not on the tool they used.

Q: Except that Joe on the street understands a hammer but he doesn't understand the computer, right?

KM: Right. So he's that much more scared of it.

Q: Isn't that one of the problems with legislators getting involved and trying to mandate defenses, because they don't understand the problem?

KM: Well, I'll give you an example. I went to Capitol Hill to testify about identity theft. So these older, people — much senior to me — decided that one of the biggest ways they were going to combat theft is that when you go to a restaurant they were going to make it mandatory that they don't print the whole credit card number on the receipt, so nobody could fish it out of the dumpster. So I'm thinking they're going about this all wrong.

They've got to start thinking like the bad guys. All they need to do is to set up some website somewhere selling some bogus product at twenty percent of the normal market prices and people are going to be tricked into providing their credit card numbers. So what you have to do is think about authenticating credit card transactions more than thinking about obfuscating the credit card number. They just didn't get it. They just don't understand the problem, so they're never going to come up with the solution.

Q: Which is the bigger threat, social engineering or specific technologies?

KM: Both! If the truth be known, you actually use a combination to compromise any type of security controls, where there is the least risk and it's the least costly. For example, Motorola; let's say I wanted to get a copy of the source code for Digital Voice Privacy because I wanted to eavesdrop on the FBI and they use DVP Astro Motorola radios. And I think maybe they made a programming error so the crypto they implemented in this product might not be sound and I could eavesdrop on Federal Agents and that would be fun, right?

So you find a vulnerability into one of Motorola's gateways into their network through a technical flaw. So once there, the hacker wants to know "where is the DVP source code?" So what's the quickest way of finding out? Social engineering, right? So he calls the department and finds out who's working on that project, and that's a lot faster than trying to scour every machine on Motorola's campus. It's a blended attack.

Page 2: Cat and Mouse Game


W3C Advances Specs For Web Interoperability
Bouquets, Brickbats for Microsoft's 'Channel 9'

#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about An Hour with Kevin Mitnick, Part 2 , Please add it free.
  • does anybody know where i can find an animation of joe jonas tripping at the ama 039 s
  • should i turn my sister in
  • is anyone else getting sick of people on here obsessing over the jonas brothers
  • r p what metal song describes me the best
  • is this normal am i the only one going through this or what
  • what do you people think of eminem 039 s new title
  • why are people so obsessed with the jonaas brothers
  • what 039 s the difference between french vanilla and vanilla
  • looking for new christian metal music please read my details
  • i need help do u think im obsessed with the jonas brothers
  • i am obsessed with joe jonas
  • for the girls what celebrity 039 s you crushing on
  • guitar callus help i don 039 t want to lose them in the shower
  • i am i really obsessed with the jonas brothers
  • i am overly obsessed with the jonas brothers i know so much about them its ridiculous is this a bad thing
  • who hates the jobros
  • im tottally obsessed with nick jonas
  • why is it that children can get so oh so obsessed with celebrities like right now the jonas brothers
  • im obsessed with nick jonas and i cant even think about any other guys help
  • the beatles vs the jonas brothers
  • poll annie or the sound of music
  • is any one else obsessed with the jonas brothers lol especially nick
  • why is every body so obsessed with the jonas brother
  • i am obsessed with the jonas brothers
  • if you have a friend obsessed w nick jonas just because you like him what should u tell them
  • why am i a banana head
  • why are all these agers obsessed with like high school musical jonas brothers and even miley cyrus
  •  Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
    Copyright© 2008 hzgn.com        Site made:CFZ