Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Security & Privacy
Weekly Brief
Windows Vista
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: HackersOnline SecurityNetwork Security

School for Hackers

Security consultants join with hackers to learn how to be the first to find Web server flaws.

Victor R. Garza, special to PC World

Monday, August 02, 2004 9:00 AM PDT
Recommend this story?

LAS VEGAS--A presentation on how to be the first to exploit new flaws in Web server software was deemed "just as cool for white hats as for black hats" attending the Defcon 12 conference here over the weekend.

The session offered new tools, as well as insight into the mindset of the so-called black hat, or malicious hacker, community, said one enthusiastic attendee, who works for a security consulting company that secures Web servers for the financial sector. The two presenters, German security consultants "FX" and Halvar Flake, spoke about taking advantage of new-found holes, known as zero-day Web-based vulnerability exploitation.

Hacking Advice

Finding vulnerabilities to exploit is real work, the presenters said. The large, packed crowd listened to them talk about "making script kiddies into real hackers," referring to novice hacker wannabes who simply use other hackers' tools to deface Web sites.

The pair outlined the procedural steps of drilling down and finding Web server weaknesses--effectively offering tips to those who want to do so, but also providing knowledgeable warning to those who guard against such action.

"You've got to like assembly language, because you'll be spending lots of time with it, and it'll make your head hurt," Flake said, referring to the detailed functionality of the low-level programming language. They also advised would-be hackers that they need to know the programming language better than the programmer of the Web site they want to crack.

FX and Flake also humorously offered opposing views on which programming or scripting language is better suited to automate the process of disabling a Web server.

FX advised attendees to "become a C language lawyer so you can find ambiguities in the code," likening familiarity with programming code to an attorney's understanding of the intricacies of the law.

Armed for Defense

The presentation was not really intended to make script kiddies into malicious hackers, but rather to tell "people how not to be a script kiddie and instead do useful work," Flake said after his talk. Wannabe hackers should do something useful with their time, he added, saying he hoped they would realize the intellectual challenge of understanding the underlying Web technologies and "see that it's exciting taking things apart instead of just defacing Web pages."

"A lot of kids will realize that [finding Web-based vulnerabilities] is hard work, and do something else," Flake added.

The security consultant in the audience said she appreciated the presenters' emphasis that finding Web-server bugs to take advantage of is a time-consuming and difficult process--but noted that offering such a challenge only makes the exercise more attractive for the tenacious. The session may be "dropping script kiddies, but helping those that are interested in robbing the bank," she added.

Still, the insight she gained will makes her job easier, she said. The detailed presentation provided useful programming tools as well as knowledge to help her anticipate and replicate a black-hat hacker's tactics--"to be a black hat so I can attack a bank's Web site and save them millions, if not billions of dollars," she said.


Recommend this story?
Related Searches: hackerdefcon 12black hatwhite hatsecurity
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
When simple measures--such as restarting--fail to patch up your Mac, it may be time to call on Disk Utility's First Aid tools... 16-May-2008
Epson's Stylus Photo R1900 uses pigment inks to produce long-lasting, borderless photographic prints at sizes up to 13 by 19... 16-May-2008
MacProVideo has released a new video tutorial for users of Apple's Logic 8 digital audio workstation. 16-May-2008
Ableton has released an LE version of its Live 7 sequencer. Ableton Live 7 LE is based on the same principles as its... 16-May-2008
Silicone cases provide the best of both worlds--a protective covering without adding a lot of bulk. In this week's iPod case... 16-May-2008
In my recent Macworld video blog, I discussed how to install and use WebKit, which is a version of Safari that includes the... 16-May-2008
Tidy Up, a utility that allows you to search for duplicate files and folders, has been updated adding support for Mac OS X... 16-May-2008
Big Fish Audio has released one of its most original music loop packages for users of music creation applications compatible... 16-May-2008
As a simple and effective way to backup a drive, Time Machine has been a welcome new feature in Leopard. However, it does not... 16-May-2008
iPass partners with likely first in-flight broadband firm over U.S. for what could be a highly affordable fixed monthly service plan, including Wi-Fi hotspots, for frequent travelers. 16-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)