Archive forWhitehat hackers

0day Vulnerabilities For Sale - the new market for weaponized exploits

The following article was posted by (Paul Goebbels) to a security mailing list
Source : http://seclists.org/fulldisclosure/2007/Dec/0028.html
From: Goebbels Amadeus
Date: Sun, 2 Dec 2007 06:12:54 +0100 (CET)

Despite the misleading subject of my e-mail, I want to
bring to attention an important topic which hasn’t been
discussed enough among the security industry: the exploit
and vulnerability research market.
Since this might be a vastly secretive community, I will
introduce some of the members of this dramatically disturbing tale:
Since a few years ago, few companies emerged, who offer
rewards for exploit information and vulnerability research.
In the beginning, only iDefense (US-based) openly disclosed
its activities.
In the last 3-7 years we have seen ZDI (TippingPoint, now
3Com and soon its Chinese major shareholder..), WSLabi (the
failed attempt on creating an auction market model for these
sales) and Netragard (the old DMCA publicity stunt SNOsoft).
Now I’ll start telling a tale of distrust, lies, middle men
and other creatures of the infraworld…
Once upon a time, there was an increasingly powerful work
force capable of crafting weapons which existed only in a
digital world. This force didn’t have a name. They didn’t
pursue certifications. They were anonymous. But some realized
they also had the power of influencing people, controlling the
flow of information from anywhere at any time. Humanity has
seen for ages how the power of controlling information can
take down whole nations. Nowadays, in an open and free market,
the corporate world is nothing but a battlefield.
There’s no crimson tie. No blood escaping the bodies of its
soldiers. The soldiers are John Does, fighting for a decent
paycheck at any cost, selling out their spirits and time for
the corporate machine. Selling out their comrades and dignity.
Losing the values, principles and matter that make them human.
Unknowingly, they are becoming mere tools of few individuals
who have a neverending desire for fame and wealth.
Have you ever considered your future in their hands? You’ve
been working for 50 years, your liver and kidneys start failing,
creating visible symptoms, stains in your skin. You can’t handle
life in the same way anymore. For what? What have you done in
those 50 years but serving another man to become more wealthy
and over powered. The approaching day of your death and its
mere vision strikes you like a burning iron blade.
In this New Age battlefield, you can make a difference. A
talented youth started emerging and dedicated passionately to
fulfill its curiosity. Day after day, spending countless hours
in front of a machine. Understanding it’s inner design and
details, breaking it apart and reassembling it the way it wasn’t
meant to be assembled.
Some others dedicated painful discipline to physical work and
trained themselves for achieving perfection in both intellectual
and physical matters. Others fell in the way and never made it
to the final round.
After realizing they could not let the corporate world exhaust
them, they tried another way. The emerging market of digital
ammunition seemed to be a potential solution for their problems.
But, unbeknown to them, they were wrong. They didn’t think at
first glance of the impossibly huge amounts of lies and fallacies
they were about experience. Because in a world where you can
claim something while denying your obligation to prove it, the
only power that is left is that of common sense and intuition.
The ability to sense the deceitful and know the truthful.
Once day, our John Doe decided to approach an independent digital
weapons dealer, looking for better offers than those coming from
more established business men. He knew that more then business men,
they were only middle men. After numerous experiences with these
little twerps, he realized they were also abusing their condition.
John was also especially disappointed with the fact that in the
world of digital ammunitions, there’s no real way of providing the
goods without turning them instantly useless and vulnerable to abuse.
John knew that these middle men were taking cuts far higher than
their alleged 10 to 15 percent of the sale. How could John prove it
otherwise? There was no way of ensuring that their contacts were
getting the very exact figure John demanded.
Despite this fact, John also realized that in this market of smoke,
the seller is not supposed to set the price of the goods. These
middle men, in their great mistake of thinking that wisdom and
knowledge are the very same thing, wanted John to believe that
they were the ones who set the price of the goods.
John’s disappointment was growing to incredibly high stakes: “As a
child, whenever I tried to tell the candy shop clerk that the
chocolate bars cost as much as the peanut butter ones, he simply
tried to smack my head down. I wasn’t supposed to even swap the
labels in a failed attempt to fool this man, who had been making
candy bars for more time than I was actually able to barely say
my name.”
John had been crafting digital weapons for so many time, with
such a high talent and effectiveness, that he was much less
dispensable than this middle men. His personal background, of an
extremely tough childhood full of misery and hostility, also
gave him the necessary wisdom and experience in this world for
quickly spotting the weaknesses of these ego-crazed men. Their
weakness lies in the fact that without John and his comrades,
they have no business. They lack far more than just knowledge.
They lack wisdom, passion and truly devoted dedication to whatever
they do. Sooner or later they will make the same mistake of other
weapon dealers: getting killed with their own goods.
Hypocrisy among these poorly educated middle-men was so high,
that they resorted to low tricks and ridiculous attempts to gain
the trust of people like John. They went as far as insulting the
intelligence of those who provided them with the goods they are
unable to produce themselves. No matter how hard the tried, it
never brought anything back but silence. The silence that can be
clearly understood as a fully precise signal of genuine despise.
The fundamental error behind their approach is that trust can’t
be gained for cheering, boosting the ego, claiming great benefits
and wealth. Trust is something sculpted in hard rock, taking years
to become an admirable master piece. It doesn’t come attached to
an email.
At the end, John and his comrades found out that wasting their
time with these miserable beings was far less than fruitful. It
was exhausting them as much as the corporate world did. They
realized that any day above ground is a good day. Let the snakes
change their skin and show their true colors. In the desert,
being unable to match with environment has deadly consequences.
It might take years, or decades, but time will set them all where
they belong. Life does not forgive and everything has come to an
end… because they lack of patience, the end will approach their
nefarious activities sooner than they ever thought and John and
his comrades will be free again.
And this tale has to come to an end itself… the end of a
story about middle-men and their madness.
Time’s striking force.
- Paul Amadeus Goebbels

very interesting, mr goebbels.

Comments (5)

NEW: How Hackers REALLY Work

Hacker Hierarchy

Psychologist and Expert Hacker Marc Rogers says there are several subgroups of hackers —

newbies, cyberpunks, coders and cyber terrorists.

Newbies are hackers who have access to hacking tools but aren’t really aware of how computers and programs work. Cyberpunks are savvier and are less likely to get caught than a newbie while hacking a system, but they have a tendency to boast about their accomplishments. Coders write the programs other hackers use to infiltrate and navigate computer systems. A cyber terrorist is a professional hacker who infiltrates systems for profit — he might sabotage a company or raid a corporation’s databases for proprietary information.

Hackers and Crackers

Many computer programmers insist that the word “hacker” applies only to law-abiding enthusiasts who help create programs and applications or improve computer security. Anyone using his or her skills maliciously isn’t a hacker at all, but a cracker.

Even if the so-called hackers using malicious hacking skills have always, and continue to label themselves and their peers as hackers first and foremost, the nomenclature does not legally apply according to the Arbitration of What Stuff is Called Act of 2002. In addition, loosely organized social groups and clubs have not traditionally been permitted to determine their own names or identities. All definitions related to hacking must be approved by at least one academic over the age of 55 years old in an authorative tone whilst speaking to a relatively-ignorant IT journalist about the latest sensationalized hacker story. - Ed.

Group of Hackers from KDE.ORG

 

Crackers infiltrate systems and cause mischief, or worse. Unfortunately, most people outside the hacker community use the word as a negative term because they don’t understand the distinction between hackers and crackers.

Spying on e-mail: Hackers have created code that lets them intercept and read e-mail messages — the Internet’s equivalent to wiretapping. Today, most e-mail programs use encryption formulas so complex that even if a hacker intercepts the message, he won’t be able to read it.

Hacker Culture

Individually, many hackers are antisocial. Their intense interest in computers and programming can become a communication barrier. Left to his or her own devices, a hacker can spend hours working on a computer program while neglecting everything else.

There are many websites dedicated to hacking. The hacker journal “2600: The Hacker Quarterly” has its own site, complete with a live broadcast section dedicated to hacker topics. The print version is still available on newsstands. Web sites like Hacker.org promote learning and include puzzles and competitions for hackers to test their skills.

Not all hackers try to explore forbidden computer systems. Some use their talents and knowledge to create better software and security measures. In fact, many hackers who once used their skills to break into systems now put that knowledge and ingenuity to use by creating more comprehensive security measures. In a way, the Internet is a battleground between different kinds of hackers — the bad guys, or black hats, who try to infiltrate systems or spread viruses, and the good guys, or white hats, who bolster security systems and develop powerful virus protection software.

Yahoo Hack Day

Glenn Chapman/AFP/Getty Images
Hackers work together to create “mashups” of Yahoo applications at Google Hack Day 2006.

Hacking For a Living

Hackers who obey the law can make a good living. Several companies hire hackers to test their security systems for flaws. Hackers can also make their fortunes by creating useful programs and applications, like Stanford University students Larry Page and Sergey Brin. Page and Brin worked together to create a search engine they would eventually name Yahoo. Today, they are tied for 26th place on Forbes’ list of the world’s most wealthy billionaires [source: Forbes].

 

Famous Hackers: Lamo

Adrian Lamo hacked into computer systems using computers at libraries and Internet cafes. He would explore high-profile systems for security flaws (such as open proxies), exploit the flaws (or make use of the proxy) to “hack” into the system, and then send a message to the corresponding company, letting them know about the security flaw. Unfortunately for Lamo, he was doing this on his own time rather than as a paid consultant — his activities were illegal. He also snooped around a lot, reading sensitive information and giving himself access to confidential material. He was caught after breaking into the computer system belonging to the New York Times.

It’s likely that there are thousands of hackers active online today, but an accurate count is impossible. Many (>99%) hackers don’t really know what they are doing — they’re just using dangerous tools they don’t completely understand.

 

Source: How Computer Hackers Really Work, by a Non Hacker

Comments (2)

Video: Chris Pirillo on Xssworm - What are Hackers? Blackhat and Whitehat discussed

White hat, gray hat, black hat: no, we’re not talking about hat styles, but hackers. What are they, how do they differ, and are all of them super-evil?

SEO search engine manipulators also call each other blackhats. Also discussed is anecdotals about dogs and hacking.

Comments

What is a Blackhat Hacker? And Where are Black-hats hacking?

Black-Hat Hacker

A black hat or black-hat hacker is a malicious or criminal hacker. The term hacker is also commonly is used as a synonym for “black hat hacker”. However, in computer jargon, the meaning of “hacker” is much more broad.

(New readers of security may refer to our Hacker Dictionary for more information)

Usually a Black Hat refers to a person that maintains knowlege of the vulnerabilities and exploits they find as secret for private advantage, not revealing them either to the general public or manufacturer for correction. Many Black Hats promote individual freedom and accessibility over privacy and security. Black Hats may seek to expand holes in systems; any attempts made to patch software are generally to prevent others from also compromising a system they have already obtained secure control over. A Black Hat hacker may have access to 0-day exploits (private software that exploits security vulnerabilities; 0-day exploits have not been distributed to the public). In the most extreme cases, Black Hats may work to cause damage maliciously, and/or make threats to do so for blackmail purposes.

From : http://www.elitehackers.info/ethic.php

Michael Lynn Black Hat

The “black hat” is any person who used their knowledge of vulnerabilities exploits for private gain, rather than revealing them either to the general public or the manufacturer for correction. Many black hat hackers use hacking to hack into networks and web pages solely for financial gain. Black_hats may seek to expand holes in systems; any attempts made to patch software are generally done to prevent others from also compromising a system they have already obtained secure control over. A black hat hacker may write their own zero-day exploits (private software that exploits security vulnerabilities; 0-day exploits have not been distributed to the public). In the most extreme cases, black hats may work to cause damage maliciously, and/or make threats to do so as extortion.

Blackhat hackers and Dark SEO

Further Blackhat Resources:

Comments (7)

Hacker releases exploits for Wordpress 2.3 with XSS (Cross Site Scripting) Attack

Title of XSS Vulnerability:  [waraxe-2007-SA#059] - XSS in WordPress 2.3

Credit of XSS Discovery: Janek Vind “waraxe”
XSS Discovery Date: 27. October 2007
XSS Discovery Location: Estonia, Tartu
Web address for XSS security alert: http://www.waraxe.us/advisory-59.html

Image Placeholder

Description of XSS Exploit:

WordPress is a state-of-the-art semantic personal publishing platform with a focus on aesthetics, web standards, and usability, at expense of security.

To run WordPress your host just needs a couple of things:

PHP version 4.2 or greater
MySQL version 4.0 or greater

Technical XSS Information: Cross-Site Scripting (XSS) in “edit-post-rows.php”

WARAXE Writes: Let’s take have a look inside “/wp-admin/edit-post-rows.php”:

[start of section of source code with XSS exploit for wordpress]

<?php foreach($posts_columns as $column_display_name) { ?>
<th scope=”col”><?php echo $column_display_name; ?></th>
<?php } ?>

[end of vulnerable source code section]

As we can see, array “posts_columns” is uninitialized and if we execute this php script directly, then arbitrary value for that variable can be delivered. This means, that reflective XSS exists here.

And of course register_globals must be on for this “exploit” to be successful.

XSS Proof of concept worm:

http://victim.com/wp-admin/edit-post-rows.php?posts_columns[]=<script>alert(123);</script>

The information above has been provided by the website of WARAXE.US

Comments (2)

What are White Hat Hackers and Whitehat hacking ? XSS Worm

White-Hat Hacker

A white hat hacker, also rendered as whitehat or white-hat, is, in the realm of information technology, a person who is ethically opposed to the abuse of computer systems. Realizing that the Internet now represents human voices from all around the world makes the defense of its integrity an important pastime for many. A white hat generally focuses on securing IT systems, whereas a black hat (the opposite) would like to break into them but this is a simplification. A black hat will wish to secure his own machine, and a white hat might need to break into a black hat’s machine in the course of an investigation. What exactly differentiates white hats and black hats is open to interpretation, but white hats tend to cite altruistic motivations.

 

From : http://www.elitehackers.info/ethic.php

 

The term white hat hacker is also often used to describe those who attempt to break into systems or networks in order to help the owners of the system by making them aware of security flaws, or to perform some other altruistic activity. Many such people are employed by computer security companies; these professionals are sometimes called sneakers.

 

Sneakers - XSS Hackers robert redford - hackers XSS

 

Notes: In recent years the terms white hat and black hat have been applied to the Search Engine Optimization (SEO) industry. Black hat SEO tactics, also called spamdexing, attempt unfairly to redirect search results to particular target pages, whereas white hat methods are generally approved by the search engines.

 

Resources:

 

Comments (1)