0% found this document useful (0 votes)
6 views128 pages

Understanding Cybercrime and Hacking

Module 4 covers the various aspects of cybercrime, including its definitions, categories, and types, such as violent and non-violent cybercrimes. It discusses the roles of hackers, the life cycle of hacking, and the different motives behind cybercriminal activities, including identity theft, cyberstalking, and cyberterrorism. The module also highlights case studies and examples of cybercrime, illustrating its impact on individuals and organizations.

Uploaded by

kpsahasrabudhe
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views128 pages

Understanding Cybercrime and Hacking

Module 4 covers the various aspects of cybercrime, including its definitions, categories, and types, such as violent and non-violent cybercrimes. It discusses the roles of hackers, the life cycle of hacking, and the different motives behind cybercriminal activities, including identity theft, cyberstalking, and cyberterrorism. The module also highlights case studies and examples of cybercrime, illustrating its impact on individuals and organizations.

Uploaded by

kpsahasrabudhe
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Module 4

Cybercrime and Hacking

Dr. Rasika Naik


Mrs Arti Sawant
Module 4

4.1 Cybercrime, Categories of Cybercrime (Cybercrime against people,


Cybercrime Against property, Cybercrime Against Government). Types of
cybercrime (Violent- Cyber terrorism, Assault by Threat, Cyberstalking, Child
Pornography, Non-violent - Cybertrespass, Cyber Theft, Cyberfraud, Destructive
Cybercrimes), Computers' role in crimes
4.2 Hacking, Life cycle of Hacking, Types of hackers (White Hackers, Black
hackers, Grey hackers), hacking techniques
CYBER CRIME
▪ Crime committed using a computer and the internet to steal data or
information.
▪ Cybercrime refers to criminal activities carried out using computers
and the internet, including hacking, data theft, malware attacks, and
financial fraud.
Alternative definitions for cybercrime
 Any illegal act where a special knowledge of computer technology is
essential for its offence, investigation or prosecution.
 Any traditional crime that has acquired a new dimension or order of
magnitude through the aid of a computer, and abuses that have come
into being because of computers.
 Any financial dishonesty that takes place in a computer environment.
 Any threats to the computer itself, such as theft of hardware or
software, sabotage and demands for ransom.
Definition of Cyber Crime

Cyber crime specifically can be defined number of ways…


 A crime committed using a computer and the internet to steal a
person’s identity(identity theft) or sell contraband or stalk
victims or disrupt operations with malicious programs.
 Crimes completed either on or with a computer.
 Any illegal activity through the Internet or on the computer.
 All criminal activities done using the medium of computers, the
Internet, cyberspace and the WWW.
Cybercrime
 Cybercrime is not a new phenomena
 The first recorded cybercrime took place in the year 1820.
 In 1820, JosephMarie Jacquard, a textile manufacturer in France, produced
the loom. This device allowed the repetition of a series of steps in the weaving
of special fabrics. This resulted in a fear amongst Jacquard's employees that
their traditional employment and livelihood were being threatened. They
committed acts of sabotage to discourage Jacquard from further use of the
new technology. This is the first recorded cyber crime!
 The loom was the technology that was being used to cause harm, which is why
this is considered the first recorded cybercrime
Cyber crime
Motives to cyber crime
Types of cyber crime
Who are Cybercriminals?
 Are those who conduct acts such as:
 Child pornography
 Credit card fraud
 Cyberstalking
 Defaming others online
 Gaining unauthorized access to computer systems
 Ignoring copyrights
 Software licensing and trademark protection
 Overriding encryption to make illegal copies
 Software piracy
 Stealing another’s identity to perform criminal acts
Types of Cyber Crime
 Cybercrime refers to the act of performing a criminal act
using cyberspace as communication vehicle.
 Two types of attacks are common:
1. Techno- crime : Active attack
2. Techno – vandalism: Passive attack
Types of Cyber Crime
1. Techno- crime : Active attack
 Techno Crime is the term used by law enforcement agencies to denote criminal activity
which uses (computer) technology, not as a tool to commit the crime, but as the subject
of the crime itself.
 Techno Crime is usually pre-meditated and results in the deletion, corruption, alteration,
theft or copying of data on an organization's systems.
2. Techno – vandalism: Passive attack
 Techno Vandalism is a term used to describe a hacker or cracker who breaks into a
computer system with the sole intent of defacing and or destroying its contents.
 Techno Vandals can deploy 'sniffers' on the Internet to locate soft (insecure) targets and
then execute a range of commands using a variety of protocols towards a range of ports.
 The best weapon against such attacks is a firewall which will hide and disguise your
organization's presence on the Internet.
Techno- crime Techno – vandalism
Techno-crime is a broad category of illegal activities Involves unauthorized access to a computer
that use computers or networks. system to damage files or programs.
Often to cause financial harm, steal information, Often for amusement, to make a statement, or to
or disrupt services. cause disruption, rather than financial gain.
Examples: Examples:
Hacking Website defacement
Data breaches DNS cache poisoning
Malware distribution (e.g., ransomware, viruses) Software sabotage
Online scams and fraud DDoS attacks
Identity theft Deleting files or data
Cyberbullying Spamming and sending viruses
Cyberstalking

Techno-crime can also involve ATM crimes, cell Techno-vandalism is more about the challenge
phone crimes, and satellite dish crimes. than the profit.
Types of Cybercrime

Violent Non-violent
 Cyberterrorism ■ Cybertrespass

 Assault by threat ■ Cybertheft


 Cyberstalking
■ Cyber Fraud
 Child pornography
■ Destructive cybercrimes
■ Other cybercrimes
Violent CybercrimeViolent or Potentially Violent Cybercrime
Violent or potentially violent crimes that use computer networks are of highest
priority for obvious reasons: these offenses pose a physical danger to some person
or [Link] of violent or potentially violent cybercrime include:
■ Cyberterrorism
■ Assault by threat
■ Cyberstalking
■ Child pornography
Cyberterrorism
● Terrorism is “premeditated politically motivated violence perpetrated against
noncombatant targets by subnational groups or clandestine agents.”
● Cyberterrorism refers to terrorism that is committed, planned, or coordinated in
cyberspace—that is, via computer networks.
This category includes
1. Using e-mail for communications between co conspirators to impart information to
be used in violent activities.
2. Recruiting terrorist group members via Web sites.
3. Sabotaging air traffic control computer systems to cause planes to collide or crash.
4. infiltrating water treatment plant computer systems to cause contamination of
water supplies.
Cyber terrerism cont….
Cyberterrorism

5. Hacking into hospital databases and changing or deleting information that could
result in incorrect, dangerous treatment of a patient or patients.
6. Disrupting the electrical power grid, which could cause loss of air conditioning
in summer and heat in winter or result in the death of persons dependent on
respirators in private residences if they don’t have generator backup.
Cyber terrerism
The first quoted case of Cyber terrorist attack was of 1996.
cont….

● The Cyber terrorist was suspected as co-accused of ‘White Supremacist


Movement’, He was alleged for temporary disablement of part of the ISP’s
(Internet service provider) record keeping system and ‘Massachusetts Internet
service provider’.
● The ISP had made efforts to restrain the hackers from spreading and sending
racist massage worldwide.
● Finally, the attacker fleshes the message “You have yet to see electric terrorism.
● This is a promise”, at signing-off the system. This was the first Cyber attack,
which opened the doors of probabilities and possibilities of Cyber terrorism
worldwide.
Cyber terrorist attacks Cyber rerrerism cont…

● In August 2013 Indira Gandhi International Airport (IGI) faced Cyber attack.
● A destructive virus program called as ‘technical snag’ hit the operations of
terminal no. 03.
● This malicious code was spread remotely for the trespassing- ‘the security
system of Airport’.
● The cyber attackers tried to take advantage of weakness of security system.
● Their modus of operandi was to transfer of virus program through ‘check-in
centers’ of boarding gates and finally to the operation of CUPPS (Common
use Passenger Processing System), which materially affects airlines online
reservation system and expected time of departure and capacity of waiting
lounge.
Assault by threat
Assault by threat can be committed via e-mail.
This cybercrime involves placing people in fear for their lives or threatening the
lives of their loved ones (an offense that is sometimes called terroristic threat). It
could also include e-mailed bomb threats sent to businesses or governmental
agencies.

Cyberstalking
Cyberstalking is a form of electronic harassment, often involving express or implied
physical threats that create fear in the victim and that could escalate to real-life
stalking and violent behaviour.
Cyberstalking (cont…)
► Stalking means “act or process of following victim silently”
► Types of stalking
1. Online stalking : They interact with victim directly with the help of Internet.
Mode of Interaction : E-mail, chat room, traditional PSTN, VoIP phones.
Stalker can make use of third party to harass victim.
2. offline stalker : Stalker may attack on victim by observing his
1. Daily routing.
2. searching personal website /blogs
3. Visiting victim organization.
Kinds of cyber stalking
► E-mail stalking
► Internet stalking
► Computer Stalking

Motives behind Cyber stalking:


► Harassment
► Fascination
► Revenge
► Boasting or showoff
Case Report on cyberstalking
► Majority of cyberstalking women are victim .
► Few cases are reported where women are cyberstalking and men are victim ,
where few cases of same gender have been identified.
► How stalking works ?
- Gathering personal info .( sp . Contact no and address)
- Established contact with victim through tel./cell phone.
- Contact via E-mail.
- Continues threaten mail to victim.
- The stalker may post victim personal photo and information social site or
porn web site.
Case study: Cyber stalking
► A 35-year-old man will serve three months in jail for sending obscene pictures
and videos via email to a woman he met on a social networking site — the state’s
first conviction in a cyber-stalking case.
► Additional chief metropolitan magistrate MR Natu convicted Yogesh Prabhu
under section 509 (word, gesture or act intended to insult the modesty of a
woman) of the IPC and section 66 (E) (punishment for violation of privacy) of
the Information Technology Act, 2008.
► “Prabhu has been sentenced to three months’ simple imprisonment and fined
Rs10,000 for the offence under the IT Act and Rs5,000 for intending to insult the
modesty of a woman,” said Dhananjay Kulkarni, deputy commissioner of police,
crime branch.
Case study: Cyber stalking (cont..)
► “The woman initially chatted with him, but she said she started finding his
behavior suspicious and stopped responding to his messages,” said public
prosecutor Kiran Bhendbhar. She even removed him from her friend’s list.
► According to the police sources, their relationship could have turned sour
after the woman turned down Prabhu’s proposal to get married. As the
woman is a year older than Prabhu, her parents were opposed to the
marriage. The woman then stopped communicating with him.
► Prabhu, however, continued to keep an eye on her profile and her
whereabouts.
Case study: Cyber stalking (cont..)
► The following month, between March 3 and March 9, 2009, the woman
got mails from an unknown ID. The mails contained obscene images and
videos. She initially ignored them, but when they did not stop, wrote a
complaint to the then crime branch chief Rakesh Maria. A case was
registered at the Shivaji Park police station on April 9 and the Cyber
Crime Investigation Cell (CCIC) took over the probe.
► The Internet Protocol (IP) address of the computer was traced to the Vashi
firm. A team headed by inspector Mukund Pawar, arrested Prabhu in April
2009. CCIC sub inspector Sachin Puranik said the cyber cell filed a 200-
page charge sheet in September 2009, after which the trial began.
Case study: Cyber stalking (cont..)
► Eight witnesses, including the woman, Prabhu’s colleagues, cyber experts
and police officials were examined by public prosecutor Bhendbhar. When
the court convicted Prabhu, it said the prosecution had proved the case
beyond reasonable doubt.
► “This is the first conviction in a cyber-stalking case in Maharashtra.
Convictions in cyber frauds cases have happened earlier, but this is the first
in which an accused has been convicted in a cybercrime where a woman was
targeted, stalked and harassed with obscene material on the internet,” said
Nandkishore More, assistant commissioner of police, cyber division.
Nonviolent Cybercrime Categories

 Most cyber crimes are nonviolent offenses, due to the fact that a defining
characteristic of the online world is the ability to interact without any
physical contact.
 The perceived anonymity and “unreality” of virtual experiences are the
elements that make cyberspace such an attractive “place” to commit
crimes.
Nonviolent Cybercrime
Nonviolent cybercrimes can be further divided into several
subcategories:
■ Cybertrespass
■ Cybertheft
■ Cyber Fraud
■ Destructive cybercrimes
■ Other cybercrimes
Cybertrespass
● In cybertrespass offenses, the criminal accesses a computer or network resources
without authorization but does not misuse or damage the data there.A common
example is the teenage hacker who breaks into networks just “because he (or she)
can”—to practice hacking skills, to prove him- or herself to peers, or because it’s
a personal challenge.
● Cyber Trespassers enjoy “snooping,” reading your personal email and documents
and noting what programs you have on the system, what Websites you’ve visited,
and so forth, but they don’t do anything with the information they find.
● Nonetheless, cybertrespass is a crime in most jurisdictions, usually going under
the name of “unauthorized access,” “breach of network security” or something
similar.
Cybertrespass (continue…)
● Law enforcement professionals need to be aware of the laws in their
jurisdictions and avoid automatically dismissing a complaint of network
intrusion simply because the victim can’t show loss or damage.
● Network administrators need to be aware of this crime because under
criminal statutes, a company can prosecute intruders simply for accessing
the network or its computers without permission.
● In this regard, it might be easier to build a criminal case than a civil lawsuit,
since the latter often requires proof of damages in order to recover.
Cybertrespass (continue…)
● The computer may be used as a tool in the following kinds of activity, e-mail
spoofing, forgery, cyber defamation, cyber stalking.
● It is necessarily the breach of personal information of a person and his personal
identity details, website databases etc.
● The computer may however be target for unlawful acts in the most of the cases for
e.g. unauthorized access to computer/ computer system/ computer networks, theft
of information contained in the electronic form, e-mail bombing, data diddling,
salami attacks, logic bombs, Trojan attacks, internet time thefts, web jacking, theft
of computer system, physically damaging the computer system and other such
confidential information.
● As the capacity of human mind is incalculable, it is not possible to eliminate cyber
trespass from the cyberspace. But it is quite possible to check them As computer
data often contain personal information a cracker can also infringe one's right to
Cybertheft
● There are many different types of cyber theft, or ways of using a computer and
network to steal information, money, or other valuables.
● Because profit is an almost universal motivator and because the ability to steal from a
distance reduces the thief’s risk of detection or capture, theft is one of the most
popular cybercrimes.

Cyber Theft offenses include:


● Embezzlement, which involves misappropriating money or property for your own use
that has been entrusted to you by someone else (for example, an employee who uses
his or her legitimate access to the company’s computerized payroll system to change
the data so that he is paid extra, or who moves funds out of company bank accounts
into his own personal account)
Cybertheft (continue…)
● Unlawful appropriation, which differs from embezzlement in that the criminal
was never entrusted with the valuables but gains access from outside the
organization and transfers funds, modifies documents giving him title to
property he doesn’t own, or the like
● Corporate/industrial espionage, in which persons inside or outside a company
use the network to steal trade secrets (such as the recipe for a competitor’s soft
drink), financial data, confidential client lists, marketing strategies, or other
information that can be used to sabotage the business or gain a competitive
advantage.
Cybertheft (continue…)
● Plagiarism, which is the theft of someone else’s original writing with the intent of
passing it off as one’s own.
● Piracy, which is the unauthorized copying of copyrighted software, music, movies, art,
books, and so on, resulting in loss of revenue to the legitimate owner of the copyright.
● Identity theft, in which the Internet is used to obtain a victim’s personal information,
such as Social Security and driver’s license numbers, in order to assume that person’s
identity to commit criminal acts or to obtain money or property or use credit cards or
bank accounts belonging to the victim.
● DNS cache poisoning, a form of unauthorized interception in which intruders
manipulate the contents of a computer’s DNS cache to redirect network transmissions to
their own servers.
Cybertheft (continue…)
● Network administrators should be aware that in many cases, network
intrusion is much more than simply an annoyance; cybertheft costs
companies millions of dollars every year.
● Law enforcement officers need to understand that theft does not always
necessarily involve money; a company’s data can also be stolen, and in
most jurisdictions, there are laws (including, in some cases, federal
laws) that can be used to prosecute those who “only” steal information.
Cyber fraud
● Generally, cyber fraud involves promoting falsehoods in order to obtain
something of value or benefit.
● Although it can be said to be a form of theft, fraud differs from theft in that in
many cases, the victim knowingly and voluntarily gives the money or property
to the criminal—but would not have done so if the criminal hadn’t made a
misrepresentation of some kind.
● Sends an e-mail asking you to send money to help a poor child whose parents
were killed in an auto accident.
● promising that if you “invest” a small amount of money (by sending it to the
con artist) and forward the same message to 10 friends, you’ll be sent thousands
of times your “investment” within 30 days.
Cyber fraud (continue…)

● misrepresenting credentials to obtain business (and often not providing the


service or product promised).
● Fraudulent schemes, cyber-based or not, often play on victims’ greed or
good will.
● Cyber Fraud can take other forms; any modification of network data to obtain a
benefit can constitute fraud (although some states have more specific computer
crimes statutes that apply).
● For example, a student who hacks into a school system’s computer network to
change grades or a person who accesses a police database to remove his arrest
record or delete speeding tickets from his driving record is committing a form of
fraud.
Destructive Cybercrimes

Destructive cybercrimes include those in which network services are


disrupted or data is damaged or destroyed, rather than stolen or misused.
These crimes include
1. Hacking into a network and deleting data or program files
2. Hacking into a Web server and “vandalizing”Web pages
3. Introducing viruses, worms, and other malicious code into a network or
computer
4. Mounting a DoS attack that brings down the server or prevents legitimate
users from accessing network resources
Other Nonviolent Cybercrimes

There are many more nonviolent varieties of [Link], many of


these only incidentally use the Internet to accomplish criminal acts that
have been around forever (including the world’s oldest profession).
Some examples include:

■ Advertising/soliciting prostitution services over the Internet


■ Internet gambling
■ Internet drug sales (both illegal drugs and prescription drugs)
■ Cyberlaundering, or using electronic transfers of funds to launder illegally
obtained money
■ Cybercontraband, or transferring illegal items, such as encryption technology
that is banned in some jurisdictions, over the Internet
Categories of Cyber crime

 Cybercrime against person


 Cybercrime against property
 Cybercrime against organization or government
1. Cybercrime against persons
⚫ Electronic mail spoofing and other
online frauds
⚫ Phishing, spear phishing
⚫ spamming
⚫ Cyberdefamation
⚫ Cyberstalking and harassment
⚫ Computer sabotage
⚫ Pornographic offenses
⚫ passwordsniffing
Spoofing
⚫Spoofing, as it pertains to cyber security, is when someone or
something pretends to be something else in an attempt to gain
our confidence, get access to our systems, steal data, steal
money, or spread malware.”
Types of spoofing
⚫ Email spoofing: email spoofing is the act of sending emails with false sender
addresses, usually as part of a phishing attack designed to steal your information, infect
your computer with malware or just ask for money.

⚫ Website spoofing:
It is all about making a malicious website look like a legitimate one. It is the creation of a
replica of a trusted site with the intention of misleading visitors to a phishing site.
Legitimate logos, fonts, colors and functionality are used to make the spoofed site look
realistic.
Domain name that looks the same at first glance. Cybercriminals use spoofed websites to
capture your username and password or drop malware onto your computer . A spoofed
website will generally be used in conjunction with an email spoof, in which the email will
link to the website.
⚫Caller ID spoofing:
It happens when scammers fool your caller ID by making the call appear to be
coming from somewhere it isn't. Scammers have learned that you're more likely
to answer the phone if the caller ID shows an area code the same or near your
own. In some cases, scammers will even spoof the first few digits of your phone
number in addition to the area code to create the impression that the call is
originating from your neighborhood .

Caller ID spoofing is the practice of causing the telephone network to indicate to


the receiver of a call that the originator of the call is a station other than the true
originating station. This can lead to a caller ID display showing a phone number
different from that of the telephone from which the call was placed.
Text message spoofing:

SMS spoofing is a technology which uses the short message service


(SMS), available on most mobile phones and personal digital
assistants, to set who the message appears to come from by
replacing the originating mobile number (Sender ID) with
alphanumeric text.
⚫ Text message spoofing:
It is sending a text message with someone else's phone number or sender
ID. If you've ever sent a text message from your laptop, you've spoofed
your own phone number in order to send the text, because the text did
not actually originate from your phone. Companies frequently spoof their
own numbers, for the purposes of marketing and convenience to the
consumer, by replacing the long number with a short and easy to
remember alphanumeric sender ID. Scammers do the same thing—hide
their true identity behind an alphanumeric sender ID, often posing as a
legitimate company or organization. The spoofed texts will often include
links to SMS phishing It is sending a text message with someone else's
phone number or sender ID.
⚫ GPS spoofing :
occurs when you trick your device's GPS into thinking you're in one location, when
you're actually in another location .

Man-in-the-middle (MitM) attack:


You like that free Wi-Fi at your local coffee shop? Have you considered what would
happen if a cybercriminal hacked the Wi-Fi or created another fraudulent Wi-Fi
network in the same location? In either case, you have a perfect setup for a
man-in-the-middle attack, so named because cybercriminals are able to intercept web
traffic between two parties. The spoof comes into play when the criminals alter the
communication between the parties to reroute funds or solicit sensitive personal
information like credit card numbers or logins.
⚫IP spoofing is used when someone wants to hide or disguise
the location from which they're sending or requesting data
online. As it applies to cyber threats, IP address is used when
someone wants to hide or disguise the location from which
they're sending or requesting data online. As it applies to
cyber threats, IP address spoofing is used in
distributed denial of service attacks (DDoS) to prevent
malicious traffic from being filtered out and to hide the
attacker's location.
[Link] against property
[Link] against property
 Arson is the willful burning of another’s person’s property.
Even if you own the building or property, it is unlawful for you to “burn it
down”. Setting fire to a building with the intent to defraud the insurance
company is illegal also. In 1996 the Church Arson Prevention Act was passed
 Vandalism is the willful destruction of or damage to, the property of another.
This crime cost all of us millions of dollars per year.
Examples of vandalism Depending upon the damage, it can be charged as a
misdemeanor or felony
 Embezzlement is the unlawful taking of property by someone to whom it was
entrusted.
Example - bank tellers who take money out of their drawer
[Link] against property
 Extortion is the use of threats to obtain the property of another. Usually called
“blackmail” Ex: A person threatens to harm you unless you give them
$1,000,000
 Robbery is the unlawful taking of property from a person’s immediate
possession by force or intimidation. Robbery is almost always a felony, but
most states have stricter penalties for armed robbery. The difference between
robbery and larceny/burglary is the potential or act of force.
 Forgery is a crime in which a person makes or alters a writing or document
with intent to take advantage of someone/thing. Includes signing, without
permission, the name of another person to a check or other document.
Cybercrime against organization
 Unauthorized accessing of computer
 Password sniffing
 Denial-of-service attacks
 Virus attack/dissemination of viruses
 E-Mail bombing/mail bombs
 Salami attack/ Salami technique
 Logic bomb
 Trojan Horse
 Data diddling
 Industrial spying/ industrial espionage
 Computer network intrusions
 Software piracy
Spamming
● People who create electronic spam : spammers

● Spam is abuse of electronic messaging systems to send unsolicited bulk messages


indiscriminately

● Spamming may be
○ E-Mail Spam
○ Instant messaging spam
○ Usenet group spam
○ Web search engine spam
○ Spam in blogs, wiki spam
○ Online classified ads spam
○ Mobile phone messaging spam
○ Internet forum spam
○ Junk fax spam
○ Social networking spam
……..
Cyber defamation
⚫ The tort of cyber defamation is considered to be the act of
defaming, insulting, offending or otherwise causing harm through
false statements pertaining to an individual in cyberspace.
⚫ Example: someone publishes defamatory matter about someone
on a website or sends an E-mail containing defamatory
information to all friends of that person.
Computers' role in crimes
1. Act as a communication tool.
2. Can be the target of attacker for criminal activity.
3. Can be tangential to crime.

Computers used in crime scenarios:

4. Witness can see suspect’s picture on screen through internet.


5. For DNA testing.
6. Small size and portable computers used in police vehicles to determine criminal records.
7. Fingerprints can be taken and can be verified with previous records.

For investigation.

1. At traffic junctions to find VIN.

2. Database of criminals can be maintained.

3. Simulations can be created.


Hacking
Every act committed toward breaking into a computer and/ or network is hacking.
Purpose
 Greed
 Power
 Publicity
 Revenge
 Adventure
 Desire to access forbidden information
 Destructive mindset
History of hacking
 hacking is any technical effort to manipulate the normal behavior of network
connections and connected systems.
 A hacker is any person engaged in hacking.
 The term "hacking" historically referred to constructive, clever technical work that was
not necessarily related to computer systems.
 In the 1950s and 1960s the term and concept of hacking was popularized for first time.
 the so-called "hacks" perpetrated by these hackers were intended to be harmless
technical experiments and fun learning activities.
 As computer networking and the Internet exploded in popularity, data networks became
by far the most common target of hackers and hacking.
Hacking vs. Cracking
 Malicious attacks on computer networks are officially known
as cracking ,
 while hacking truly applies only to activities having good
intentions.
 Most non-technical people fail to make this distinction,
however.
 Outside of academia, its extremely common to see the term
"hack" misused and be applied to cracks as well.
Hackers, crackers, phreakers
 General term
 Breaks computers system
 Targeting mobile phones
There are 3 types of modern hackers
 Black Hats: Criminal Hackers.
 Possess desire to destruction
 Hack for personal monetary gains : Stealing credit card
information, transferring money from various bank accounts to their
own account, extort money from corporate giant by threatening.
 White Hats: Ethical Hackers.
 Network Security Specialist.
 Grey Hats: Deals in both of the above (jack of all trades, master
of none).
1. Coders
2. Admins
3. Script kiddies
Real life case : Dec 2009
NASA site hacked via SQL Injection
⚫ Two NASA sites recently were hacked by an individual, wanted to demonstrate that the sites are susceptible
to SQL injection.
⚫ The websites for NASA's Instrument Systems and Technology Division and Software Engineering Division
were accessed by a researcher, who posted to his blog screenshots taken during the hack.
⚫ The researcher, using the term "[Link]," used SQL injection to hijack the sites.
⚫ SQL injection is an attack process where a hacker adds additional SQL code commands to a page request
and the web server then tries to execute those commands within the backend database
⚫ The NASA hack yielded the credentials of some 25 administrator accounts.
⚫ The researcher also gained access to a web portal used for managing and editing those websites.
⚫ In this particular case, the researcher found the vulnerabilities, made NASA aware of them, then published
findings after the websites had been fixed.
⚫ An attacker, however, could have tried to use that web server as an entry point into other systems NASA
might control or edit the content of the sites and use them for drive-by downloads.
Nadya Suleman’s Website Hacked,
feb 2009
The story..
 LOS ANGELES, CA – Octuplet mom Nadya Suleman launched
a website to solicit donations for her family, but it was
immediately hacked by a group of vigilante mothers!
 The website originally featured photos of all eight octuplets, a
thank you note from Suleman, images of children’s toys and a
large donation button for viewers to send money through.
Suleman also provided an address where people can send items
such as diapers and formula.
 Suleman was perhaps not prepared for the backlash she was to
receive, as the site was hacked and brought down within hours.
The original homepage was left up but defaced, as seen in the
screenshot.
 The site was tagged by the famous hacker group MOD, also known as
the Mothers of Disappointment. The mysterious group has a history of
attacking personal sites they disapprove of, including Britney Spears
when she infamously hung dry her sons on a clothes line after a bath,
and Angelina Jolie for being Angelina Jolie.
 Weekly World News could not reach any members for comment,
however reporters did receive a short note from an anonymous e-mail
address:
 mod will not tolerate the selfish acts of bad parenting we will remain
true to our mission despite any setbacks viva la maternity (call your
mother, she misses you)
 The site has since been restored, and Suleman’s PR representative has
stated they are now taking extra security measures to arm against future
attacks.
Life cycle
of Hacking
Steps performed by hackers

1 Performing Reconnaissance
2 Scanning and enumeration
3 Gaining Access
4 Maintaining access and placing backdoor
5 governing tracks or clearing logs
1. Reconnaissance: This is the first phase where the Hacker tries to collect
information about the target. It may include Identifying the Target, finding out the
target’s IP Address Range, Network, DNS records, etc.

He may do so by using a search engine like maltego, researching the target say a
website (checking links, jobs, job titles, email, news, etc.), or a tool like HTTPTrack
to download the entire website for later enumeration, the hacker is able to determine
the following: Staff names, positions, and email addresses.
2. Scanning: This phase includes the usage of tools like dialers, port scanners,
network mappers, sweepers, and vulnerability scanners to scan data. Hackers are
now probably seeking any information that can help them perpetrate attacks such as
computer names, IP addresses, and user accounts. Now that the hacker has some
basic information, the hacker now moves to the next phase and begins to test the
network for other avenues of attacks. The hacker decides to use a couple of methods
for this end to help map the network (i.e. Kali Linux, Maltego and find an email to
contact to see what email server is being used). The hacker looks for an automated
email if possible or based on the information gathered he may decide to email HR
with an inquiry about a job posting.
3. Gaining Access: In this phase, the hacker designs the blueprint of the
network of the target with the help of data collected during Phase 1 and Phase
2. The hacker has finished enumerating and scanning the network and now
decides that they have some options to gain access to the network.
4. Maintaining Access: Once a hacker has gained access, they want to keep that access for future
exploitation and attacks. Once the hacker owns the system, they can use it as a base to launch
additional attacks.

In this case, the owned system is sometimes referred to as a zombie system. Now that the hacker has
multiple e-mail accounts, the hacker begins to test the accounts on the domain. The hacker from
this point creates a new administrator account for themselves based on the naming structure and
tries and blends in. As a precaution, the hacker begins to look for and identify accounts that have not
been used for a long time. The hacker assumes that these accounts are likely either forgotten or not
used so they change the password and elevate privileges to an administrator as a secondary account
in order to maintain access to the network. The hacker may also send out emails to other users with
an exploited file such as a PDF with a reverse shell in order to extend their possible access.
5. Clearing Tracks (so no one can reach them): Prior to the attack, the attacker would
change their MAC address and run the attacking machine through at least one VPN to help
cover their identity. They will not deliver a direct attack or any scanning technique that would
be deemed “noisy”.
Once access is gained and privileges have been escalated, the hacker seeks to cover their
tracks. This includes clearing out Sent emails, clearing server logs, temp files, etc. The
hacker will also look for indications of the email provider alerting the user or possible
unauthorized logins under their account.
Most of the time is spent on the Reconnaissance process. Time spend gets reduced in
upcoming phases. The inverted triangle in the diagram represents a time to spend in
subsequent phases that get reduced.
Reasons for hacking

1. For fun
2. To steal
3. To disrupt
Impact of Hacking

1. Loss in finance
2. Information loss
3. Decline privacy
4. Reputation can be damaged
Preventions from hackers
 Use a firewall.
 Use virtualization.
 Install antivirus software.
 Secure your network.
 Install an anti-spyware package.
 Use two-factor
 Use complex passwords. authentication.
 Keep your OS, apps and browser up-to-date.  Use encryption.
 Ignore spam.
 Back up your computer.
 Shut it down.
How to secure your phone from hackers

 Turn off Bluetooth.


 Don't use unsecured public Wi-Fi.
 Get a security app.
 Use a better passcode.
 Switch off [Link] your browsing history.
2. Modern Techniques

• site cloning and false merchant sites on


internet (direct users to such bogus/ fake
sites –phishing)
• Triangulation
• Credit card generation
Prevention of Cybercrime
1
2
3
.
.
.
.
Self-learning topics

1. Steps performed by Hacker


2. Case study of Hacking

You might also like