How to Hack - Part Two 06-23-2014, 09:17 PM
#1
Last time I talked about what hacking actually is, and what a Skid is. In this thread, I'll be discussing how hacking fits together with computer systems and how you can get started.
So, hacking is to literally think creatively to get around a problem. In computing, it's generally defined as finding and exploiting vulnerabilities in a network or system for the purpose of malicious gain, to cause havoc, or just for personal enjoyment, as a challenge.
The three main groups of hackers are Black Hats, Grey Hats, and White Hats.
A Black Hat is a hacker that hacks for personal gain. For example, hacking into a system simply to steal and then sell or leak data, or hacking individuals to steal bank account details etc.
A Grey Hat is a hacker that is willing to break the law in order to further security. This is the general definition, but it's much wider than that. This kind of hacker is the one that hacks for enjoyment, for a challenge. They don't do it for personal gain. For example, they might try to hack into a big site, succeed and then play around for a bit. Then they'd report the problem.
A White Hat is the boring but completely legal one. They are mostly hired out by companies and businesses to try and hack into their network. They do so with explicit authorization and submit a full report at the end. They only try to do anything with full written permission and only hack for the betterment of security.
What can you do to get started? Well, there's a great many things that you have to familiarize yourself with.
I'll list a few basic steps below.
Let me give you an example/guide:
In the next thread, I'll go over some basic website vulnerabilities and attack vectors. I hope you enjoyed reading this!
Aurora
So, hacking is to literally think creatively to get around a problem. In computing, it's generally defined as finding and exploiting vulnerabilities in a network or system for the purpose of malicious gain, to cause havoc, or just for personal enjoyment, as a challenge.
The three main groups of hackers are Black Hats, Grey Hats, and White Hats.
A Black Hat is a hacker that hacks for personal gain. For example, hacking into a system simply to steal and then sell or leak data, or hacking individuals to steal bank account details etc.
A Grey Hat is a hacker that is willing to break the law in order to further security. This is the general definition, but it's much wider than that. This kind of hacker is the one that hacks for enjoyment, for a challenge. They don't do it for personal gain. For example, they might try to hack into a big site, succeed and then play around for a bit. Then they'd report the problem.
A White Hat is the boring but completely legal one. They are mostly hired out by companies and businesses to try and hack into their network. They do so with explicit authorization and submit a full report at the end. They only try to do anything with full written permission and only hack for the betterment of security.
What can you do to get started? Well, there's a great many things that you have to familiarize yourself with.
I'll list a few basic steps below.
- First thing that you should do is join a good, HQ technology and/or hacking forum. Stay active, stay HQ, and you will learn a LOT. Trust me.
- Familiarize yourself with the different tools and operating systems out there. Linux is a must, preferably install Kali Linux on a live USB.
- Read some eBooks. No, not the two page guides on HF that tell you how to hack Twitter accounts, but proper 500 page eBooks by security professionals.
- Learn a programming language or two. PHP, MySQL etc. Don't just learn them and not know what they're for. Understand them. Find out how they fit into the world of hacking.
- Browse sites where vulnerabilities and exploits are posted. http://exploit-db.com is a good example. Find a good exploit, read through the vulnerable code and the exploit that takes advantage of it, and understand it. Understand how it works. Once you've done that, you can write your own!
- Research recon. This is the stage in a penetration test where you gather information and try to find vulnerabilities. This is why Kali Linux is such a good operating system, it comes pre-loaded with hundreds of tools that'll allow you to perform every part of a penetration test. Yes, you won't be familiar with these, but it's easy to learn. Google "Kali Linux Guide for Penetration Testers". Find a good eBook on Amazon and buy it! If you're a typical internet person, then go ahead and torrent it for free. You can also get other guides such as 'Metasploit Guide for Penetration Testers' etc. Familiarize yourself with the main tools in Kali Linux.
- Google the steps of a Penetration Test. Go over the steps and understand them. Then find out how you can perform them. Here's one such site: http://www.pen-tests.com/the-phases-of-an-attack.html Note: It's not the only site out there. You'll have to do some research yourself.
- Familiarize yourself with the different attack vectors, understand them, learn them, and then try to find and exploit them.
Let me give you an example/guide:
Aurora's guide on how to hack a site!
- Browse to the site in question. No, not to Google, but rather to some old WordPress site etc.
- Find out if it's running a CMS etc. Let's use a WordPress site as an example in this tutorial. To find out if it's running a CMS, view the source code > between the <head></head> tags. There should be a reference to whatever the site's running on.
- Find out what version of it is running. Let's say 1.2.3
- Google "WordPress 1.2.3 vulnerability".
- Find a suitable exploit. Don't just copy and paste and then run it like a skid would. First understand it. Find out how and why it works.
- If the version isn't vulnerable, or is too difficult to exploit, find plugins or other things running on the site and try to exploit them. You have to assess the site for attack vectors, avenues of attack.
In the next thread, I'll go over some basic website vulnerabilities and attack vectors. I hope you enjoyed reading this!
Aurora














![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)






![[Image: miNuqGq.png]](https://i.imgur.com/miNuqGq.png)

![[Image: R5aCcWV.png]](http://i.imgur.com/R5aCcWV.png)


![[Image: inkexplosion.jpg]](http://i0.wp.com/techverse.net/wp-content/uploads/2013/09/inkexplosion.jpg)