Build your professional network on facebook via our app Go to app
 
 1 of 19 in Topic  Next >>
Topic : How to hack?
  Rate : 
Associated with other topics :
 
Started by : Saurabh Gautam, Project Manager, ADP   12 18 2008 11:16:15 +0000
Industry : InternetFunctional Area : Strategy Execution(Strategy & Execution)
Activity:  473 views;  last activity : 09 13 2011 06:48:47 +0000

Hacking,Phishing, cracking, and cyber crimes are hot topics these days and this will continue even in the future
 The catch is to understand what risks, threats, and vulnerabilities currently exist in one's environment, and then learning about the problems by which one can devise a solid response, So how will you protect your critical assets, to know this one needs to get into the hacker's shoes, So how hackers breach security?? share your views on this critical issue.

 
 Refer 19
Share
 
 
  Rate : 
 
 
 
 
  11 6 2 1 1
 
 
 
 
 
 
 
 
 
 
 
 
 
1 2 3 4 5
1 network security
2 XSS and SQL injection (for Web Application)
3 Cross-site request forgery
4 Stealing Passwords
5 Trojan Horse
6 List of website vulnerable to XSS attacks
7 Social engineering?
8 The evolution of Cross-Site Scripting Attacks (XSS)
9 What are the threats for a Web Application.
10 SQL Injection
11 Using GET Method for form posting
12 Insider Threat !!
13 list effected point
14 Below Link is the link on True Story
15 recent consumer citation on phishing
16 Securing Web Application
17 We need to know, how to secure our informations
18 Passing SQL Injection
19 Attend today's Live Webcast on Network Security: How to protect your network from Fraudsters breaking in
20 Attend today's Live Webcast on Network Security: How to protect your network from Fraudsters breaking in
21 I know Some hacking and Cracking !!!!!
22 Network Security
23 How hackers breach security??
24 hack minds

network security

idea posted by Puneet Seth Network Engineer-Security, Cisco Systems

ports and the ip address leads to a network getting hacked.

hacking passwords is a young boy's game which atleast am not interested in.

try your hands on big things. instead of making your network getting compromised its very important to have a right device and right knowledged to help you.

 

Ports and ip address can help you getting in anywhere. In my personal opinion one should use a network based ips(intrusion prevention system) instead of host based.

IPS/IDS can be used in the network with the firewalls to make the network secure.

 

11
0
  

but if scan all the ports of a network or a computer and its easy to find one door to enter.

0
  
by Ajay Ziz, Dy. Registrar,, University of Jammu  | 04 18 2010 08:01:07 +0000

puneet .. got the hint for a big time job big joe ::

2
  
by mun jas, IT consutling & network architect  | 12 06 2009 19:18:07 +0000

you are rigth ...

cn u tell me some methods about password cracking

 

thanks

Add your argument:

XSS and SQL injection (for Web Application)

idea posted by Anirban Bhattacharya Software Architect, Novartis Healthcare Pvt Ltd

Cross side scripting and sql injection is the widely used ways to break the login and to get inside verified session. One tries to explore the vulnerability of sql query in the script and use it to create an identifed session. XSS is mainly used to hijack cookie value so that one can use it to enjoy an unexpired session.

6
0
  

ya sql injection is easy way to enter , mainly in  the govt. website i find this fault. 

1
  

Yeah XSS attack and SQL injections are most common way to break the security... There are many more but above 2 are tried first..

Add your argument:

Cross-site request forgery

idea posted by Murari Srivastava Team Lead, Infosys

Cross-site request forgery, also known as one-click attack or session riding and abbreviated as CSRF ("sea-surf") or XSRF, is a type of malicious exploit of a website whereby unauthorized commands are transmitted from a user that the website trusts. Unlike cross-site scripting (XSS), which exploits the trust a user has for a particular site, CSRF exploits the trust that a site has in a user's browser.

2
References :
Cross-site request forgery - Wikipedia, the free encyclopediaCross-site request forgery, also known as one-click attack or session riding and abbreviated as CSRF ("sea-surf" [1]) or XSRF, is a type of malicious ...en.wikipedia.org
No supporting Arguments for this idea
Add your argument:

Stealing Passwords

idea posted by Saurabh Gautam Project Manager, ADP
According to me this is the most simple thing for hackers, because passwords that are too complex for a person to remember easily can be discovered by a cracking tool in a very short period of time. Dictionary attacks, brute force attacks, and hybrid attacks are all various methods used to guess or crack passwords. The only real protection against such threats is to make very long passwords or use multiple factors for authentication.

 So what are the other ways hackers breach security??
1
0
  
by Ajay Ziz, Dy. Registrar,, University of Jammu  | 04 19 2010 05:10:31 +0000

long passwords .. multiple authentication :: crackable..

 

have you heard of ... silent passwords ..

hissing passwords ..

no password\protection :::

just mind food :: great indian software pros ..

 

Add your argument:

Trojan Horse

idea posted by Dayanand Deshpande Senior Consultant, Ernst & Young
A Trojan horse is a continuing threat to all forms of IT communication. Basically, a Trojan horse is a malicious payload which is delivered inside a benign host. You are sure that you have heard of some of the famous
Trojan horse malicious payloads such as Back Orifice, NetBus, and SubSeven, but then the real threat of Trojan horse attack is an unknown entity..

All a Trojan horse attacks if it  needs to be successful it should be done by a  single user to execute the host program, and any simple guy who knows basic computer skills can develop trojan horse, then  the  payload is automatically launched as well, usually without any symptoms of unwanted activity. A Trojan horse could be delivered via e-mail as an attachment, it could be presented on a Web site as a download, or it could be placed on a removable media like memory card, CD/DVD, USB and floppy etc. So good anti virus, malware scanners and user education is important to tackle such incidents..hope this helps
1
No supporting Arguments for this idea
Add your argument:

List of website vulnerable to XSS attacks

idea posted by Srikanth IT/Technical Content Developer, Bigtec Private Limited

Hello every one,

In the website http://www.xssed.org you can find list of all websites which are vulnerable to attack and by seeing the example one can have practical view of how the website gets hacked.

 

1
No supporting Arguments for this idea
Add your argument:

Social engineering?

idea posted by Ganesh Pavale Information Systems(MIS)-Manager, Dolphin EMT Pvt. Ltd.

Let us not Social engineering is the key to start hack, what you think?

1
0
  

Let us not forget, Social engineering is the key to start hack.

Add your argument:

The evolution of Cross-Site Scripting Attacks (XSS)

idea posted by vijayvkvelu IT Security Leader, Attomic Labs

Dear Saurabh,

It seems today that Cross-Site Scripting (XSS) holes in popular web applications are being discovered and disclosed at an ever-increasing rate. Take a glance of all bug tracks etc.

Here are some of the solutions :-

As a web application user/common user , there are a few ways to protect yourself from XSS attacks. The first and most effective solution is to disable all scripting language support in your browser and email reader. If this is not a feasible option for business reasons, another recommendation is to usereasonable caution when clicking links in anonymous e-mails and dubious web pages.

Additionally, as a last resort, proxy servers can help filter out malicious scripting in HTML,although commercial systems have a long way to go in this regard.

Web application developers and vendors should ensure that all user input is parsed and filtered properly. User input includes things stored in GET Query strings, POST data, Cookies, URLs,and in general any persistent data that is transmitted between the browser and web server. The best philosophy to follow regarding user input filtering is to deny all but a pre-selected element
set of benign characters in the web input stream. This prevents developers from having to constantly predict and update all forms of malicious input in order to deny only specific characters (such as < ; ? etc. we call it metacharacter ).

1
No supporting Arguments for this idea
Add your argument:

What are the threats for a Web Application.

idea posted by Anirban Bhattacharya Software Architect, Novartis Healthcare Pvt Ltd

A web application is vulnerable in terms of hacking threat. Here the discussion point are not in terms of network security but application security. The loose ends of an application can be explored by

1. XSS attack.

2. SQL Injection.

3. Cookie poisoning.

XSS Attack: XSS or cross site scripting is the most potential threat. A web application has two avenues of control. Server end and client end. When a user requests a page, the request goes to server and the server prepares the page and sends it to the browser. Now, in the browser end all dynamicity is brought by client side script like javascript. Now think of the a situation where a user injects malicious script through your form input which gets stored in the database and the script fired when the server fetches data and throws it to browser. The script then can get activated and can steal vital information and can send to other sites. This is XSS attack.

The most effective solution is to decativate HTML display by converting into HTML entities. Like an HTML tags starts and ends with < > symbol. if it is converted into &lt; and &gt; it would still display but will remain inactive.

 

1
0
  
by PalaniMurthy , B.Tech/B.E. student, JJCET-Trichy  | 08 11 2009 06:08:17 +0000

Actually,

           All even the domain name is also a threat...........

                    I can know about the admin of any domain name,Means on cracking that admin account i can do anything with your web-site or within the whole control of yours...................

Add your argument:

SQL Injection

idea posted by Bhushan Patil Project Lead, Birlasoft Limited

The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed

1
References :
SQL injection - Wikipedia, the free encyclopediaSQL injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an application. ...en.wikipedia.org
1
  
by Basant Sharma, Team Leader -(Technical), webgrity  | 03 03 2009 12:27:32 +0000

Some hacker enter the sql injection which will destroy or explore the  tables of your website. Or they enter to your account without entering the actual pass word . i have some trick but due to some reason i will not explaing those trick here...

Add your argument:

Using GET Method for form posting

idea posted by Asim Banerjee Team Lead, Wipro

If you use GET method that leads to database inserts, you are very vunerable. And you did all this to just save time for yourself.

1
No supporting Arguments for this idea
Add your argument:

Insider Threat !!

idea posted by subhendu kumar barik Information Security Consultant, Crystal Solutions Pvt Ltd

One should first make sure there is no insider in the security breach because now a days organizations are more vulnerable to this threat.The history shows more attacks are generated from inside the network.The organization should make their employees are aware of the security trends.And the most important thing is to have a good administrator who will keep a vigil eye on the network and he should update his knowledge of the vulnerabilities till date.

0
No supporting Arguments for this idea
Add your argument:

list effected point

idea posted by ravindra shrivastava Information Systems(MIS)-Manager, iifs pvt ltd

Hacking, cracking, and cyber crimes are hot topics these days and will continue to be for the foreseeable future. However, there are steps you can take to reduce your organization's threat level. The first step is to understand what risks, threats, and vulnerabilities currently exist in your environment. The second step is to learn as much as possible about the problems so you can formulate a solid response. The third step is to intelligently deploy your selected countermeasures and safeguards to erect protections around your most mission-critical assets. This white paper discusses ten common methods hackers use to breach your existing security.

1. Stealing Passwords

2.Trojan Horses

3. Exploiting Defaults

4. Man-in-the-Middle Attacks

5.Wireless Attacks

6. Doing their Homework

7. Monitoring Vulnerability Research

8. Being Patient and Persistent

 9. Confidence Games

10.Already Being on the Inside

0
No supporting Arguments for this idea
Add your argument:

Below Link is the link on True Story

idea posted by Abdulhaq Syed Chisty IS Auditor, Solution Architect

http://www.securityfocus.com/infocus/1527

0
No supporting Arguments for this idea
Add your argument:

recent consumer citation on phishing

idea posted by tamilarasi babu Legal Dept -Associate Manager, GMR

account using net banking facility.

The Court directed the bank to pay account holder money that has been stolen , with 8% interest and legal expenses amounting to Rs. 25,000 for mental agony that has been caused to account holder

 

Case details

Mr. Nikhi Futan , an account holder of HDFC , was shocked to find on Oct. 2008  that Rs. 4.6 lakhs had been transferred from  hearing the  account to two accounts with – to a Shukla in Lucknow and Rajiv in Vijayawada

Bank did not take cognition of the complaint and he registered a police complaint

Both Shukla and Rajiv were arrested and only Rs. 70,500 were recovered

Bank’s version

Futan went to the Consumer Court in April 2009 . Bank argued that the money has been transferred after a request from Futan and that it had alerted Mr. Futan through SMS and e mail and he had failed to respond

Unauthorized transaction had taken place only if the customer had shared account details, used  a shared computer or had malicious software.

 

Futan  version

 Not received any message or email from bank

 

Court Version

The court accepted his contention that the bank had no evidence to prover there was malicious software  or viruns in his computer

The court cannot assume customer’s assent  if does not reply to text message  or e mail intimating his assent for transfer

The bank has not taken precaution as per RBI guidelines

0
No supporting Arguments for this idea
Add your argument:

Securing Web Application

idea posted by Ankit Mehta Software Test Engineer, C1 India

Securing web application can occur in many ways, what I use to implement I have mentioned below.

  1. Use URL rewrite to hide application pages or control flow.
  2. If you are using IIS then it is better to apply URL scan. or IIS Lockdown tool
  3. Change server header
  4. Block not required ports and services.
  5. Frequently check your application with various vurnability detection tool
  6. Change default Eroor message
  7. Never show detailed error message to end user
  8. To secure your application from Man In Middle attacks, spoof client mac address and use it in cookies
  9. Never relay on HTTPS (Port 443) connections, do encryption at client end with your own developed logic (Not only MD5 or any other algorithm).
0
No supporting Arguments for this idea
Add your argument:

We need to know, how to secure our informations

idea posted by Mithun.Sagar Information Security Engineer, Sify technologies

Its not that simple to make this short.Anyway we need to secure our network,system,application,database and classify data according to the severity and give different layers of protection based on the classification.

So we need to keep ourselves update with new security flows and the preventive measures.eg:secunia,cert,symantec threat report etc.

0
No supporting Arguments for this idea
Add your argument:

Passing SQL Injection

idea posted by Basant Sharma Team Leader -(Technical), webgrity

Some hacker enter the sql injection which will destroy or explore the  tables of your website. Or they enter to your account without entering the actual pass word . i have some trick but due to some reason i will not explaing those trick here...

0
No supporting Arguments for this idea
Add your argument:

Attend today's Live Webcast on Network Security: How to protect your network from Fraudsters breaking in

idea posted by Viraj Mehta Webmaster, UBM India Pvt Ltd
Over the past 18 months there has been a seismic shift in the threat landscape. What can organisations do to protect themselves from fraudsters breaking in? This webinar will highlight some of the measures organisations can take to mitigate risks in this dynamically changing threat environment. When: September 13th 2011, 2:00pm (IST) Onwards Register and attend for Free http://www.informationweek.in/webcast
0
No supporting Arguments for this idea
Add your argument:

Attend today's Live Webcast on Network Security: How to protect your network from Fraudsters breaking in

idea posted by Viraj Mehta Webmaster, UBM India Pvt Ltd
Over the past 18 months there has been a seismic shift in the threat landscape. What can organisations do to protect themselves from fraudsters breaking in? This webinar will highlight some of the measures organisations can take to mitigate risks in this dynamically changing threat environment. When: September 13th 2011, 2:00pm (IST) Onwards Register and attend for Free http://www.informationweek.in/webcast
0
No supporting Arguments for this idea
Add your argument:

I know Some hacking and Cracking !!!!!

idea posted by Anand Vishwakarma Web Developer, IT Development

Through My Point of view,,,,The Hacking is the art of technics..there are many and alots of  hacking,,eg,(email hacking,password hacking,websites hacking and windows hacking, etc,,,),The many ways to hack these to use of some software ,batch programms and net tools,,available in the internet,,

And Cracking the is technic which is used to crack any trail software to register version,,,to use of registry editor ,, and resources hacker,ollydebug and many other softwares for  used to cracking and also you can cracked software through online,,,,,,

 

0
No supporting Arguments for this idea
Add your argument:

Network Security

idea posted by Anand Vishwakarma Web Developer, IT Development
A ``network'' has been defined[1] as ``any set of interlinking lines resembling a net, a network of roads || an interconnected system, a network of alliances.'' This definition suits our purpose well: a computer network is simply a system of interconnected computers. How they're connected is irrelevant, and as we'll soon see, there are a number of ways to do this.
0
No supporting Arguments for this idea
Add your argument:

How hackers breach security??

idea posted by mun jas IT consutling & network architect

They do it using combination of one or more skills and methods. These generally include :

using automated tools : many are freewares

write scripts and send them hidden inside an otherwise good payload or header encapulation : this is called obfuscation or malforming packets

sniffing application and session layer information

scanning tools etc

 

 

0
No supporting Arguments for this idea
Add your argument:

hack minds

idea posted by Ajay Ziz Dy. Registrar,, University of Jammu

hackers don't crack the security network..

they read and think above the mind of the security expert ..

hacker is the best in the hand of security agencies ( but are difficult to handle as 99.99% are insane nerds)

0
0
  
by Ajay Ziz, Dy. Registrar,, University of Jammu  | 04 18 2010 06:50:07 +0000

what u rdoing that is hacking is just researching trash..no body can brace even the surface of real networks..

czecks , russians are the masters .. coolest areas .. cool minds .. impregnable networks they make ..

indians if you have guts .. hack russians .. erstwhile ussr counteries minds ( real god fathers of computers)..

chinese ching ming choons are just ants..

Add your argument:

Add your Idea
Idea* : 
Add your argument:
edit in rich text ...
Could not find any idea interesting in: "How hackers breach security??" ? Click here to add a new idea...

Found the idea contest "How hackers breach security??"  interesting ?  Click here to refer to your connections and communities
Top IT Recruitment Firm
  • Create a confidential Career Profile and Resume/C.V. online
  • Get advice for planning their career and for marketing of experience and skills
  • Maximize awareness of and access to the best career opportunities
Viewers also viewed
Kerela IT firms are hunting hackers .. recruiting them in their companies...This is  unique way...
 
2872 referals 23 arguments, 401 views
in my view the aviation security,particularly airport security,should be funded from from the...
 
28 referals 4 comments, 31 views
more...  
 
More From Author
It is very difficult to say whether standardised or rationalized. And now automated thing has also come in. But still I would say if any comapny is following standardised way it should shift towards Rationalised. Though there are a lot of security...
What do you use to monitor the "health" of your IT infastructure?
"GREEN IT" is an upcoming trend nowadays. So why not make our IT infrastructure more energy-efficient? But how to do it is a big doubt? Can you all please help me by giving some effective ways to do it?
more...