10
Ethical Hacking Pratheeba Murugesan

Ethical hacking

Embed Size (px)

Citation preview

Page 1: Ethical hacking

Ethical Hacking Pratheeba Murugesan

Page 2: Ethical hacking

HACKER

Page 3: Ethical hacking

AENDA

What is Ethical Hacking? Who are ethical hackers? Every Website-A Target Get out of jail free card Kinds of Testing Final Report

Page 4: Ethical hacking

Ethical Hacking

Independent computer security Professionals breaking into the computer systems.

Neither damage the target systems nor steal information.

Evaluate target systems security and report back to owners about the vulnerabilities found.

Page 5: Ethical hacking

Ethical Hackers but not Criminal Hackers Completely trustworthy. Strong programming and computer

networking skills. Learn about the system and trying to

find its weaknesses. Techniques of Criminal hackers-

Detection-Prevention. Published research papers or released

security software. No Ex-hackers.

Page 6: Ethical hacking

Being Prepared What can an intruder see on the target systems? What can an intruder do with that information? Does anyone at the target notice the intruder's

attempts or successes?

1. What are you trying to protect? 2. Who are you trying to protect against? 3. How much time, effort, and money are you willing to

expend to obtain adequate protection?

Page 7: Ethical hacking

Get out of Jail free card

Security evaluation plan1. Identify system to be tested

2. How to test?

3. Limitations on that testing

Evaluation done under a “no-holds-barred” approach.

Clients should be aware of risks. Limit prior knowledge of test.

Page 8: Ethical hacking

Kinds of Testing Remote Network Remote dial-up network Local network Stolen laptop computer Social engineering Physical entry

1.Total outsider2.Semi-outsider3.Valid user

Page 9: Ethical hacking

Final Report

Collection of all discoveries made during evaluation.

Specific advice on how to close the vulnerabilities.

Testers techniques never revealed. Delivered directly to an officer of the client

organization in hard-copy form. Steps to be followed by clients in future.

Page 10: Ethical hacking

Suggestions?