Re: RE: How to stop hackers at the root cause
SneakySimian <[email protected]>
| Newsgroups | gmane.comp.security.websecurity,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
I like where this is going. I agree education is a big part of ensuring kids behave. However, enjoying offensive security myself, hacking isn't bad or something to be feared. I started out in defensive security, handling networks (wired and wireless), physical security, and web application (server configuration, secure coding, etc.) security. I managed PIX 515e's, 505's, Snort IDS sensors, TippingPoint IPS'es, Cisco 7200 and 2600 routers, various switches, researched related laws (eDiscovery, for example) and and generally acted in a role that was responsible for forensics and incident response in my workplace. While I absolutely enjoyed these responsibilities, as I continued down this road, I was asked again and again to prove a finding which led to my "popping boxes" (thanks David Kennedy for that phrase!) on our networks. This is where I got a taste and enjoyed the taste of offensive security. If I may, think of it as a yin and yang. No matter how much education you do, you are still going to have people who choose to be malicious, so you need to have those who defend the networks. However, while some may disagree, I still feel that in order to understand the motivations and techniques of those who choose to be bad, you need to learn those techniques and motivations. That's not to say that in order to understand why and how a bank robber robs banks you need to commit that crime yourself, far from it, but rather study those techniques and motivations. I like offensive security because I get to help those doing the defensive side improve their defense, so at the end of the day, I'm still a good guy. Likewise, if I were a consultant to a bank or some other high value target, I'd need to know ways that someone could breach the physical security. Do the cameras provide proper coverage? Is the alarm system going to detect someone trying to sneak by under the sensors? Can the locks on the doors provide enough protection against lock picking to give time for security/police to arrive? Are the employees susceptible to social engineering ala chocolate ( http://www.theregister.co.uk/2008/04/16/password_security/) or some smooth talker? How are you going to know for certain unless you test these things? As the old adage goes, if it ain't broke, don't fix it. But how do you know it isn't broken unless you test it? You can defend all day long which is the end goal, but it only takes one thing to go wrong for someone to get the keys to the kingdom (http://blogs.zdnet.com/security/?p=6123) and you won't find that problem necessarily unless you employ offensive techniques in addition to defensive techniques. I'm not sure that made any sort of sense at all, so feel free to ignore me. ;)