Re: RE: How to stop hackers at the root cause

SneakySimian <[email protected]>
Newsgroups gmane.comp.security.websecurity,gmane.comp.security.web-applications
Message-ID <[email protected]>
I like where this is going. I agree education is a big part of ensuring kids
behave. However, enjoying offensive security myself, hacking isn't bad or
something to be feared.

I started out in defensive security, handling networks (wired and wireless),
physical security, and web application (server configuration, secure coding,
etc.) security. I managed PIX 515e's, 505's, Snort IDS sensors, TippingPoint
IPS'es, Cisco 7200 and 2600 routers, various switches, researched related
laws (eDiscovery, for example) and and generally acted in a role that was
responsible for forensics and incident response in my workplace. While I
absolutely enjoyed these responsibilities, as I continued down this road, I
was asked again and again to prove a finding which led to my "popping boxes"
(thanks David Kennedy for that phrase!) on our networks. This is where I got
a taste and enjoyed the taste of offensive security.

If I may, think of it as a yin and yang. No matter how much education you
do, you are still going to have people who choose to be malicious, so you
need to have those who defend the networks. However, while some may
disagree, I still feel that in order to understand the motivations and
techniques of those who choose to be bad, you need to learn those techniques
and motivations. That's not to say that in order to understand why and how a
bank robber robs banks you need to commit that crime yourself, far from it,
but rather study those techniques and motivations. I like offensive security
because I get to help those doing the defensive side improve their defense,
so at the end of the day, I'm still a good guy. Likewise, if I were a
consultant to a bank or some other high value target, I'd need to know ways
that someone could breach the physical security. Do the cameras provide
proper coverage? Is the alarm system going to detect someone trying to sneak
by under the sensors? Can the locks on the doors provide enough protection
against lock picking to give time for security/police to arrive? Are the
employees susceptible to social engineering ala chocolate (
http://www.theregister.co.uk/2008/04/16/password_security/) or some smooth
talker? How are you going to know for certain unless you test these things?

As the old adage goes, if it ain't broke, don't fix it. But how do you know
it isn't broken unless you test it? You can defend all day long which is the
end goal, but it only takes one thing to go wrong for someone to get the
keys to the kingdom (http://blogs.zdnet.com/security/?p=6123) and you won't
find that problem necessarily unless you employ offensive techniques in
addition to defensive techniques.

I'm not sure that made any sort of sense at all, so feel free to ignore me.
;)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.