Aqua
JF-Expert Member
- Jul 23, 2012
- 1,657
- 1,236
Its no secret that unsecured servers may be hacked in as little as a few minutes. But even secure servers are vulnerable, thanks to a slew of common oversights.
Ethical, white hat hacker Asher de Metz lead senior consultant, information security, Sungard Availability Services (Sungard AS) exploits these mistakes to uncover clients vulnerabilities.
Ethical hackers must think deviously like criminals, yet be very honorable, reputable people, de Metz says. Never a black hat (criminal) hacker, de Metz began his IT career as a systems administrator building large global networks for clients throughout the world. That gave me a fantastic knowledge base to go into information security, he says.
White hat hackers view the world differently than traditional security experts. De Metz says that hackers see computer systems in terms of informational vulnerabilities. He says that defenders focus on intrusion detection systems, log management systems and firewalls big things that ultimately, are only the icing on the cake.Yet he adds that defenders often have the wrong priorities. Defenders need to focus on the basics first, de Metz says.
De Metz runs penetration tests for Sunguard clients. That involves hacking internal networks and Internet-facing services, as well as infiltrating buildings, he says.
Much of the time, he uses social engineering techniques to trick employees into revealing passwords via phishing emails and ostensible calls from the help desk asking for users private log-in information, he says. Once my team understands the vulnerabilities, we write a report showing how we broke into the system and what the organization must do to improve its security.
[h=2]Mistake 1: Unhardened systems[/h]Those reports often detail vulnerabilities resulting from unhardened systems (which by definition allow access to unnecessary sites and applications) from which administrators failed to log off, unpatched systems and weak passwords.
I can easily access unhardened systems through security mistakes like leaving open software that allows attackers to upload malware, de Metz says.
This can happen when website administrators dont close an application after uploading or editing a Web page or after altering services. I find these open applications either by a brute force attack that tries combinations of numbers or directories, or by browsing the Web for files that contains known file names, URLs and directories, like /admin1.
[h=2]Mistake 2: Out-of-date security patches[/h]Unpatched systems offer another way in. I was just at a company that hadnt installed security patches since 2003! de Metz says. Ironically, at another company, I recently hacked into the IT systems through its unpatched vulnerability scanner, which checks for unpatched systems.
With proper data center documentation, administrators would have been aware of that lapse and could have fixed it. However, few data centers have the robust inventories and application documentation they need. Organizations have this basic step for granted. If they dont know whats there, they cant patch it, de Metz says.
This applies to servers as well as applications. Its not uncommon to find an old server running in a data center without anyone knowing whats on it or which department owns it. Yet, de Metz says, nearly every server carries useful information that may help a hacker exploit a vulnerability. For example, a hacker with an outdated password may be able to use it to access an old machine and, from there, enter the broader network.
[h=2]Mistake 3: Obvious or missing passwords[/h]The trend nowadays is to protect not only the machine but the data. But the plethora of passwords designed to fool hackers may not be documented or updated to reflect changing levels of authorization. For instance, When we test clients systems, we add ourselves to the active password domain, de Metz says. When we return a year later, were often still there. IT didnt delete us as users. That happens when employees leave or transfer, too, particularly when they have multiple accounts.
Despite years of warnings about crafting robust passwords, end-users and even administrators still fail to use passwords, use the default passwords or use easy-to-guess passwords. These are huge security mistakes, de Metz says.
A lot of people still believe theyll never be hacked. But, in fact, its quite likely, de Metz says. White hat hackers, however, find the vulnerabilities to help reduce those odds.
source