What is this document about anyway? While I was writing this document a book “Hack Proofing Your Network” was released. I haven’t been able to read it (dunno if its in print yet, and besides - everything takes a while to get to South Africa). I did however read the first chapter, as it is available to the public. In this chapter the author writes about different views on IT security - hackers, crackers, script kiddies and everything in between. I had some thoughts about this and decided that it was a good starting point for this document. I want to simplify the issue - let us forget motives at the moment, and simply look at the different characters in this play. To do this we will look at a real world analogy. Let us assume the ultimate goal is breaking into a safe (the safe is a database, a password file, confidential records or whatever).

The safe is located inside of a physical building (the computer that hosts the data). The building is located inside of a town (the computer is connected to a network). There is a path/highway leading to the town and the path connects the town to other towns and/or cities. (read Internet/Intranet). The town/city is protected by a tollgate or an inspection point (the network is protected by a firewall, screening router etc.) There might be certain residents (the police) in the town looking for suspicious activity, and reporting it to the town’s mayor (the police being an IDS, reporting attacks to the sysadmin). Buildings have their own protection methods, locks chains, and access doors (on-host firewalling, TCP wrappers, usernames and passwords). The analogy can be extended to very detailed levels, but this is not the idea.

Download Breaking into computer networks from the Internet PDF