Hack in Progress - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Hardware & Infrastructure
04:10 PM

Hack in Progress

Just how easy is it to break into your company's networks? Hire a hacker, then sit tight.

The SetUp
Ryan Breed is a hacker. He's honed his skills since his undergraduate days at the University of Rochester, where a cryptography course piqued his interest in network security. Breed, 28, enjoys the analysis of computer systems and "decomposing systems and figuring out how they work."

Ryan Breed -- Photo by Ken Schles

As a security consultant for Unisys, hacker Breed tests his mettle against company security systems, pointing out weak spots.

Photo of Ryan Breed by Ken Schles
He's gearing up to do his thing. But this evening's hack is sanctioned, commissioned, and paid for by the targeted company. Breed is an ethical hacker, a security consultant for Unisys, and tonight he's conducting a penetration test on an international business-consulting firm with 10 servers and more than 150 desktops. The name of the company and information that would disclose its identity have been withheld at the company's request.

The scene is the third-floor conference room of a building in a suburban office park. It's a hot and humid July night. Seated around the wood-grained conference table, opposite Breed, are three people: the financial officer of the company, a director, and the company's IT manager. Breed's black Dell notebook is hooked up to a projector that displays what's happening on his screen on the wall.

The Hack
Breed likes his work. You can see it in his eyes as he readies his PC on the table. The notebook holds a few hints of his personality, such as a copy of the shoot-'em-up game Quake III, as well as the tools of his trade, such as a network-protocol analyzer named Ethereal and a tool called NetStumbler, an app that's used to find wireless networks. "That's standard issue," he says. "It's a must-have." You get the impression Breed carries around plenty of these "standard-issue" tools.

Surprisingly, the first tool Breed employs is Google.com. "Google is great for researching a company," he explains. "You can often catch information about the corporate domains and find interesting things that reference other sites that the company may be connected to."

Another of Breed's favorite places for preattack recon, he says, is a company's help-wanted ads for IT jobs. "You'll find out what kind of software and systems they run from the skills and experience they're seeking in their IT job listings," he says. Another tactic is scanning Internet message boards on financial sites such as Yahoo and seeking out sites set up by ex-employees. "There's lots of information about any corporation; it's all over and easily found if you just go and look for it."

The hacker-for-hire doesn't find much of interest in his Google search. He then looks up the company's domain name to see what he can find at Whois.net. "I'm looking for targets," he says. The Whois search reveals a contact name and a pair of domain servers.

"Why is that information available?" asks the company's director, surprised that domain-server information is so easily accessible. The IT manager explains that such information is commonly available on the Net.

As Breed clicks away on his notebook, he lets an occasional grin surface, lifts his eyebrows, and crinkles his forehead. After jotting down the domain addresses, he takes an educated guess at what may be the block of network addresses on the company's system. He launches Nmap, or Network Mapper, and begins sweeping to see what his guess may turn over. Nmap uses IP packets to see what operating systems the network is running, what servers are connected to it, what services and ports are available, even whether packet filters and firewalls are in place.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
1 of 3
Comment  | 
Print  | 
More Insights
State of the Cloud
State of the Cloud
Cloud has drastically changed how IT organizations consume and deploy services in the digital age. This research report will delve into public, private and hybrid cloud adoption trends, with a special focus on infrastructure as a service and its role in the enterprise. Find out the challenges organizations are experiencing, and the technologies and strategies they are using to manage and mitigate those challenges today.
What Becomes of CFOs During Digital Transformation?
Joao-Pierre S. Ruth, Senior Writer,  2/4/2020
Fighting the Coronavirus with Analytics and GIS
Jessica Davis, Senior Editor, Enterprise Apps,  2/3/2020
IT Careers: 10 Job Skills in High Demand This Year
Cynthia Harvey, Freelance Journalist, InformationWeek,  2/3/2020
Register for InformationWeek Newsletters
Current Issue
IT Careers: Tech Drives Constant Change
Advances in information technology and management concepts mean that IT professionals must update their skill sets, even their career goals on an almost yearly basis. In this IT Trend Report, experts share advice on how IT pros can keep up with this every-changing job market. Read it today!
White Papers
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll