Penetration testing

Apart from sounding slightly rude its what I am learning more about.

Many businesses will I hope have given some thought about this and how to protect their Computer network from hackers.

For the home users, many have not gone further than making sure (I hope) that their wireless router is password protected and they have a firewall

and a virus checker.

 

In my view this is not really enough. I have mentioned some of the issues on the web-security.html page but more could be done.

To aid with my learning more and to offer some basic penetration testing I have some software and hardware kit to aid with this.

 

Risks outside the home

Basically the risk is high when you are out and about and hooking up to the free or cheap WiFi hotspot on offer. Ask yourself this question am I actually logged on to the correct one and not a bogus one with the same name etc? Is there anyone listening in on your net traffic between the host and your laptop or smart phone? 'Man in the middle attacks'. If you think having a  https connection is the way to go, well think again. The 'Man in the middle' could be your https server and is capturing those details before passing them onto your bank and your none the wiser!

 

Risks within the home

I have and much has been said in the media but some the biggest threats are 'social engineering' that handy 'app' for Facebook and just plain hacking into your network at home and much much more. recently a friend had her Facebook hacked and a message sent to all her contacts. I was one of those and it was a link which would when clicked would install this app or something... well I did not go any further as I did not want my own Facebook account hacked!

I have yet to contact the young lady to find out how she got hacked in the first place but I suspect someone either guessed or stole her password or more likely the usefull/fun app that got installed. I keep folks posted when I find out. UPDATE - The trail went back further back than her, a Facebook friend was hacked and on it went!

 


 

For those that are worried I might have some fun or whatever hacking into their computer, network or smartphone.

1. I would not without permission and what limits I am allowed to go. (it is against the law folks! so don't do it, 'NotW! hack!, prison! cover up!')

2. I expect to be paid for any advice or testing I do.

3. Any hacking I do is for none evil purposes anyway and I want to protect myself and my friends and clients from such evils.

 


 

PS.

Some would say get a MAC but network hacks don't really care what computer you use.