fbpx
Wikipedia

Black hat (computer security)

A black hat (black hat hacker or blackhat) is a computer hacker who violates laws or ethical standards for nefarious purposes, such as cybercrime, cyberwarfare, or malice. These acts can range from piracy to identify theft. A Black hat is often referred to as a "cracker".[1]

The term originates from 1950s westerns, with "bad guys" (criminals) typically depicted as having worn black hats and "good guys" (heroes) wearing white ones. In the same way, black hat hacking is contrasted with the more ethical white hat approach to hacking. Additionally, there exists a third category, called grey hat hacking, characterized by individuals who hack, usually with good intentions but by illegal means.[2][3][4]

Description edit

Criminals who intentionally enter computer networks with malicious intent are known as "black hat hackers".[5] They may distribute malware that steals data (particularly login credentials), financial information, or personal information (such as passwords or credit card numbers). This information is often sold on the dark web. Malware can also be used to hold computers hostage or destroy files. Some hackers may also modify or destroy data in addition to stealing it. While hacking has become an important tool for governments to gather intelligence, black hats tend to work alone or with organized crime groups for financial gain.[2][6]

Black hat hackers may be novices or experienced criminals. They are usually competent infiltrators of computer networks and can circumvent security protocols. They may create malware, a form of software that enables illegitimate access to computer networks, enables the monitoring of victims' online activities, and may lock infected devices. Black hat hackers can be involved in cyber espionage or protests in addition to pursuing personal or financial gain.[7] For some hackers, cybercrime may be an addictive experience.[citation needed]

History edit

 
Countries initially affected by the WannaCry ransomware attack

One of the earliest and most notorious black hat hacks was the 1979 hacking of The Ark by Kevin Mitnick. The Ark computer system was used by Digital Equipment Corporation (DEC) to develop the RSTS/E operating system software.

The WannaCry ransomware attack in May 2017 is another example of black hat hacking. Around 400,000 computers in 150 countries were infected within two weeks. The creation of decryption tools by security experts within days limited the extortion payments to approximately $120,000, or slightly more than 1% of the potential payout.[8]

The notable data breaches typically published by major news services are the work of black hat hackers. In a data breach, hackers can steal the financial, personal, or digital information of customers, patients, and constituents. The hackers can then use this information to smear a business or government agency, sell it on the dark web, or extort money from businesses, government agencies, or individuals.[9] The United States experienced a record number of 1,862 data breaches in 2021, according to the Identity Theft Resource Center's 2021 Data Breach Report. Data breaches have been on the rise for some time[timeframe?]. From 2013 to 2014, black hat hackers broke into Yahoo and stole 3 billion customer records, making it possibly the largest data breach ever.[10] In addition, the adult website Adult FriendFinder was hacked in October 2016, and over 412 million customer records were taken.[10] A data breach that occurred between May and July 2017 exposed more than 145 million customer records, making the national credit bureau Equifax another victim of black hat hacking.[10]

Strategies edit

Concealing edit

One of the most famous black hat methods is to utilize nasty "doorway pages", which are intended to rank highly for specific search queries. Accordingly, the substance of these doorway pages is stowed away from both the clients and the web indexes. Doorway pages are designed to deceive search engines so that they cannot index or rank a website for synonymous keywords or phrases.

Keyword stuffing edit

Another form of black hat search engine optimization (SEO) is known as keyword stuffing, which involves repeatedly using the same keywords to try to trick search engines. This tactic involves using irrelevant keywords on a webpage (such as on the homepage or in metadata tags) to make it appear more relevant for particular keywords, deceiving people who visit the site.[11]

Link farming edit

Link farming occurs when multiple websites or pages link to a particular website. This is done to profit from the pay-per-click (PPC) advertisements on these websites or pages. The issue is that the links only point to the specific website because it promises something in return, when in fact they are only there to increase traffic to the desired website and its popularity. These websites are unethical and will damage the credibility of the website's other pages, possibly reducing its income potential.

Shrouding edit

Shrouding involves showing different content to clients and web search tools. A website may present search engines with information irrelevant to the website's real content. This is done to boost the website's visibility in search results.

Spamdexing edit

Spamdexing is a form of black hat SEO that involves using software to inject backlinks to a website into search engine results. This is done solely to raise the website's ranking in search engines.

Unethical redirects edit

A redirect link is considered unethical if it takes the user to a webpage different from the one indicated in the link. For instance, it is unethical to have a link that should take the user to the website "ABC" but instead takes them to "XYZ". Users are tricked into following an unintended path, even though they might not be interested in the website they land on.

Examples of famous black hats edit

 
Kevin Mitnick
  • Kevin Mitnick is one of the most well-known black hat hackers. At one point, he was the most wanted cybercriminal in the world. He hacked into over forty major corporations, including Motorola and IBM, and even the US National Defense warning system. He was taken into custody and incarcerated in 1995. He became a cybersecurity consultant after his release in 2001, utilizing his hacking expertise for white hat hacking.[12]
  • Vladimir Levin is a Russian hacker who, while working with a dial-up connection and a laptop from his Saint Petersburg apartment in 1994, accessed the accounts of several large corporate customers of Citibank, stealing USD$10.7 million. He ended up spending three years in jail. However, in 2005, an anonymous hacker group claimed responsibility for the theft, stating that they only sold Vladimir the data needed to steal the money.[citation needed]

Other hat types edit

White hat edit

An ethical security hacker is referred to as a white hat or white hat hacker. The term "ethical hacking" is meant to mean more than just penetration testing. White hat hackers aim to discover any flaws in the current system with the owner's permission. Many organizations engage white hat hackers to enhance their network security through activities such as vulnerability assessments. Their primary objective is to assist the organization.[13] While a black hat will illegally exploit a vulnerability or instruct others on how to do so, a white hat hacker will only exploit it with permission and will not reveal its existence until it has been fixed. Teams known as "sneakers and/or hacker clubs," "red teams," or "tiger teams" are also common among white-hat hackers.[citation needed]

Grey hat edit

A grey hat is a hacker who typically does not have malicious intent but often violates laws or common ethical standards. A vulnerability will not be illegally exploited by a grey hat, nor will it instruct others on how to do so; however, the grey hat may trade this information for personal gain.[14] A special group of gray hats are hacktivists, who hack to promote social change.[3]

The ideas of "white hat" and "black hat" hackers led to the use of the term "grey hat" at the end of the 1990s.

Another difference between these types of hackers is how they find vulnerabilities. The black hat will break into any system or network to uncover sensitive information for personal gain, whereas the white hat does so at the request of their employer or with explicit permission to determine how secure it is against hackers. The grey hat typically possesses the white hat's skills and intentions and the black hat's disregard for permission or laws.[4] A grey hat hacker might request organizations for voluntary compensation for their activities.[15]

See also edit

References edit

  1. ^ Sheikh, Ahmed (2021), "Introduction to Ethical Hacking", Certified Ethical Hacker (CEH) Preparation Guide, Berkeley, CA: Apress, pp. 1–9, doi:10.1007/978-1-4842-7258-9_1, ISBN 978-1-4842-7257-2, S2CID 239755067, retrieved 2024-03-08
  2. ^ a b "What is a Black-Hat hacker?". www.kaspersky.com. 2022-02-09. Retrieved 2022-11-27.
  3. ^ a b testovaniebezpecnosti (2017-11-10). "Hackers are not just the bad guys – brief history and classification". HackTrophy (in Slovak). Retrieved 2022-11-27.
  4. ^ a b Luciano, Michael (2018-09-05). "What Are the Three Types of Hackers?". Design World. Retrieved 2022-11-27.
  5. ^ "Black hat, White hat, and Gray hat hackers – Definition and Explanation". www.kaspersky.com. 2022-05-11. Retrieved 2022-11-27.
  6. ^ "Kevin Mitnick - Once the world's most wanted hacker, now he's getting paid to hack companies legally | Black Hat Ethical Hacking | Black Hat Ethical Hacking". 2020-09-14. Retrieved 2024-01-09.
  7. ^ "What is a black hat hacker?". SearchSecurity. Retrieved 2022-11-27.
  8. ^ "What is WannaCry ransomware?". www.kaspersky.com. 2022-02-09. Retrieved 2022-11-27.
  9. ^ Espinosa, Christian (2018-03-09). "Black Hat vs White Hat Hackers". Alpine Security. Retrieved 2022-11-27.
  10. ^ a b c "Biggest Data Breaches in US History [Updated 2022] | UpGuard". www.upguard.com. Retrieved 2022-11-27.
  11. ^ "Black hat SEO". Twaino. 2022-06-06. Retrieved 2022-11-27.
  12. ^ Greenberg, Andy. "Kevin Mitnick, Once the World's Most Wanted Hacker, Is Now Selling Zero-Day Exploits". Wired. ISSN 1059-1028. Retrieved 2022-11-27.
  13. ^ Banda, Raphael; Phiri, Jackson; Nyirenda, Mayumbo; Kabemba, Monica M. (2019-03-07). "Technological Paradox of Hackers Begetting Hackers: A Case of Ethical and Unethical Hackers and their Subtle Tools". Zambia ICT Journal. 3 (1): 40–51. doi:10.33260/zictjournal.v3i1.74. ISSN 2616-2156.
  14. ^ "What is an ethical hacker and what does the work entail?". SearchSecurity. Retrieved 2022-11-27.
  15. ^ Hanusch, Yonnique Francesca (2021-04-03). "Financial institutions should decline hackers' requests for voluntary compensation". South African Journal of Philosophy. 40 (2): 162–170. doi:10.1080/02580136.2021.1933733. ISSN 0258-0136. S2CID 235676146.

black, computer, security, blackhat, redirects, here, other, uses, black, black, black, hacker, blackhat, computer, hacker, violates, laws, ethical, standards, nefarious, purposes, such, cybercrime, cyberwarfare, malice, these, acts, range, from, piracy, ident. Blackhat redirects here For other uses see Black hat A black hat black hat hacker or blackhat is a computer hacker who violates laws or ethical standards for nefarious purposes such as cybercrime cyberwarfare or malice These acts can range from piracy to identify theft A Black hat is often referred to as a cracker 1 The term originates from 1950s westerns with bad guys criminals typically depicted as having worn black hats and good guys heroes wearing white ones In the same way black hat hacking is contrasted with the more ethical white hat approach to hacking Additionally there exists a third category called grey hat hacking characterized by individuals who hack usually with good intentions but by illegal means 2 3 4 Contents 1 Description 2 History 3 Strategies 3 1 Concealing 3 2 Keyword stuffing 3 3 Link farming 3 4 Shrouding 3 5 Spamdexing 3 6 Unethical redirects 4 Examples of famous black hats 5 Other hat types 5 1 White hat 5 2 Grey hat 6 See also 7 ReferencesDescription editCriminals who intentionally enter computer networks with malicious intent are known as black hat hackers 5 They may distribute malware that steals data particularly login credentials financial information or personal information such as passwords or credit card numbers This information is often sold on the dark web Malware can also be used to hold computers hostage or destroy files Some hackers may also modify or destroy data in addition to stealing it While hacking has become an important tool for governments to gather intelligence black hats tend to work alone or with organized crime groups for financial gain 2 6 Black hat hackers may be novices or experienced criminals They are usually competent infiltrators of computer networks and can circumvent security protocols They may create malware a form of software that enables illegitimate access to computer networks enables the monitoring of victims online activities and may lock infected devices Black hat hackers can be involved in cyber espionage or protests in addition to pursuing personal or financial gain 7 For some hackers cybercrime may be an addictive experience citation needed History edit nbsp Countries initially affected by the WannaCry ransomware attack One of the earliest and most notorious black hat hacks was the 1979 hacking of The Ark by Kevin Mitnick The Ark computer system was used by Digital Equipment Corporation DEC to develop the RSTS E operating system software The WannaCry ransomware attack in May 2017 is another example of black hat hacking Around 400 000 computers in 150 countries were infected within two weeks The creation of decryption tools by security experts within days limited the extortion payments to approximately 120 000 or slightly more than 1 of the potential payout 8 The notable data breaches typically published by major news services are the work of black hat hackers In a data breach hackers can steal the financial personal or digital information of customers patients and constituents The hackers can then use this information to smear a business or government agency sell it on the dark web or extort money from businesses government agencies or individuals 9 The United States experienced a record number of 1 862 data breaches in 2021 according to the Identity Theft Resource Center s 2021 Data Breach Report Data breaches have been on the rise for some time timeframe From 2013 to 2014 black hat hackers broke into Yahoo and stole 3 billion customer records making it possibly the largest data breach ever 10 In addition the adult website Adult FriendFinder was hacked in October 2016 and over 412 million customer records were taken 10 A data breach that occurred between May and July 2017 exposed more than 145 million customer records making the national credit bureau Equifax another victim of black hat hacking 10 Strategies editConcealing edit One of the most famous black hat methods is to utilize nasty doorway pages which are intended to rank highly for specific search queries Accordingly the substance of these doorway pages is stowed away from both the clients and the web indexes Doorway pages are designed to deceive search engines so that they cannot index or rank a website for synonymous keywords or phrases Keyword stuffing edit Another form of black hat search engine optimization SEO is known as keyword stuffing which involves repeatedly using the same keywords to try to trick search engines This tactic involves using irrelevant keywords on a webpage such as on the homepage or in metadata tags to make it appear more relevant for particular keywords deceiving people who visit the site 11 Link farming edit Link farming occurs when multiple websites or pages link to a particular website This is done to profit from the pay per click PPC advertisements on these websites or pages The issue is that the links only point to the specific website because it promises something in return when in fact they are only there to increase traffic to the desired website and its popularity These websites are unethical and will damage the credibility of the website s other pages possibly reducing its income potential Shrouding edit Shrouding involves showing different content to clients and web search tools A website may present search engines with information irrelevant to the website s real content This is done to boost the website s visibility in search results Spamdexing edit Spamdexing is a form of black hat SEO that involves using software to inject backlinks to a website into search engine results This is done solely to raise the website s ranking in search engines Unethical redirects edit A redirect link is considered unethical if it takes the user to a webpage different from the one indicated in the link For instance it is unethical to have a link that should take the user to the website ABC but instead takes them to XYZ Users are tricked into following an unintended path even though they might not be interested in the website they land on Examples of famous black hats edit nbsp Kevin Mitnick Kevin Mitnick is one of the most well known black hat hackers At one point he was the most wanted cybercriminal in the world He hacked into over forty major corporations including Motorola and IBM and even the US National Defense warning system He was taken into custody and incarcerated in 1995 He became a cybersecurity consultant after his release in 2001 utilizing his hacking expertise for white hat hacking 12 Vladimir Levin is a Russian hacker who while working with a dial up connection and a laptop from his Saint Petersburg apartment in 1994 accessed the accounts of several large corporate customers of Citibank stealing USD 10 7 million He ended up spending three years in jail However in 2005 an anonymous hacker group claimed responsibility for the theft stating that they only sold Vladimir the data needed to steal the money citation needed Other hat types editWhite hat edit An ethical security hacker is referred to as a white hat or white hat hacker The term ethical hacking is meant to mean more than just penetration testing White hat hackers aim to discover any flaws in the current system with the owner s permission Many organizations engage white hat hackers to enhance their network security through activities such as vulnerability assessments Their primary objective is to assist the organization 13 While a black hat will illegally exploit a vulnerability or instruct others on how to do so a white hat hacker will only exploit it with permission and will not reveal its existence until it has been fixed Teams known as sneakers and or hacker clubs red teams or tiger teams are also common among white hat hackers citation needed Grey hat edit A grey hat is a hacker who typically does not have malicious intent but often violates laws or common ethical standards A vulnerability will not be illegally exploited by a grey hat nor will it instruct others on how to do so however the grey hat may trade this information for personal gain 14 A special group of gray hats are hacktivists who hack to promote social change 3 The ideas of white hat and black hat hackers led to the use of the term grey hat at the end of the 1990s Another difference between these types of hackers is how they find vulnerabilities The black hat will break into any system or network to uncover sensitive information for personal gain whereas the white hat does so at the request of their employer or with explicit permission to determine how secure it is against hackers The grey hat typically possesses the white hat s skills and intentions and the black hat s disregard for permission or laws 4 A grey hat hacker might request organizations for voluntary compensation for their activities 15 See also editBlueHat Cybercrime CyberwarfareReferences edit Sheikh Ahmed 2021 Introduction to Ethical Hacking Certified Ethical Hacker CEH Preparation Guide Berkeley CA Apress pp 1 9 doi 10 1007 978 1 4842 7258 9 1 ISBN 978 1 4842 7257 2 S2CID 239755067 retrieved 2024 03 08 a b What is a Black Hat hacker www kaspersky com 2022 02 09 Retrieved 2022 11 27 a b testovaniebezpecnosti 2017 11 10 Hackers are not just the bad guys brief history and classification HackTrophy in Slovak Retrieved 2022 11 27 a b Luciano Michael 2018 09 05 What Are the Three Types of Hackers Design World Retrieved 2022 11 27 Black hat White hat and Gray hat hackers Definition and Explanation www kaspersky com 2022 05 11 Retrieved 2022 11 27 Kevin Mitnick Once the world s most wanted hacker now he s getting paid to hack companies legally Black Hat Ethical Hacking Black Hat Ethical Hacking 2020 09 14 Retrieved 2024 01 09 What is a black hat hacker SearchSecurity Retrieved 2022 11 27 What is WannaCry ransomware www kaspersky com 2022 02 09 Retrieved 2022 11 27 Espinosa Christian 2018 03 09 Black Hat vs White Hat Hackers Alpine Security Retrieved 2022 11 27 a b c Biggest Data Breaches in US History Updated 2022 UpGuard www upguard com Retrieved 2022 11 27 Black hat SEO Twaino 2022 06 06 Retrieved 2022 11 27 Greenberg Andy Kevin Mitnick Once the World s Most Wanted Hacker Is Now Selling Zero Day Exploits Wired ISSN 1059 1028 Retrieved 2022 11 27 Banda Raphael Phiri Jackson Nyirenda Mayumbo Kabemba Monica M 2019 03 07 Technological Paradox of Hackers Begetting Hackers A Case of Ethical and Unethical Hackers and their Subtle Tools Zambia ICT Journal 3 1 40 51 doi 10 33260 zictjournal v3i1 74 ISSN 2616 2156 What is an ethical hacker and what does the work entail SearchSecurity Retrieved 2022 11 27 Hanusch Yonnique Francesca 2021 04 03 Financial institutions should decline hackers requests for voluntary compensation South African Journal of Philosophy 40 2 162 170 doi 10 1080 02580136 2021 1933733 ISSN 0258 0136 S2CID 235676146 Retrieved from https en wikipedia org w index php title Black hat computer security amp oldid 1223202101, wikipedia, wiki, book, books, library,

article

, read, download, free, free download, mp3, video, mp4, 3gp, jpg, jpeg, gif, png, picture, music, song, movie, book, game, games.