|
|
| Author |
Message |
| 5v3d3b0 |
This post is not being displayed .
|
 5v3d3b0 World Chat Champion
Joined: 24 Sep 2006 Karma :     
|
 Posted: 18:53 - 21 May 2013 Post subject: Learning how to hack without breaking the law? |
 |
|
I'm interested in pursuing a security related job in IT after uni (penetration testing, network security or something like that).
Recently I've been learning about SQL Injection a bit, and trying to expand my knowledge in my free time.
I think it would be useful for me to learn at least basic to intermediate techniques to be aware of the potential threats and vulnerabilities that I'm oblivious to now, but I can't just go on a trial and error around random websites trying to break in to their databases
I'm doing it purely for educational purposes but I don't know where/how to do it without getting in trouble.
Any ideas? |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Zen Dog |
This post is not being displayed .
|
 Zen Dog World Chat Champion

Joined: 11 Aug 2004 Karma :    
|
 Posted: 18:57 - 21 May 2013 Post subject: |
 |
|
Setup your own servers. Hack away.
Zen Dog ____________________ Current - '94 VFR750FR (Dead), '00 VFR800FI, '11 600 Hornet - Previous - '11 CBF125, '10 Street Triple R, '92 MZ ETZ301, '05 TTR250, NSR125R, KMX125, "Honda" Win
My bike trip around S.E. Asia 2010/2011 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| herulach |
This post is not being displayed .
|
 herulach World Chat Champion
Joined: 19 Apr 2010 Karma :  
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| J.M. |
This post is not being displayed .
|
 J.M. World Chat Champion

Joined: 27 Mar 2011 Karma :    
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| toshpot |
This post is not being displayed .
|
 toshpot Scooby Slapper

Joined: 12 Aug 2012 Karma :  
|
 Posted: 19:58 - 21 May 2013 Post subject: |
 |
|
Install something like damn vulnerable linux in a VM, or install anything, and install/configure known exploitable software versions locally, and you can hack away as you see fit. If you just want web based stuff, maybe Mutillidae may be more suitable?
You can grab a VPS or similar, however, the host may not appreciate that kind of thing on their networks, read the AUS and TOS if you go this route.
Keep track of software vulnerabilities using security advisories, etc.
If you also want a windows specific thing, you can probably avoid licensing issues/fees with something like NT4 or other discontinued products. ____________________ Sometimes, I touch myself and smell my fingers. |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Frost |
This post is not being displayed .
|
 Frost World Chat Champion

Joined: 26 May 2004 Karma :  
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| SQL |
This post is not being displayed .
|
 SQL World Chat Champion

Joined: 09 Aug 2012 Karma :   
|
 Posted: 20:26 - 21 May 2013 Post subject: |
 |
|
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| bazza |
This post is not being displayed .
|
 bazza World Chat Champion
Joined: 27 Aug 2004 Karma :  
|
 Posted: 23:02 - 21 May 2013 Post subject: |
 |
|
Start with the essentials:
https://www.youtube.com/watch?v=zixpms1oo40 ____________________ "That's it. You people have stood in my way long enough. I'm going to clown college."
'98 Ducati 750SS, '08 Suzuki GSX650F ©2004-2014, Bazza's Harmless Banter |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Rogerborg |
This post is not being displayed .
|
 Rogerborg nimbA

Joined: 26 Oct 2010 Karma :    
|
 Posted: 08:11 - 22 May 2013 Post subject: |
 |
|
<Geezer>I remember when hacking was just programming</Geezer>
As well as system penetration and SQL injection, I'd suggest that you take a look at application network protocol analysis as well.
We had a chap in who quite comprehensively reverse engineered our app's communication protocol by sending it sequences of data until he triggered a response, then hammered on those. He found a fair number of the holes that we already knew were in there, and also flushed out a few new ones.
Even I was moderately impressed, although in essence he was running a Very Small Shell Script and then applying some experience to the results. ____________________ Biking is 1/20th as dangerous as horse riding.
GONE: HN125-8, LF-250B, GPz 305, GPZ 500S, Burgman 400 // RIDING: F650GS (800 twin), Royal Enfield Bullet Electra 500 AVL, Ninja 250R because racebike |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| J.M. |
This post is not being displayed .
|
 J.M. World Chat Champion

Joined: 27 Mar 2011 Karma :    
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Rogerborg |
This post is not being displayed .
|
 Rogerborg nimbA

Joined: 26 Oct 2010 Karma :    
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| J.M. |
This post is not being displayed .
|
 J.M. World Chat Champion

Joined: 27 Mar 2011 Karma :    
|
 Posted: 12:32 - 22 May 2013 Post subject: |
 |
|
There needs to be some structure to the mess though.
But no. Uni exams are done now. Need to spend my time doing something. Thinking about building an app/website. Totally going to hack it. ____________________ 2004 R1 & 2018 XSR900 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Rogerborg |
This post is not being displayed .
|
 Rogerborg nimbA

Joined: 26 Oct 2010 Karma :    
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| J.M. |
This post is not being displayed .
|
 J.M. World Chat Champion

Joined: 27 Mar 2011 Karma :    
|
 Posted: 12:46 - 22 May 2013 Post subject: |
 |
|
I can work with messy providing that I don't stop. If I come back to a messy project after a week or two break I just stare at it, lost as to what is going on.
That said, now I've been coding for years, structure comes easily whilst hacking. Apply a tiny bit of refactoring here and there, good enough!
I feel sorry for my Robot Programming lecturer though. My final assignment was a mess. GUI with a graphical map and bluetooth communication protocol, implementing A* search and some voodoo localisation code... all messy as hell. Implemented on a robot I programmed to implement the bluetooth protocol I designed and just act as a droid. I think I can count the number of comments I used on one hand... which isn't usually a bad thing except the code was hard to follow to a 3rd party! I was going to refactor it but it worked better than 99% of the classes stuff so I figured I had nothing to lose. Scored 100%. 96% in the module overall  ____________________ 2004 R1 & 2018 XSR900 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| The Shaggy D.A. |
This post is not being displayed .
|
 The Shaggy D.A. Super Spammer

Joined: 12 Sep 2008 Karma :  
|
 Posted: 13:14 - 22 May 2013 Post subject: |
 |
|
https://www.smbc-comics.com/comics/20120220.gif ____________________ Chances are quite high you are not in my Monkeysphere, and I don't care about you. Don't take it personally.
Currently : Royal Enfield 350 Meteor
Previously : CB100N > CB250RS > XJ900F > GT550 > GPZ750R/1000RX > AJS M16 > R100RT > Bullet 500 > CB500 > LS650P > Bullet Electra X & YBR125 > Bullet 350 "Superstar" & YBR125 Custom > Royal Enfield Classic 500 Despatch Limited Edition (28 of 200) & CB Two-Fifty Nighthawk > ER5 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Ste |
This post is not being displayed .
|
 Ste Not Work Safe

Joined: 01 Sep 2002 Karma :    
|
 Posted: 15:08 - 22 May 2013 Post subject: Re: Learning how to hack without breaking the law? |
 |
|
Hack BCF, replace logo with nobcat.  |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| supZ |
This post is not being displayed .
|
 supZ World Chat Champion

Joined: 03 Feb 2009 Karma :   
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Alpha-9 |
This post is not being displayed .
|
 Alpha-9 Super Spammer

Joined: 19 Jan 2012 Karma :  
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| J.M. |
This post is not being displayed .
|
 J.M. World Chat Champion

Joined: 27 Mar 2011 Karma :    
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Alpha-9 |
This post is not being displayed .
|
 Alpha-9 Super Spammer

Joined: 19 Jan 2012 Karma :  
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Going |
This post is not being displayed .
|
 Going Nearly there...
Joined: 26 Feb 2012 Karma :     
|
 Posted: 19:42 - 22 May 2013 Post subject: |
 |
|
Had to watch that second one a few times just to make sure I wasn't hearing things. |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| J.M. |
This post is not being displayed .
|
 J.M. World Chat Champion

Joined: 27 Mar 2011 Karma :    
|
 Posted: 20:26 - 22 May 2013 Post subject: |
 |
|
Don't underestimate the network capabilities of a Visual Basic GUI, my good sir!  ____________________ 2004 R1 & 2018 XSR900 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
Old Thread Alert!
The last post was made 13 years, 29 days ago. Instead of replying here, would creating a new thread be more useful? |
 |
|
|