Wall Street &
Technology
November, 1998
(pgs 32-34)
Are You Threatening Me ?
(
and my system )
"The detested hacker,
mythical bane of network
security, isn't the most pressing threat to proprietary
information. According to security experts, most
firms' biggest problems come from within."
"The obvious solution to this problem is to limit
trust as much as possible."
Top
10 "Exploits"
"A program designed to exploit the vulnerability of a
computer network or a network of
computers."
"These are readily available for download, for free, off of the
Internet. These and many more exploits are all available at
Web sites like www.rootshell.com."
BACK ORIFICE:
A set of programs specially designed to provide a hacker with
unauthorized access and control of Windows 95/98/NT based
computers over a network.
PASSWORD SNIFFERS:
A whole category of programs designed to "catch" passwords
as they fly by on a network so they can be used later for
unauthorized access.
WINHACK GOLD:
A very useful program designed to scan entire networks
looking for all files that can be accessed.
NETWORK SCANNERS:
An entire class of programs designed to look for, and identify
servers that can be readily accessed.
CISCOCRACK.C:
A program designed to decrypt Cisco router passwords so
access can be gained and exploited.
DECEIT.C:
A program designed to fool you into disclosing your password
over a secure network.
CHANGEMAC:
A program designed to fool a highly secure network into
thinking you are someone else (i.e.: a good guy).
SYN FLOOD:
A program designed to remotely flood a computer's network
port to the point that it can no longer communicate and must
be restarted.
SMURF:
A series of programs designed to make a network attack itself.
PING OF DEATH:
A network "ping" program designed to crash a computer or
entire network.