Skip to main content

Command Palette

Search for a command to run...

Common Hacking Techniques πŸ€—

Published
β€’2 min readβ€’View as Markdown
S

Just a girl studying InfoSystems at the University of Utah.

I like learning about Linux and System Administration

Hey Hashnode πŸ€—

I am starting to learn more about Security!πŸ’… Security definitely goes hand in hand with Linux, so starting today, I will be releasing Security Articles the more I learn about it!

Today, I will be going over COMMON hacking techniques. 😎

1. Phishing 🎣

Phishing is probably the most common way someone can get hacked or tricked into giving personal information. This is the practice of pretending to be a well known company and emailing people to get information, like credit card numbers.

2. Keylogger πŸ”‘

Keyloggers are programs that track the movement of your keyboard. So if you are to enter in a password or credit card information, this program logs every key stroke

3. Fake W.A.P πŸ“Ά

WAP stands for fake wireless access point. Basically, a fake 'wifi' network in public, and once you connect to it your information can get stolen and malware can be installed on your device

4. Password Spraying πŸ’»

In this method, hackers will try the same password on many different accounts before they finally get in.

5. Social Engineering πŸ”

Social engineering is not exactly a traditional cyberattack- but it's manipulating someone into giving personal out or confidential information

That is it for my first Security Article! Thank you for reading this far πŸŽ‰

For future Linux and Security articles! Give me a follow @linuxeb on twitter and Hashnode. I post content weekly. πŸ₯³

S

One of my "favorite" is id scanning. It's so simple... When I was a teen we wanted to call the 1-900 numbers (they were 056 in my area). So we found out that each of those numbers had a regular "technical support" number that was free.

We started calling phone number in the area e.g. if the support number was 03-555-5555 we'd try 03-555-5554 and onwards and the other direction 03-555-5556 and on...

The phone company would issue numbers in bulk and they would usually be in sequence. So we were able to dial in without charge (and find out it was super lame).

ID scanning is the same thing. You have user ID 99876. Then you try the same API call or web request with 99877 etc. This surprisingly works really well and was used to hack many companies in the past.

The solution is simple: don't use numeric ids. Use UUID or even a hash if you're super paranoid.

1