Chapter 01: Ethical Hacking Overview
mentioning laws and regulations is to make sure you’re aware of the dangers of being a security tester.
– Hacking wireless networks
– Viruses and worms
– Physical security
– Hacking Linux
– Intrusion detection systems (IDSs), firewalls, and honeypots
– Buffer overflows
– Cryptography
– Penetration-testing methodologies
35. What is the SANS Institutes “Top 25 Software Errors” list?
One of the most popular SANS Institute documents is the Top 25 Software Errors list, which describes the
most common network exploits and suggests ways of correcting vulnerabilities. This list offers a wealth of
information for penetration testers or security professionals.
36. A Security professional may think they are following the requirements set forth by the client who hired
them to perform a security test, don’t assume that management will be happy with the test results. Provide an
example of an ethical hacking situation that might upset a manager.
One tester was reprimanded by a manager who was upset that the security testing revealed all the user names
and passwords to the tester. The manager believed that the tester shouldn’t know this information and
considered stopping the security testing.
37. Describe some actions which security testers cannot perform legally.
Accessing a computer without permission, destroying data, or copying information without the owner’s
permission is illegal. Certain actions are illegal, such as installing worms or viruses on a computer network
that deny users access to network resources. As a security tester, you must be careful that your actions do not
prevent customers from doing their jobs. For example, DoS attacks should not be initiated on your customer’s
networks.
38. Why is it a challenge and concern for an ethical hacker to avoid breaking any laws?
Because the job of an ethical hacker is fairly new, the laws are constantly changing. Even though a company
has hired you to test its network for vulnerabilities, be careful that you aren’t breaking any laws for your state
or country. If you’re worried that one of your tests might slow down the network because of excessive
bandwidth use, that concern should signal a red flag. The company might consider suing you for lost time or
monies caused by this delay.
39. What are four different skills a security tester needs to be successful?
– Knowledge of network and computer technology
– Ability to communicate with management and IT personnel
– An understanding of the laws that apply to your location
– Ability to apply the necessary tools to perform your tasks
40. Why should a security professional or student learning hacking techniques be aware of the local, state, and
federal laws that apply to their field of study?
Laws are written to protect society, but often the written words are open to interpretation. Having some
hacking tools on your computer might be illegal. You should contact local law enforcement agencies and ask
about the laws governing your state or country before installing hacking tools on your computer. The point of