Ethical hacking is the act of locating weaknesses, scan vulnerabilities and to find potential threats on a computer and information systems or networks by the actions of malicious hackers. An ethical hacker finds the weak points or loopholes in a computer, web applications or network and send reports to the organization. So, let’s explore more about Ethical Hacking step-by-step.
If you give a hacker a new toy, the first thing he’ll do is to take it apart to figure out how it works.
-Jamie Zawinski
types of hackers

“WHITE HAT” is an internet slang which means an ethical hacker, or a computer security expert. Usually, a white hat hacker specialises in pentesting.
White hackers may also work in teams called “sneaker”, “red teams” or “tiger teams“.
In simple words they use their skills to improve security by exposing vulnerabilities before malicious hackers (black hat hackers) can detect an exploit them.

“BLACK HAT”term is often attributed to contrast the exploitative hacker with the white hat hacker who hacks protectively.
Here, the organization doesn’t allow the user to test it. They unethically enter inside the website and steal data from the admin panel or manipulate the data.
They only focus on themselves and the advantages they will get from the personal data for personal financial gain.

“GREY HAT”is derived from the concepts of “white hat” & “black hat” who may sometimes violate laws or ethical standards, but does not have malicious intent like a black hat hacker.
WHITE HAT breaks into a system with explicit permission to determine how secure it is against hackers.
BLACK HAT breaks into a system in order to uncover sensitive information & for personal gain.
GREY HAT has the skills & intent of the white hat but will break into any system or network without permission.
types of hacking
Now that we have discussed different types of hackers, let’s discuss different types of hacking. We can segregate hacking into different types depending on what the hacker is trying to achieve.
- PASSWORD HACKING It is the process of recovering passwords from data that have been stored in or transmitted by a computer system.
- WEBSITE HACKING It means taking unauthorized control over a web server and its softwares such as databases and other interfaces.
- NETWORK HACKING It means any technical effort to gather information about a network by using tools like Ping, Tracert, Netstat, etc. with the intent to harm the network system and hamper its operation.
- EMAIL HACKING It means unauthorized access to an Email account and manipulating it without taking the consent of its owner for sending out spam links, third-party threats, and other such harmful activities.
- COMPUTER HACKING It is the process of getting unauthorized access to a computer system for stealing computer ID, exploiting weaknesses and password by applying hacking methods .
Most hackers are young because young people tend to be adaptable. As long as you remain adaptable, you can always be a good hacker.
-Emmanuel Goldstein, Dear Hacker: letters to the Editor of 2600
PHASES OF ETHICAL HACKING
Ethical hacking is divided into 6 distinct phases.
- Reconnaissance
- Internet sources
- Social Engineering
- Dumpster diving
- Observation
- Scanning
- Port scanners
- Vulnerability scanners
- Network mappers
- Gaining Access
- Exploiting vulnerability
- Breaking into weakly secured network
- Sending malware to target
- Maintaining Access
- Privilege escalation
- Installing a backdoor or remote access trojan
- Creating own credentials
- Covering Access/Clearing Tracks
- Remove logging
- Exfiltration of data via DNS tunnelling or Steganography
- Reporting
BOOKS FOR reference
There is no single book that you can refer to learn ethical hacking. If you prefer books, then you need to read various books to learn several books. For example, for web apps & web application “Hacker’s Handbook” and also “OWASP Guide”. For shellcoding, the book called “Shellcoder’s handbook”.
Few of the books are:
- Hacking: The Art of Exploitation This is considered to be greatest hacking book of all time. Unlike others it spends more time explaining technical foundation and how things work. from inside.
- The basics Of hacking and penetration testing : This is probably the best hacking book for beginners because it covers wide range of topics on penetration testing and instructs you on how to perform an ethical hack.
- Black hat python: Python programming for hackers and pentesters This book explains the application of python language in exploitation and pentesting.
TOP 3 ETHICAL HACKING EXAMS
1. Certified Ethical Hacking Certification
CEH is one among the oldest, most popular and superlative certification programs that can be provided for ethical hackers. A person who has acquired a certification in this course would be a skilled professional who can understand on how to look at vulnerabilities and weaknesses in target systems and uses the identical knowledge and tools as a malicious hacker but in a more legit and lawful manner so as to evaluate the security posture of a target system.
The CEH qualification confirms that individuals as certified in the specific network security discipline of Ethical Hacking from a vendor-neutral standpoint. The CEH informs the public that the certified individual meets minimum criteria. It also helps reinforce ethical hacking as an exclusive and self-regulating profession. This course will help you to think into the mindset of a hacker. After all, if you need to be a hacker, you need to think like one! This will enable you to defend against future attacks. This course will put you in a control with hands-on environment with a systematic process. You will definitely be exposed to a totally different way of attaining optimum information security posture in their organization. That is by hacking it. You will be taught the phases of hacking as mentioned earlier. And the objective of this course is to assist you to grasp the ethical hacking methods that can be used in a penetration testing or ethical hacking situation. Earning this internationally recognized cert means obtaining ethical hacking knowledge and skills that are in high demand now.
2. GIAC Penetration Tester
SANS GPEN is another type of certification provided under ethical hacking. SysAdmin, Networking, and Security (SANS) is an institute which offers multiple course and certifications with GIAC Penetration Tester (GPEN) being the most popular one. It mainly covers in-depth technique approaches to verifying the entire way up through reporting and scoping. The main objectives to learn under GPEN are attacking password hashes, advanced password attacks, initial target scanning, exploitation fundamentals, pen-testing foundations, vulnerability scanning, moving files with exploits, penetration testing using the Windows command line and power shell, reconnaissance, and web application attacks.
3. Offensive Security Certified Professional
OSCP has been only about 10 years, but it has already gained good reputation for durability and toughness. It contains practical training and exam. The Offensive security certified professional course teaches how to attain, alter and apply public exploit code. This course also offers advanced pen testing exams and courses such as wireless, web, advanced Windows exploitation. The OSCP is designed to show the students’ practical, accurate, precise and clear understanding of the penetration testing process and life-cycle through a strenuous twenty-four (24) hour certification exam. So, to conclude, this certification proves that its holder is able to recognize vulnerabilities, generate and alter exploit code, exploit hosts, and successfully accomplish tasks on the compromised systems over several operating systems.
Good information guys
Keep building sutffs like tis
LikeLike
Informative
LikeLike
Informative
LikeLike
Informative
LikeLike