Saturday, May 10, 2014

Extra hacking info

Hey everyone-In class I mentioned how things are developed with vulnerabilities built into them half the time. I forgot the videos title that I have watched about this sort of thing but I have finally remembered. If you google or youtube search " To protect and infect" You will see a 3 part video series of some very interesting topic. I hope everyone has a great summer and it was great having class with you all.

Tuesday, May 6, 2014

Revised Ethical Post


I believe in civilization. In a civilized and moral correct form of interactions with one another. I believe people that want to reflect good moral qualities should strive for: Integrity, responsibility, fairness, friendship and the mutual security of each other. Because of my moral views the only option I have with my new knowledge is to use it in a way that reflects my previously motioned values.  

I have the moral responsibility to use my new technical skills responsibly. I try at least for the most part of my time being morally righteous as a person to the best of my abilities. Is kind of like being tough to drive a tank and to know that my new knowledge can only be used in a responsible and morally correct manner other ways the new skills can cause me and the people around me unnecessary problems. Is just like discussed before, having the ability to do something and knowing that you can get away with it doesn’t make it right when you do it. I have acquired more knowledge on how to analyze, secure, and pen test a computer network.

A Door We Must Choose Ourselves - A Revisit

A power indeed we have learned, for the dark side is as tasty as the light. Although not as epic as the powers Jedis hold, I have learned a great deal from this class. These skills that I have learned have opened many doors for me. These doors, however, are no longer simply labeled as good and bad, dark and light, but rather each of these doors hold a cautionary question: "Is this ethical?"

In general, I would not perform actions on networks and computers if they have analogous actions performed on homes or organizations that I would reject; homes or organizations are defined by their property lines. As such, intrusive actions are analogous to entering someone's property, while non intrusive actions are analogous to actions performed from outside the property. Just as I would only enter a home if let in, I would only enter a network or computer if I was let in. In most cases, the method of entrance to a home or network is determined either explicitly by the home owner, or at the location the agreement to enter was made at, in either case there in a clear means and agreement of entering. As such I only enter computers or networks that I have been given explicit consent, and by extension the mode of entrance. Once inside a property, the rules of interaction are sometimes explicitly noted upon entry. There are some situations where someone is explicitly given power such as a administrator, or penetration tester. Thankfully, I do not plan on working within the IT fields. I do not wish to be put in situations where I must pick between upholding job efficiency and retaining moral code. But if I were, I would choose to uphold the privacy of people as much as I can and only breach such conditions if it was clear and imminent that the person or people risk the safety of others or breach any rules of the property. I hold this analogous to being a security guard, I would not peek into a bathroom stall unless it was clear and imminent that the person was performing actions that either endangered others or violated the organization's rules. I for one would not work for an organization who's rules did not have a clear purpose, or if they had obscure rules but did not explicitly and clearly state these rules. If these rules are not clear as a non administrator, I would proceed with caution and try to figure them out. Just as I try not to make too many assumptions when in someone's house I will not make too many assumptions in another's network or computer. I will often limit my actions to common actions performed by non enlightened personnel, so no hacking or scanning when inside a network or computer.

Non-intrusive actions are fair to me. Just as there are fences you can lean on an buildings you can look at, there are parts of a system that you are allowed to interact with such as ports. So any information gathering is fair game as long as it's information that is publicly available. And port scanning is fair game. Since I know these skills I have the responsibility to inform people if I do find any vulnerabilities when scanning. I also do not consider these vulnerabilities as open doors but instead a closed door with a faulty lock. In both cases I would not take advantage of the problem.

Although many consider packet sniffing fair game, thinking that the information is in free air, that it is information that is available to collect and decrypt. I think otherwise as I think this analogous to finding a delivery truck and opening the letters inside. So no, I do not consider packet sniffing acceptable and I would not do it.

To summarize, any information that is publicly available is fair to interact with, any intrusive action must be given explicit consent, and any vulnerabilities I find must be reported accordingly. This outline of my actions are of course a mere guideline and put into many theoretical settings. My actual actions will be based on much more than what is outlined and will require information such as the purpose of performing such actions as well who it affects and the level of communication with the people effected.

Below is a reflection I previous wrote in the original version of this post:

Throughout the class we learned how to hack. We learned how to search for vulnerabilities within a network, and exploit them. We learned that through old and possibly current systems, we are able to access the internal information not available to the public. In many cases, these actions are deemed illegal outside a virtual or closed environment. And to most, the combination of the words "hacking" and "illegal" induce an almost automatic response to labeling these actions as "bad" or unethical. But early in the class we realized that these lines are not as defined as we thought. We watched a documentary for class on Anonymous and their hacktivism. Through this film and our discussion, the class came to the understanding that laws regarding technology, just like all laws, can come under scrutiny and that its status as a law does not define it as unethical. We also ran through the scenario of being a penetration tester. We assume that since it is our job to test a system, and that we have a certain level of access to their information, that what we do is okay. But does this make it okay to sift through personal information that may be within the bounds of your contract as well? What if you realize that the company you work for runs a shady business in the side, but you are contractually obligated not to divulge any information found in the network. This is where our lines begin to blur, and where we began to paint our own lines. Because without this guideline, the task of determining what is right and what is wrong no longer default to the law, but instead it is determined by our own hands. This is our first responsibility: judging our own actions.




In class we learned how to collect packets that are sent over the network that are not necessarily meant for us. There are some arguments that suggest that these packets are free for the taking since they are in free air, and that the information in public space is public as well. But we can also liken this situation to playing catch, when we throw the ball to our friend, do we loose ownership of the ball? We ran through many similar situations regarding property, but what was apparent to me is that our current view on technological philosophy is ancient. This is our second responsibility, moving forward our philosophical views on technology.

Final Ethical Power Revised

What sorts of moral responsibilities come with the hacking powers you have acquired this semester?  Be specific and precise!  What powers have you acquired?  What responsibilities do you take on with those powers?

In this semester i have learn a lots of thing , such hacking and social engineering task. The hacking power come with  a lot abilities and responsibilities. In this semester we learn about what is ethical hacking is and what is good and bad is. As i learn ability to hack, also come with some responsibility such as when can you used this power and what low allowed to do with power.Hacking is very big deal it can used for bad thing, so we have careful when we used and who to tell. Other Power I have acquired this semester is Social Engineering. Social Engineering is very power full a person can have. This Power we can do lot of thing we take lot of information about company just by calling at company. we can used for good or bad of this abilities. In my opinion leaning this semester is we have to take responsibility.we have to thing if am not crossing  the line and what right and wrong. What is moral value.  Moral value are principle and standers  which determine whether is right or wrong.  When we have more power we have responsibility. so it depend on what principle and stander you follow.  my moral value depend on religion., so if i tried to hack some one computer , but my religion  does't let me.
i always follow the what is good  and be honest. In the class we did  social engineering task some of the task i couldn't because it was right for me and my principle. I learn a lot of think that doing social engineering that i didn't have  power  before ,  I learn how take information from and communicate. taking information it not easy, but good power to have, because you can do anything  without  hacking. reputability of this power is  we us it good way or   bad way. my principle is use good way. let other know people what could do just by taking and taking your information. 

Last Ethics Assignment (REVISED)

What sorts of moral responsibilities come with the hacking powers you have acquired this semester?  Be specific and precise!  What powers have you acquired?  What responsibilities do you take on with those powers?


The only powers I have acquired this semester is lying and tricking people into giving me information. To be honest, I don't consider them powers because people do them on a daily basis (unfortunately). Real powers would be powers people everyday wouldn't have like flying themselves up in the air, x-ray vision, super strength, transformation, and etc. Those are the kinds of power that saves people's lives. If I had super strength, my moral responsible would be to help prevent violence in the city. As a super hero, I believe in helping ours in times of trouble, being kind and honest. Although, there are pros to lying and trickery in ethic hacking. As ethical hackers, we are responsible for knowing different types of tools and techniques to help prevent computer networks from being attacked. We are responsible for upholding contracts for different companies we work for. We should never use what we learn in ethic hacking in vein, only to help others.






















Final Ethics (Revised)


           Throughout the semester, we have been exposed to an intense training on how to become ethical hackers. With the support of our two great professors, the training was full of both theory and practical sessions. What is an ethical hacker? By definition, an ethical hacker is a computer and network expert who attacks a security system on behalf of its owners, seeking vulnerabilities that a malicious hacker could exploit. To test a security system, ethical hackers use the same methods as their less principled counterparts, but report problems instead of taking advantage of them. Ethical hacking is also known as penetration testingintrusion testing and red teaming. Today, as ethical hackers, we are asked about the sorts of moral responsibilities that come with the hacking powers we have acquired this semester. What powers have we acquired?  What responsibilities do we take on with those powers?

            First of all, let’s talk about those powers acquired. In this semester, we got to understand two main part of the exercise, which are ethics and hacking (technical). When talking hacking, we developed the skills of doing penetration testing, brutal force attacks, network sniffing, password cracking, victim exploitation, sql Injection, social engineering, DDOS Attacks (Distributed Denial Of Services), etc. With these skills, we have the power of attacking, disabling, stealing, change or destroying as well as defending information in networks and systems infrastructures.

            Secondary, the ethics part we acquired a better understanding of topics with which the ethical hacker interacts. Talking about property, a thing or things belonging to someone, an entity, or an organization. Since the ethical hacker doesn’t own a systems or a network infrastructure, he has no right to attack or still or destroy its information, unless the owner (organization) asks him to do so. How would the owner ask an ethical hacker to do a penetration testing or an sql injection, etc? There comes the term “contract”, a written agreement or commitment, especially one concerning employment, sales, or tenancy in which parties must sign, and which is intended to be enforceable by law. So when a scope is defined and agreed upon by a client or an organization and an ethical hacker, both parties are bound to this agreement or contract by showing consents. Contracts have boundaries meaning that the hacking is not supposed to do a task that doesn’t fall under the scope of the work, as well as the client have towards him.

            Finally, we learned about justice, which means doing something just, or right, or fair. As an ethical hacker, I have the power to do bad things but morally unless I’m permitted to do so, I wouldn’t do them to anyone’s property. So my responsibilities are to keep my moral and cultural values as I live in a society which has rules and regulations. My moral values are based on my personal system of honesty and integrity. Therefore I maintain a high degree of awareness to perform only the mutually negotiated items of our signed contract. In order to maintain a good relationship with customers and what is right. The culture in which I was raised has consistently stressed the importance of honesty and integrity which reinforces the way in which I would honor my professional contract with customers. Doing something which will offence someone would make me feel bad!

N.Y

Final ethics post



Original post:
The power I feel with the hacking powers I’ve learned is to my friends, family, and loved ones. I feel like I have a responsibility to let them know that these things, such as SQL attacks and password crackers, and people who do these types of things and more, are out there and they can cause major problems. I feel the need to tell my loved ones that they need to be careful with the way they use computers of any form. I’ve been continuously sharing with friends and family (especially my parents) throughout this course about various things and how they can protect themselves. That is my biggest thing. I don’t want people I know and care about to get ripped off by thieves online. Any of the hacking powers I have obtained, I have no intention of using, unless it is in a working manner when I have permission to do so. Any social engineering I would do is just me being me – being friendly. That’s just the type of person I am. I wouldn’t use any information I gathered against people, that wouldn’t be right, and quite frankly it is beneath my character.

What do you believe?  What are your values? 
Simply put, I believe there is a right way to treat people and a wrong way to treat people. I try to treat people how I would want to be treated. I try to be nice to people. I try to be fair to people. I may joke around about certain things, and if someone gets hurt, that’s unfortunate, but it certainly wasn’t on purpose. I definitely don’t believe in doing something, just because you can – as one of our ethics questions earlier this season asked. I actually like the example PZB used in class about this subject when he discussed milk – if a person needs milk and they have the money to go buy it at the store, of course I would have no problem with that, but if the person steals milk from a store or otherwise, just because they can get away with it, that’s wrong. I would say it is wrong regardless of why it is needed and regardless if a person has a family to feed and they are in dire straits financially. I can understand an argument for that last scenario, but personally I wouldn’t see myself doing it. Then again, I’m a single person living alone and maybe I would feel differently if I did actually have a family to feed and things  got to that point.
The above is also how I feel about hacking and the computer world as well. Just because a person has the ability to trick people or hack into people’s systems, that doesn’t mean they should do it. As I’ve stated in class – although I realize it is unrealistic, I don’t believe IT security and related professions should even be needed because people shouldn’t be trying to access other people’s information or flat out steal from other people, that’s just not how I was brought up. When I was younger I did my fair share of downloading music that I shouldn’t have. It was kind of the thing to do, and at that point I didn’t realize it wasn’t supposed to be happening. Now, any music I download is from iTunes and I pay for it. I’ve told people this, and they look at me funny and say I’m stupid. I might be stupid, but at least I’m honest.
Hopefully all of the above fulfills what I was supposed to write about in this assignment – now for this: 

 Now, why is that the case?  Why is that the right thing to do?

So, why is all of that important to me? Again, it goes back to my parents and how I was raised. I was raised to earn an honest living, not take from others. I’m not saying I’m a perfect person, far from it, but I do my best to live a virtues life, and I try to surround myself with friends who are the same way.
Think about it this way, how does it feel when you get your information or money or secrets or whatever stolen from you? How does that make you feel? My guess would be pretty crappy or pretty upset or hurt or violated or some combination of all of the above. I leave you with this, why would you want to do that to someone else, and make them feel that way?