99% of hackers are script kiddies. They run batches of known exploits against your infrastructure if you have any or use other tools that help them coordinate spear fishing attacks and whatnot. This is doubly true about any hacks you read about in the mass media.
In the 99.5% range you will run into people who are capable of crafting their own sql injection attacks or potentially a buffer overflow attack if the system they are attempting to gain entry too is written in something that actually allows that. From that point on you get into ivory tower shit and complicated exploits to steal or reveal asymmetric keys in cryptographic exchange systems and complicated man in the middle attacks that almost always rely on them having access to layer 2 hardware on ISP networks or having gained physical access to the system they are compromising. Very few people i would consider actual hackers and certainly no one from the Antifa or BLM crowd as they are being handed tools to use by Government organizations if indeed they have ever pulled off an actual hack.
couldnt agree more!
I'm going to put up a tiny bit of poser music now, but the lyrics are on point with the discussion.
I really enjoy the beginning dig on buzzwords, makes me chuckle everytime: https://youtu.be/PXA0G21jA0E
I'm honestly delighted to see that other people see what I see.
Its hilarious when someone says you aren't a hacker because you dont know metasploit, lol, because you dont need it.
My path was carding, then chasing 'legit hacks' for personal internal cred (knowledge of self), sql injection was years back as you noted, these days I'm happy to jam into memory and poke around. You make a fine point about 'prior knowledge' and 'physical access', my frustration with many "hacks" is exactly this.
I poked around with it in the 80's beige boxing and hacking payphones and stuff. Im a programmer now and took some pretty intense exploit programming courses in college at the post graduate level in the early 2000's when they still required programmers to know how networking and computers work even down to the metal. Mostly I don't partake in the white or black hat game other than to fuck with the white hats at work and as your song says their "threat models" lol and how they are always signing up for some new security service to protect them while they let indian contractors write shit that does dumb stuff like parse xml files out of public facing ftp servers.
(post is archived)