Risk

3/4/2008
02:42 PM
Tom LaSusa
Tom LaSusa
Commentary
50%
50%

Teens Still In The Hacking Biz -- On Both Sides

Way on the other side of our little blue planet, folks in New Zealand are reeling from the recent arrest of 18-year old Owen Thorn Walker, who masterminded a group of programmers that infected more than a million computers around the world.

Way on the other side of our little blue planet, folks in New Zealand are reeling from the recent arrest of 18-year old Owen Thorn Walker, who masterminded a group of programmers that infected more than a million computers around the world.Authorities contend Walker and his legion of hacking doom successfully stole banking and credit card information and manipulated stock trades. The FBI estimates the botnet they unleashed may have stolen as much as $20 million worldwide. In addition, Walker is allegedly responsible for placing advertising spam on about 1.3 million computers worldwide through systems based in the Netherlands. All total, he's looking at a decade of jail time if convicted.

John E. Dunn at Techworld.com writes "The world has been reminded that the era of the teen hacker is far from dead." Indeed, Dunn reports that just a few weeks ago a U.S. teenager plead guilty to hacking thousands of computers, including several belonging to the U.S. military.

In that case, authorities have been tight-lipped on details of the teen (hacker moniker B.D.H), leading to speculation that he's underage.

Does anyone remember that early '80s TV show Whiz Kids? The premise centered on a gang of teenage, mystery-solving computer experts. Despite their hacker-like skills, they solved crimes and used their abilities to help the helpless, defend the defenseless, and stop -- well, the stopless. Wouldn't it be nice if life imitated art?

Fortunately, for every couple of BDHs and Owen Thorns, there's a kid like Shane Kelly. This U.K. resident recently completed a Certified Ethical Hacker course, which instructs students on the various types of attacks, and how to help organizations defend against them. What makes Shane so special is that, at 16 years old, he is the youngest person to complete the course, which normally requires students to be at least 21. Shane plans to take his certification and apply it to a career in IT (helping companies defend themselves from the bad guys) and already has attracted attention of several key security executives.

We often report (read: lament) over the shortage of IT talent. With interest waning, students are dropping computer, science, and engineering courses left and right. Just as it's our responsibility as a society to make sure that there's plenty of this planet left for future generations, a similar goal for IT pros should be to cultivate interest in the technology sector among the young (lest we be forced to resort to coding via abacus). Imparting a positive attitude about our profession also can help steer these kids clear of its darker sides as well.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
To Be Ready for the Security Future, Pay Attention to the Security Past
Liz Maida, Co-founder, CEO & CTO, Uplevel Security,  9/18/2017
1.9 Billion Data Records Exposed in First Half of 2017
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/20/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Jan, check this out! I found an unhackable PC.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.