Read up on the latest ideas and technologies from companies that sell hardware, software and services. Social Networking Guide for IT Managers
Revolutionising Back-up and Recovery
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Radicati Market Quadrant 2008 on Corporate Web Security
Email Archiving Technical Overview
Strategies for Eliminating .PST Files
How to Beef Up Your Sales Pipeline
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
I recently attended a local meeting of the Information Systems Audit and Control Association (ISACA) to hear a presentation by Mark Loveless, who heads up the Razor research team at BindView.
As well as talking about the many daunting threats that face security administrators, Loveless also spoke about the changing nature of the hackers and groups that are causing security threats.
Many hackers are known as "black-hat" hackers, those who generally hack systems for personal gain or malicious reasons. The black-hat hacker either exploits these hacks for themselves or trades or sells that information.
A "gray-hat" hacker hacks systems and software without the administrator's or developer's permission in order to uncover network or software problems. Many of these hackers used to operate alone but now work for organized crime, foreign governments, or spammers.
According to Loveless, the black-market price for exploit code for a known flaw -- such as some of the recently announced Internet Explorer flaws -- is between US$100 and US$500. That's the price if no exploit code is currently available; after the exploit code is made available on public forums, the price drops to zero, under the "carrying coals to Newcastle" principle of economics.
Exploit code for an unknown flaw is -- not surprisingly -- considerably more valuable: Prices for unknown exploits range between US$1,000 and US$5,000. Among the buyers of those codes are various foreign governments, foreign and domestic organized crime groups, and iDefense, a company that buys the exploits then informs its clients of the flaw.
Want to know who has your e-mail address? Get in line. A list of 5,000 IP addresses of computers infected with spyware and ready and able to go into "bot" mode goes for US$150 to US$500.
If you're in the black market for a list of 1,000 working credit card numbers, expect to fork over between US$500 and US$5,000. Some sites even will send you a couple of free numbers to test drive prior to purchase, Loveless says, while others have rating services of the different credit card number sellers, much like eBay.
Prices were even cheaper for those numbers, although the price has increased since the U.S. Secret Service began Operation Firewall, an investigation that targets underground hacker organizations known as Shadowcrew, Carderplanet, and Darkprofits.
What do these black-hat hackers working for spammers make for their trouble? According to Loveless, the annual salary of a top-end, skilled black-hat hacker working for spammers is between US$100,000 and US$200,000. Not bad -- although if you are caught, legal costs will eat that up in a matter of weeks.
Apparently not all black-hat hackers are making the big bucks, however. I spoke recently with Dr. Bill Hancock, Savvis Communications's chief security officer and chairman of the FCC's National Reliability & Interoperability Council (NRIC) Homeland Security focus group on cyber-security, who says some black-hat hackers are wearing their hats under protest.
Hancock had dinner with a hacker from Eastern Europe last year who said the Russian Mafia threatened his family if he did not perform work for them. "I think it shows how serious and how difficult a problem this can be," he says.
Indeed, but it still pays to know your foe.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Frost & Sullivan Gears up for Annual IT Industry Gala Awards Event 2008-10-07 08:29:00+10
Multimedia Technology & EVERKI sign exclusive distribution agreement. 2008-10-06 14:34:00+10
ONCE A YEAR OPPORTUNITY TO SPEAK TO THE VENDORS! 2008-10-06 13:48:00+10
New IBM Cognos Analytic Application Enables Quick, Actionable Insights Into Financial Performance 2008-10-03 14:41:00+10
Verizon Business Data-Breach Report Examines Industry-Specific Challenges 2008-10-03 12:24:00+10
How to Beef Up Your Sales Pipeline
Our economy may be heading towards a recession. Sales rates are dropping. Promotional campaigns are proving less effective than you would like. So how do you continue to grow your business and bring home the sales in such an environment? Download this white paper now to find the answers.











