Translate

Showing posts with label What is Hacking? Introduction & Types. Show all posts
Showing posts with label What is Hacking? Introduction & Types. Show all posts

Wednesday, 21 March 2018

Certified Ethical Hacker

Certified Ethical Hacker (CEH) is a qualification obtained by assessing the security of computer systems, using penetration testing techniques. The code for the CEH exam is 312-50, and the certification is in Version 9 as of 2016.
Penetration tests are employed by organizations that hire certified ethical hackers to penetrate networks and computer systems with the purpose of finding and fixing security vulnerabilities. The EC-Council offers another certification, known as Certified Network Defense Architect (CNDA). This certification is designed for United States Government  agencies and is available only to members of selected agencies including some private government contractors, primarily in compliance to DOD Directive 8570.01-M.

Controversy

The CEH certification has drawn criticism since inception due to higher than average preparation costs, low-tech exam registration procedures, and limited technical content within the exam itself. Some computer security professionals have objected to the term "ethical hacker" as a "contradiction in terms" Part of the controversy may arise from the older, less stigmatized, definition of hacker, which has since become synonymous with the computer criminal. According to the EC-Council, there has been an increase of careers where CEH and other ethical hacking certifications are preferred or required.
A proforma of CEH has been given in the picture as provided by the Council 

 

ELIGIBILITY CRITERIA

All the three programs, CEH, CHFI and ECSA v10 require the candidate to have two years of work experience in the Information Security domain and should be able to provide a proof of the same as validated through the application process unless the candidate attends official training.

Attend Official Training

If a candidate attends an official EC-Council training either at an Accredited Training Center, via the iClass platform, or at an approved academic institution, the candidate is eligible to attempt the relevant EC-Council exam without going through the application process.
Certification TitleCourseware PriceCourseware Store LinkMore Information is Available at:
CEH$850https://store.eccouncil.org/product/cehv10-courseware/https://www.eccouncil.org/programs/certified-ethical-hacker-ceh/
CHFI
$650 (US Market)

$718 (Europe Market)
https://store.eccouncil.org/product/chfi-v9-courseware-us-market/

https://store.eccouncil.org/product/chfi-v9-courseware-europe-market/
https://www.eccouncil.org/programs/computer-hacking-forensic-investigator-chfi/
ECSA v10$899 (Courseware + Range)https://store.eccouncil.org/product/ecsav10-e-courseware-range-only/https://www.eccouncil.org/programs/certified-security-analyst-ecsa/

Attempt Exam without Training

In order to be considered for the EC-Council exam without attending training, candidates must first be approved via the eligibility application process. The application can be found here: https://cert.eccouncil.org/Exam-Eligibility-Form.html. Prices for vouchers, links for purchasing, and websites for further information can be found below.
Certification TitleInformation Security Related ExperienceRemit a Non-Refundable Eligibility Application FeeSubmit an Eligibility Application FormRecieve a Formal Approval from EC-Council’s Cert. Dept.Exam Voucher PriceExam Voucher Store LinkMore Information is Available at:
CEH
2 years
$100
Pearson Vue voucher ($950)
ECC exam voucher ($950)
https://store.eccouncil.org/product/ceh-vue-exam-voucher

https://store.eccouncil.org/product/ceh-ecc-exam-center-voucher/
https://www.eccouncil.org/Certification/certified-ethical-hacker
CHFI
2 years
$100ECC exam voucher ($500)https://store.eccouncil.org/product/chfi-v9-ecc-exam-voucher/https://www.eccouncil.org/programs/computer-hacking-forensic-investigator-chfi
ECSA v10
2 years
$100ECC exam voucher ($999)https://store.eccouncil.org/product/ecsav10-ecc-exam-center-voucher/https://www.eccouncil.org/about-ec-council-certified-security-analyst

ELIGIBILITY PROCESS

Applicants who do not attend training must prove 2 years of work experience in the Information Security domain via the application form found here: https://cert.eccouncil.org/Exam-Eligibility-Form.html.
If further information is requested from the applicant after the application is submitted and 90 days pass with no response from the applicant, the application will be automatically rejected and a new form will have to be submitted.
On an average an application processing time would be between 5-10 working days once the verifiers on the application respond to EC-Council’s requests for information.
On the application, there is a section for the applicant to list a boss, supervisor, or department lead who will act as their verifier. EC-Council reaches out to the listed verifier to confirm the applicant’s experience.
If the application is approved, the applicant will be sent instructions on purchasing a voucher from EC-Council directly. EC-Council will then send the candidate the eligibility code and the voucher code which candidate can use to register and schedule the test.
If application is not approved, the application fee of USD 100 will not be refunded.
The approved application is valid for 3 months from the date of approval so the candidate must purchase a voucher within 3 months. After the voucher codes are released, the applicant has one year to use the codes.
Should you require the exam voucher validity to be extended, kindly contact finance@eccouncil.org before the voucher expires. Only valid vouchers can be extended.
An application extension request will require the approval of the Director of Certification.


Important Notes:
Successful applicants are required to purchase an exam voucher directly from EC-Council through the webstore at www.store.eccouncil.org
Warning:
Candidates whose voucher code does not match the details in the eligibility application and bears a different voucher code than which was provided will not be certified.
EC-Council reserves the right to revoke the certification status of candidates who attempt this exam without a valid voucher number.

Tuesday, 20 March 2018

What is EC- Council

The International Council of E-Commerce Consultants (EC-Council) is a member-based organization that certifies individuals in various information security and e-business skills. EC-Council has been certified by American National Standards Institute to meet its ANSI 17024 standard. It is the owner and creator of the world famous Certified Ethical Hacker (CEH), Computer Hacking Forensics Investigator (CHFI) and EC-Council Certified Security Analyst (ECSA)/License Penetration Tester (LPT) programs, and as well as many others programs, that are offered in over 92 countries through a training network of more than 500 training partners globally.

As of January 1st, 2012 EC-Council has trained over 120,000 individuals and certified more than 60,000 security professionals.

The International Council of Electronic Commerce Consultants (EC-Council) is a member-supported professional organization. The EC-Council is headquartered in Albuquerque, New Mexico

The EC-Council is known primarily as a professional certification body. Its best-known certification is the Certified Ethical Hacker. It also operates a series of IT security conferences, as well as the EC-Council University. EC-Council cosponsored SC Magazine's 2007 salary survey.

Certification

The EC-Council is best known for its professional certifications for the IT security field. It offers numerous certifications in a variety of fields related to IT security, including disaster recovery, secure programming, e-Business and general IT security knowledge

IT Security Professional Certifications


Certified EC-Council Instructor (CEI)
Certified Ethical Hacker (CEH)
Certified Network Defense Architect (CNDA)
Certified Secure Computer User (CSCU)
Computer Hacking Forensic Investigator (CHFI)
EC-Council Certified Chief Information Security Officer (CCISO)
EC-Council Certified Computer Investigator (ECCI)
EC-Council Certified Encryption Specialist (ECES)
EC-Council Certified Incident Handler (ECIH)
EC-Council Certified Secure Programmer-Java (ECSP)
EC-Council Certified Security Analyst (ECSA)
EC-Council Certified VOIP Professional (ECVP)
EC-Council Network Security Administrator (ENSA)
Licensed Penetration Tester (LPT)
EC council Certified Secure Computer User (CSCU)

Disaster Recovery and Business Continuity


EC-Council Disaster Recovery Professional (EDRP)

Programming Certifications

Certified Secure Application Developer (CSAD)
EC-Council Certified Secure Programmer (ECSP)

Entry Level Security Certifications

Security 5 (Security|5)
Network 5 (Network|5)
Wireless 5

Graduate Level Certifications

Fundamentals in Computer Forensics
Fundamentals in Information Security
Fundamentals in Network Security
EC-Council Certified Security Specialist (ECSS)

E-Business Certifications

Certified e-Business Professional (CEP)

Training

iClass is EC-Council's Official Training Portal.

EC-Council University

The EC-Council University, sister company to EC-Council, offers master's degrees in Security Science (MSS) and graduate certificates. The EC-Council University was founded in 2006 and is licensed by the state of New Mexico and is accredited by Distance Education Accrediting Commission (DEAC) and CHEA.
According to EC-Council, the MSS program attracted more than 150 candidates for its initial class, only six of whom were accepted. Users are required to take courses in ethical hacking and countermeasures, computer forensics and network intrusion detection. Candidates must then complete six electives to qualify for the degree along with a master's thesis, with the option to choose courses from a list that includes secure network management, security analysis and vulnerability assessment, cyberlaw, principles of e-business security, disaster recovery, project management, penetration testing, secure programming, and wireless networking

For more information visit:

*EC-Council welcomes questions, comments, and photos on our page from the community. Please note, community contributed content on this page is not the opinion nor does it represent EC-Council. EC-Council follows Facebook’s Statements of Rights and Responsibilities. EC-Council reserves the right to remove any comments. Thanks in advance for your cooperation*

What is Hacking? Introduction & Types

What is Hacking?

Hacking is identifying weakness in computer systems or networks to exploit its weaknesses to gain access
Example of Hacking: Using password cracking algorithm to gain access to a system,Using to get the access in right and wrong both the ways
Computers have become mandatory to run a successful businesses. It is not enough to have isolated computers systems, they need to be networked to facilitate communication with external businesses. This exposes them to the outside world and hacking. Hacking means using computers to commit fraudulent acts such as fraud, privacy invasion, stealing corporate/personal data, etc. Cyber crimes cost many organizations millions of dollars every year. Businesses need to protect themselves against such attacks.
Before we go any further, let’s look at some of the most commonly used terms in the world of hacking.

Who is a Hacker? Types of Hackers

Hacker is a person who finds and exploits the weakness in computer systems and/or networks to gain access. Hackers are usually skilled computer programmers with knowledge of computer security.
Hackers are classified according to the intent of their actions. The following list classifies hackers according to their intent.

1- Script Kiddie

Script Kiddies normally don’t care about hacking (if they did, they’d be Green Hats. See below.). They copy code and use it for a virus or an SQLi or something else. Script Kiddies will never hack for themselves; they’ll just download overused software (LOIC or Metasploit, for example) and watch a YouTube video on how to use it. A common Script Kiddie attack is DoSing or DDoSing (Denial of Service and Distributed Denial of Service), in which they flood an IP with so much information it collapses under the strain. This attack is frequently used by the “hacker” group Anonymous, which doesn’t help anyone’s reputation.

2- White Hat  


Also known as ethical hackers, White Hat hackers are the good guys of the hacker world. They’ll help you remove a virus or PenTest a company. Most White Hat hackers hold a college degree in IT security or computer science and must be certified to pursue a career in hacking. The most popular certification is the CEH (Certified Ethical Hacker) from the EC-Council.

3- Black Hat


Also known as crackers, these are the men and women you hear about in the news. They find banks or other companies with weak security and steal money or credit card information. The surprising truth about their methods of attack is that they often use common hacking practices they learned early on.


4- Gray Hat

Nothing is ever just black or white; the same is true in the world of hacking. Gray Hat hackers don’t steal money or information (although, sometimes they deface a website or two), yet they don’t help people for good (but, they could if they wanted to). These hackers comprise most of the hacking world, even though Black Hat hackers garner most (if not all) of the media’s attention.

5- Green Hat 


These are the hacker “n00bz,” but unlike Script Kiddies, they care about hacking and strive to become full-blown hackers. They’re often flamed by the hacker community for asking many basic questions. When their questions are answered, they’ll listen with the intent and curiosity of a child listening to family stories






6- Red Hat


These are the vigilantes of the hacker world. They’re like White Hats in that they halt Black Hats, but these folks are downright SCARY to those who have ever tried so much as PenTest. Instead of reporting 
the malicious hacker, they shut him/her down by uploading viruses, 
DoSing and accessing his/her computer to destroy it from the inside out. They leverage multiple aggressive methods that might force a cracker to need a new computer.

7- Blue Hat 


If a Script Kiddie took revenge, he/she might become a Blue Hat. Blue Hat hackers will seek vengeance on those who’ve them angry. Most Blue Hats are n00bz, but like the Script Kiddies, they have no desire to learn.





What is Cybercrime?

Cyber crime is the use of computers and networks to perform illegal activities such as spreading computer viruses, online bullying, performing unauthorized electronic fund transfers, etc. Most cybercrimes are committed through the internet. Some cybercrimes can also be carried out using Mobile phones via SMS and online chatting applications.

Type of Cybercrime:

  • The following list presents the common types of cybercrimes:
  • Computer Fraud: Intentional deception for personal gain via the use of computer systems.
  • Privacy violation: Exposing personal information such as email addresses, phone number, account details, etc. on social media, websites, etc.
  • Identity Theft: Stealing personal information from somebody and impersonating that person.
  • Sharing copyrighted files/information: This involves distributing copyright protected files such as eBooks and computer programs etc.
  • Electronic funds transfer: This involves gaining an un-authorized access to bank computer networks and making illegal fund transfers.
  • Electronic money laundering: This involves the use of the computer to launder money.
  • ATM Fraud: This involves intercepting ATM card details such as account number and PIN numbers. These details are then used to withdraw funds from the intercepted accounts.
  • Denial of Service Attacks: This involves the use of computers in multiple locations to attack servers with a view of shutting them down.
  • Spam: Sending unauthorized emails. These emails usually contain advertisements.

What is Ethical Hacking?

Ethical Hacking is identifying weakness in computer systems and/or computer networks and coming with countermeasures that protect the weaknesses. Ethical hackers must abide by the following rules.
  • Get written permission from the owner of the computer system and/or computer network before hacking.
  • Protect the privacy of the organization been hacked.
  • Transparently report all the identified weaknesses in the computer system to the organization.
  • Inform hardware and software vendors of the identified weaknesses.

Why Ethical Hacking?

  • Information is one of the most valuable assets of an organization. Keeping information secure can protect an organization’s image and save an organization a lot of money.
  • Hacking can lead to loss of business for organizations that deal in finance such as PayPal. Ethical hacking puts them a step ahead of the cyber criminals who would otherwise lead to loss of business.

Legality of Ethical Hacking

Ethical Hacking is legal if the hacker abides by the rules stipulated in the above section on the definition of ethical hacking. The International Council of E-Commerce Consultants (EC-Council) provides a certification program that tests individual’s skills. Those who pass the examination are awarded with certificates. The certificates are supposed to be renewed after some time.

Summary 

  • Hacking is identifying and exploiting weaknesses in computer systems and/or computer networks.
  • Cybercrime is committing a crime with the aid of computers and information technology infrastructure.
  • Ethical Hacking is about improving the security of computer systems and/or computer networks.
  • Ethical Hacking is legal.