Theory
हर Hacker एक Criminal नहीं है
'Hacker' शब्द 'criminal' जैसा sound करता है, पर यह इतना simple नहीं है। Hackers इनके intent और इनके पास permission है या नहीं इससे classify किए जाते हैं। कुछ systems में break होते हैं harm करने के लिए; दूसरे यह, authorisation के साथ, help करने के लिए करते हैं, weaknesses ढूँढते हुए तो इन्हें fix किया जा सके।
Subject का यह closing lesson main types distinguish करता है: white hat, black hat, और बीच वाला grey hat। Distinction matter करता है: एक criminal है, दूसरा एक valued security professional है। यह subject को एक important note पर खत्म करता है, कि systems defend करने के लिए skilled, ethical hackers भी चाहिए।
At a glance
| Type | Permission? | Intent |
|---|---|---|
| White Hat (Ethical) | हाँ, authorised | Help: weaknesses ढूँढना और fix करना, security improve करना |
| Black Hat | नहीं, unauthorised | Harm: malicious या personal gain (चुराना, damage करना) |
| Grey Hat | अक्सर कोई permission नहीं | बीच में: clearly malicious नहीं, पर unauthorised |
Theory
White Hat और Black Hat
एक white hat hacker (एक ethical hacker) permission के साथ systems में break होता है, precisely criminals से पहले vulnerabilities ढूँढने के लिए, तो इन्हें fix किया जा सके। Penetration testers और security researchers white hats हैं; इनका काम legal और beneficial है, एक attacker की तरह सोचकर पर help करने के लिए act करके security strengthen करते हुए।
एक black hat hacker malicious purposes या personal gain के लिए permission के बिना break होता है, data या money चुराते हुए, damage cause करते हुए। यह वह criminal है जिसके against बाकी subject warn करता है; यह illegal और harmful है।
दोनों दो चीज़ों में differ करते हैं जो matter करती हैं: authorisation (permission या नहीं) और intent (help या harm)। एक grey hat इनके बीच बैठता है: ये बिना permission के एक system access कर सकते हैं पर बिना clear malicious intent के, उदाहरण के लिए एक flaw uninvited ढूँढना और इसे report करना, जो ethically और legally ambiguous है।
Quiz
एक security professional को एक company hire करती है इसके systems में break करने की कोशिश करने के लिए, permission के साथ, ताकि weaknesses ढूँढी और report की जा सकें तो इन्हें fix किया जा सके। यह किस तरह का hacker है?
- एक black hat, क्योंकि ये break होते हैं
- एक white hat (ethical hacker), क्योंकि ये permission के साथ और security improve करने में help करने के intent के साथ act करते हैं
- एक grey hat, क्योंकि सारे hired hackers grey होते हैं
- बिल्कुल hacker नहीं
Show the answer
एक white hat (ethical hacker), क्योंकि ये permission के साथ और security improve करने में help करने के intent के साथ act करते हैं
Permission के SAATH systems में break होना, weaknesses ढूँढने और report करने के लिए तो इन्हें fix किया जा सके, white hat (ethical) hacking है, एक legal, valuable security role (penetration testing)। Option A गलत है: एक black hat permission के BINA act करता है और harm या profit करने के malicious intent के साथ, इस authorised, helpful काम का opposite। Option C गलत है: एक grey hat typically permission के BINA act करता है (हालाँकि बिना clear malicious intent के); यहाँ hacker explicitly authorised है, इन्हें एक white hat बनाते हुए। Option D गलत है: ये काफ़ी hacker हैं, एक ethical वाला। दो deciding factors authorisation (permission) और intent (help vs harm) हैं: permission plus help करने का intent white hat का मतलब है।
Think first
Organisations White Hat Hackers को अपने Own Systems Attack करने के लिए Pay क्यों करती हैं?
अपने own systems में break करने के लिए किसी को hire करना strange लगता है। Ethical hacking इतनी valuable क्यों है? फिर tap कीजिए।
Show the answer
क्योंकि वे weaknesses ढूँढने का best तरीका जो CRIMINALS exploit करेंगे यह है कि एक skilled, trusted hacker इन्हें FIRST ढूँढे, permission के साथ, तो organisation एक real attacker के इन्हें ढूँढने और abuse करने से पहले इन्हें fix कर सके। Defenders एक hard truth face करते हैं: attackers को सिर्फ़ ONE exploitable weakness ढूँढनी होती है, जबकि defenders को इनमें से SABKO के against protect करना पड़ता है, और अपने own blind spots जानना बहुत difficult है। आप best practices follow कर सकते हैं और फिर भी एक vulnerability रख सकते हैं जो आपने कभी notice नहीं की, एक injection flaw, एक misconfiguration, एक weak authentication path, exactly वो kinds के holes जो इस subject में study किए गए। एक white hat hacker (ethical hacker) को hire किया जाता है एक attacker की तरह सोचने और act करने के लिए, actively systems probe करते हुए उन holes discover करने के लिए, पर crucially permission के SAATH और HELP करने के intent के साथ। जब ये एक weakness ढूँढते हैं, ये इसे REPORT करते हैं (exploit करने की बजाय), तो organisation इसे patch कर सके इससे पहले कि एक black hat करे। यह enormously valuable है: एक controlled, authorised test के through एक vulnerability discover और fix करना एक real breach से सीखने से कहीं better है, और कहीं cheaper है, जो data चुराता है और trust destroy करता है। Ethical hacking (penetration testing) attacker के mindset को एक defensive tool में बदल देता है, वही skills इस्तेमाल करते हुए जो harm कर सकती थीं इसके बजाय security strengthen करने के लिए। यह यह भी validate करता है कि defences realistic attack के under actually काम करते हैं, सिर्फ़ theory में नहीं। यही वजह है ethical hacking एक respected, in-demand profession है, और यही वजह है subject यहाँ खत्म होता है: cyber security सिर्फ़ walls और rules के बारे में नहीं है, इसे skilled लोग चाहिए जो attackers की तरह सोच सकें इनसे आगे रहने के लिए। एक white hat को hire करना पहले attack करने के लिए यही तरीका है अपने enemies से पहले अपनी weaknesses ढूँढने का। Better है एक friendly hacker hole ढूँढे बजाय एक criminal के।
Theory
BCA601-01 Complete
आपने subject के दोनों halves cover किए हैं: e-commerce side (concepts, I-Way, transactions, payments, SSL) और security side (cyber crimes, cyber security, attacks, vulnerabilities, और इनके पीछे के hackers)। दोनों साथ belong करते हैं, क्योंकि एक online business तभी काम करता है जब यह secure भी हो। आगे carry करने के लिए एक key takeaway: security सिर्फ़ technology नहीं बल्कि awareness और ethics भी है, और systems defend करने के लिए skilled, ethical लोग चाहिए। Online build कीजिए, पर securely build कीजिए।
Summary
Key takeaways
- Hackers intent और authorisation से classify किए जाते हैं, सभी criminal नहीं हैं।
- एक white hat (ethical hacker) permission के साथ break होता है weaknesses ढूँढने और fix करने के लिए, security improve करते हुए; legal और beneficial (penetration testers)।
- एक black hat permission के बिना break होता है malicious purposes या personal gain के लिए; illegal और harmful।
- एक grey hat बीच में बैठता है: अक्सर बिना permission के पर बिना clear malicious intent के, ethically और legally ambiguous।
- दो deciding factors authorisation (permission या नहीं) और intent (help या harm) हैं।
- Organisations white hats को criminals से पहले vulnerabilities ढूँढने के लिए hire करती हैं, तो इन्हें एक real breach से पहले fix किया जा सके।
- Memory hook: white hat permission के साथ help करता है, black hat इसके बिना harm करता है; ethical hacking criminals से पहले holes ढूँढता है।