Neil Barrett
Neil Barrett

Hackers aim for the head

Head hackers who worm their way into the confidence of users are a growing menace

Written by Neil Barrett

One of the most fascinating aspects of computer security is the growing interest in social engineering - "head hacking" rather than computer hacking - a topic certain to become even more important in 2004.

In one way, all computer hacking is about the human factor. Hackers succeed in hacking not just by exploiting weaknesses in computers, but also the shortcomings in the ways that those computers are managed or applications are developed.

But social engineering is slightly more than this. In head hacking, the attacker deliberately tries to fool an individual into allowing access to their computer system. Most obviously, they may do this by phoning the helpdesk and asking for assistance, pretending to be a panicking employee or a senior manager demanding access to a remote server. Clever social engineers can be surprisingly persuasive in these attempts and surprisingly persistent, phoning repeatedly to helpdesk staff over long periods of time. Moreover, even the smallest snippet of information accidentally revealed - say, that a PIN for remote access is six rather than four characters long - can be of enormous assistance to an intruder struggling with an unfamiliar and otherwise well-protected computer system.

In recent months, there have been a spate of more sophisticated measures, the most widely publicised being the attempt to infect computers with Trojan horse programs by means of email attachments that appeared to have been sent from trusted organisations - the most famous of which was the Bank of England.

This is a social engineering trick that is broadly similar to the email worms such as I Love You, which attempt to persuade recipients to open them, and more recent worms that transmitted themselves to users within victims' address books - the assumption being that even the most outre email apparently from someone whom the recipient knows might well be opened.

Hackers have many other, even more sophisticated techniques that can be applied. For example, in researching the potential vulnerabilities of a targeted organisation, hackers will often encounter a lot of information about the personal interests and hobbies - even the foibles - of certain employees. These people then become the target for focused attempts at subversion - for example, by persuading them that the hacker shares their interests. Over a period of time - and these sophisticated hackers can be extraordinarily patient - an employee can come to trust the hacker as a friend, and then either deliberately or accidentally reveal information of interest to them.

Protecting an organisation's information assets from such an insidious form of intrusion can be frustratingly difficult. After all, most information security measures are designed to block intruders, rather than protect insiders from being subverted and inadvertently revealing information.

The answer is to educate users about the risks and to adequately monitor both insiders and outsiders. It won't be easy, but companies simply cannot afford to ignore this form of attack.

Tags:

Further reading

Leniency may encourage more hackers

Soft sentences could encourage more hacking, according to experts   More...

Human errors cause most harm

History shows that data has always faced a greater threat from errant or careless staff than from determined hackers   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement