blank blank blank blank Government Security
blank
   Home         Technology Front         On The Homefront         Click here to Subscribe         Media Kit         Free Product Information       
blank
blank blank blank blank
blank blank blank
blank blank blank blank
blank
blank blank blank blank
blank blank Access Control & Security Systems Online Directory blank
blank

blank
blank blank blank blank
blank blank In the News blank
blank blank blank blank
blank
blank blank blank blank
blank blank
Mayors, states still squabbling over Homeland funding

New Hampshire to implement first responder communications network

The Democratic candidates on security

Terrorists planning to assemble bombs on planes

TSA takes heat for background check miscues

ACLU blasts Louisiana for traffic camera proposal

Community colleges offer Homeland security education

Bush proposes billions more for Homeland security

DHS to launch Cyber Alert System

Security concerns ground six Saturday flights

Mayors' survey says cities still on short end of Homeland funding

Customs slip-ups let hijackers into U.S., commission says

GAO says government not ready for Net security system

Countries worry that U.S. security will hamper free trade

Bush to deliver "State of Secure Union" tonight

Air Force to adopt ASIS International CPP program

Mail room security stepped up in European Parliament

New Years brought search for dirty bombs

Maritime security deadline passes with little action

US-VISIT implemented nationwide

Government security market continues growth

U.S. nuclear labs facing another review

Airport security chiefs removed from duty

High alert for the holidays

New standards for general aviation security

Pennsylvania brings public, private security together

Task Force: Government not taking advantage of info sharing technology

ASIS develops guide for Homeland security advisories

College laboratory security lacking, investigators say

Grants awarded to urban areas, metro transit authorities

DHS looking for ideas from small business

DHS to allocate $2.2 billion in state grants

TSA to go off duty in LaGuardia

Capitol police to change policies after toy gun incident

Customs turns to technology for shipping containers

DHS prepares to implement US-VISIT

Final maritime security regulations released

Flight attendants lament lack of training, poor security

Box cutter incident puts airport security under microscope

Federal study finds security flaws at NY bio facility

Security taking shape for Democratic Convention

Ridge urges companies to disclose cyber-security efforts

Expert says public health the weakest link in Homeland security

TSA considers measures for increased air cargo security

GAO finds security holes in nuclear plants

TSA under fire, but still focused on technology

DHS establishes Terrorist Screening Center

Congress hammers out DHS funding details

Stowaway sheds light on air security hole

GAO issues transportation security update

U.S. 'icon parks' lacking security

DHS announces new security initiatives

LAX gets massive reimbursement for detection machines

Intercity buses get security grants

New York governor contemplates security for electricity generators

Coast Guard: Passenger ferries a prime target

Representative sees vulnerability in some air cargo

NSA cyber-chief ready to de-bug government infrastructure

Terrorists again targeting airlines

Senate approves $28.5 billion in Homeland Security funding

Think tank gives Bush "D" on Homeland security report card

Additional Funds for Seaport Cargo Security Released

Homeland Security Contracts Vendors to Secure Borders

DHS encourages investment in technologies with Safety Act

Port security regulations include technology upgrades

National Emergency Training Center can help security professionals

Military launches cyber-security campaign

Report: Lack of funding leaves first responders unprepared

Ashcroft: Technology Helping In Anti-Terrorism Effort

Coast Guard, maritime officials discuss new security rules

U.S. Customs releases new shipping regulations

Homeland Security Procurement: A Guide

Homeland defense securing lobbyists

Homeland Security Stocks Soaring

Ashcroft: Technology helping in anti-terrorism effort

House subcommittee approves DHS funding bill

DHS unveils new cyber security division

Seaport security funding may be redirected

Sept. 11 panel questions federal airport security

Proposed ship security worries maritime industry

FBI issues alert to nuclear plant operators

Guard services firm supports legislation for background checks

Bush proposes legislation for chemical plant security

Homeland security to boost technology spending

Ridge: Military advances in Iraq do not diminish risk of terrorism at home

DHS awards urban areas with extra funding

Twenty-two federal agencies merge with DHS

blank
blank

blank

Beware of Script Kiddies

 Michael Fickes

Access Control & Security Systems, May 1, 2003

Print-friendly format E-mail this information

Internet security experts call them a host of names: wannabe hackers, Internet vandals, criminals and nuisances. But the term “script-kiddies” may describe them best.

Last March, someone broke into a computer at the National Security Agency in Ft. Meade, Md., and made off with materials from the public affairs office including biographies and some unclassified e-mail correspondence.

Government officials did not appear to consider the breach a security threat. The hackers, however, posted the stolen materials around the Internet with a message boasting about the break-in.

The incident may have embarrassed the NSA, but then, who cares if information in the public affairs office is made public? After all, isn't that the goal?

Sounds like a script kiddie caper.

Maybe, says Chris Shutters, chief engineer with Polivec Inc., Mountain View, Calif., a company that helps businesses to automate information technology (IT) security policies. “That's the kind of thing script kiddies do,” Shutters says. “They want to perform an unauthorized or malicious act against a computer system but often don't have the technical skills to pull it off.”

Script kiddies are a hacker subset. They attack systems when they can, for bragging rights, or political reasons. Unlike their counterparts, script kiddies need technical help.

Skilled hackers often succeed in figuring out ways to break into computer systems. When successful, they sometimes produce scripts or software applications that automate their methods of attack and post them on Internet Web sites for anyone to use.

Script kiddies use these scripts but often don't understand everything the scripts will do, says William Orvis, senior security specialist with the Lawrence Livermore National Laboratory in Livermore, Calif. A script kiddie might want to break into a system and look around — in secret — but could end up shutting the system down by accident, thanks to an unnoticed feature in the script.

The NSA break-in in March had script kiddie fingerprints of a different sort. Whoever carried out that attack felt the urge to brag about it in the media despite the innocuous results.

“A good hacker is like a savvy car thief who can get past a ‘Club’ and other security systems,” says Bill Murray, a spokesperson for the FBI's cyber division. “A script kiddy is more like a car thief testing door handles to find the car that has been left unlocked.”

In other words, to counter script kiddies, system administrators must lock the doors to the computer system.

“We advocate firewalls, anti-virus protection, and strong passwords with more than eight characters combining upper and lower case letters, numbers, and symbols,” Murray says.

Orvis also recommends keeping up-to-date on system patches supplied by operating system vendors. “Suppose someone runs a program called Winnuke and types in the address of an un-patched Windows box on your network,” says Orvis. “The computer will go blue screen.”

Operating system vendors regularly issue patches or security updates designed to protect against specific kinds of attack programs such as Winnuke.

In fact, most of the newer operating systems can update patches on their own — Windows 2000, for example, will automatically check the Microsoft Web site for newly-issued security patches, and the computer can be set to download and install those patches as they become available.

“The fact that a company issues a security update means that someone knows how to do bad things to your system, and that's what leads to scripts,” Shutters says.

In addition to these basic script kiddie defenses, Shutters recommends turning off unnecessary Internet servers connected to a network. “If it's turned off, a script kiddie can't break into it.”

Shutters also points out that network software has grown so complex that system administrators may not know about all the portals a hacker might find to crawl through. “One of our clients built a network system, and the installation process added 14 network services that the administrator didn't know were there,” Shutters says.

Finally, Shutters suggests taking a hacker's view of a system and looking for ways to break in. Many script kiddies use software called vulnerability scanners, he says. By typing a computer's Internet address into the scanner, such a program will search for and report back on weaknesses of a particular server or a series of servers. “Then a script kiddie will launch scripts at those weak spots,” he says. “If a system administrator runs the vulnerability scanner first, it's possible to fix problems before script kiddies find them.”



© 2008, Primedia Business Magazines and Media, a PRIMEDIA company. All rights reserved. This article is protected by United States copyright and other intellectual property laws and may not be reproduced, rewritten, distributed, redisseminated, transmitted, displayed, published or broadcast, directly or indirectly, in any medium without the prior written permission of PRIMEDIA Business Corp.

Get Copyright Clearance Want to use this article? Click here for options!
© 2008, PRIMEDIA Business Magazines & Media Inc.

Print-friendly format E-mail this information
Brought to you by:

blank
blank blank blank blank
blank blank Take our Online Poll! blank
blank blank blank blank
blank
blank blank blank blank
blank blank
  Is the federal government spending too much money on security?
  Yes, they have spent too much to this point
  No, they have already spent enough
  No, they need to spend more
   
  View Results 
blank
blank

blank
blank blank blank blank
blank blank Contact me! blank
blank blank blank blank
blank
blank blank blank blank
blank blank
Larry Anderson
Editor

E-mail
blank
blank

Access Control & Security Systems
Access Control and Security Systems magazine is a business-to-business publication that focuses on how America's commercial, industrial and institutional facilities employ security systems to make their sites safer. Our readers -- more than 39,000 of them -- come mostly from larger companies (Fortune 1000-size) and are the high-level personnel in charge of security at their companies or institutions. We focus on the equipment used in security systems, and especially on how that equipment is integrated into "security solutions."

blank

blank
blank blank blank blank
blank blank Helpful links blank
blank blank blank blank
blank
blank blank blank blank
blank blank
Subscribe to GOVERNMENT SECURITY

Access Control & Security Systems

Subscribe to AC&SS magazine!

Subscribe to SECURITY BEAT, the AC&SS e-mail newsletter!

2004 Security Industry Events Calendar

American City & County magazine

American School & University magazine

Homeland One First Responder Network

blank
blank

blank
blank