|
Source: Financial Times - Posted by Alex
|
Organisations do not want their systems hacked, so they ask us to do it, in order to fix their weaknesses. If they are setting up, say, an online shop, they give us five days to try to break into it before they launch.
We use exactly the same methods and tools as ordinary, illegal hackers to try to find a way in. Essentially, it is puzzle-solving – you against the system’s administrator.
As well as web security, we test a lot of organisations’ internal networks. Generally, internal system security is quite weak. Often, you will try really technical ways to break in and then discover, say, test accounts where the username and password are set to just the word “test”.
We often find gaping holes in security, and even servers that have already been hacked.
You also see quite a few corporate networks that are protected but are connected to wireless networks that anyone on the street can log into.
Read this full article at Financial Times
Only registered users can write comments. Please login or register. Powered by AkoComment! |