Answer

Hacker chatter: Can hacker websites help companies anticipate attacks?

I've heard hacker chatter can be a helpful defense against potential exploits, but where are the best places to find it, and how can I determine if what hackers are talking about could pose a threat to my enterprise?

    Requires Free Membership to View

Hacker chatter can be helpful in determining defenses against potential attackers, but it might be more effective for the general industry to track hacker chatter, not necessarily the average enterprise.

For enterprises under targeted attack with sufficient resources, however, independently tracking hacker chatter might make sense. Rob Rachwald, director of security strategy at Imperva, describes hacker chatter as the discussion found on black market or cybercriminal websites that includes attack tools for sale, information on how to automate attacks and the business side of cybercrime. Some of the attacks under discussion include SQL injection, compromised accounts and passwords, DDOS, spam and zero-day attacks. If you are curious about visiting hacker websites, you could visit some of the sources Brian Krebs lists on his blog like antichat.ru, mn0g0.su or rock3d.cc, but you should be prepared to do so securely in order to not put yourself or organization at risk.

Much of the same information could be obtained from more legitimate sources, and potentially even from just following some interesting people on Twitter, such as Dave Aitel, CEO of vendor Immunity Inc. (@daveaitel), or reviewing conference presentations from Defcon or Black Hat.

To determine if your enterprise is under attack by looking at hacker chatter, you could search for usernames and the word "password" (including other translations of the word "password") to see if there is a list of compromised accounts, your IPs or DNS names, or names of internal projects or internal sensitive data examples. You could even use Google hacking to look for internal vulnerabilities. Once you have found specific examples, you could determine effective strategies to prevent or remediate the attacks, and to build support internally for these efforts.

This was first published in October 2011

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: