School Teaches 'Ethical Hacking'
Yardboy writes "A Yahoo! News/Reuters story discusses students in Los Angeles paying $4,000 to attend 'Hacker College' and become 'Certified Ethical Hackers'. Apparently: 'Instructors race through topics like symmetric versus asymmetric key cryptography (symmetric is faster), war dialing (hackers will always call late at night) and well-known TCP ports and services (be wary of any activity on Port 0)', and the president of the college: says 'What we attempt to do in our classes is teach how the hackers think.' Hmmm, perhaps 'Certified Script Kiddie' would be a more accurate designation."
Now we have SCHOOLS that teach that "hacking" means breaking into computer systems
The problem with teaching Comp Sci, let alone "hacking," is the methodology in which the teachers teach. The only way I ever learned any type of programming was when someone said, "Go build an application that simulates RSA cryptography." 12 C++ files later I learned more then I did in 2 years of "intro" classes. The same goes for this as well, these kids wont get much more out of these classes then learning to use some scripts or demon dial or whatever.
They should get a project that entitles building some sort of application which can be relseased to the Open Source community.
Wow, war dialing, early 90s, wow.
GroupShares Inc. - A Free Online Investment Community.
-------
artlu.net
Learning how to defend against getting hacked by learning how to hack is nothing novel. It sounds like a great idea on the surface, because it gives you the tools to probe your own weaknesses the way your attackers will. But you're always going to have to keep up with the latest methods, scripts, etc. IMO, A net admin who isn't at least a hobbyist hacker probably won't get much from a hacking bootcamp except a false sense of security.
- Greg
Start a happiness pandemic
is never good or evil. If the students are atttending for the right reasons, then this will help them understand the basics of how script kiddies work. And what do the current stats tell us about most attacks? That they are unsophisticated and are run by people who have little deep knowledge of systems. So this course wil (theoretically) allow them to better protect against the majority of attacks. If the students are attending for the wrong reasons, then they spent $4k for what a day or two of googling and reading would have gotten them. BFD.
Always value the individual over the system. --Bruce Lee "I don't need a Sig - I have a custom 191" - me
I haven't read it yet, but I'm rather skeptical. It seems like $4000 dollars and a few weeks in the classroom teaches you how to run sploits you download from packetstorm. It doesn't make you suddenly become skeptical of everything a vendor tells you, or make it become a habit to run a sniffer with watchtemp when you install software on your test lan. It doesn't make you enjoy reading bugtraq.
There's a heck of a lot more to "hacking" than what they can teach you....think "lifestyle"
"Weapons should be hardy rather than decorative" - Miyamoto Musashi
I think that goes for OS's too
$4,000 seems a bit expensive. I'm not seeing the true benefit of having a "Certified Hacker Certificate"? I think the days of getting a job out of highschool because you took a hacking course are over (if they ever existed in the first place).
Right now the University of Cincinnati is about $8,000 for a year. And I thought that was expensive.
Seems trendy to me...I just don't see hacker courses having much of a true impact on security.
But kudos to whoever is making money off the idea. Wish I would have thought of it.
Better than Flickr - Manage, Share, Archive
All about machine language and security as mandatory part of the program?! Where did you get that degree? I want to go there too! Around here, universities teach you some high level language, how to comment your code, and writing a few apps and a few parsers.
You can do the real stuff, but it's all optional, giving me the feeling that I can as well kiss the university goodbye and study for myself - which is, in fact, how I learned everything I know about computers and programming. And I mean everything. The only reason I still attend university is that I want to get the diploma, but I'm not even sure how much people are going to care about that if you don't really need to have any deep knowledge and experience to get it.
Please correct me if I got my facts wrong.
Man creates computer, internet.
Intelligent, misunderstood youths discover internet, realize they've been lied to, strung along, generally mistreated. Youths show the guts and brains to learn without teachers.
Feds discover internet, realize there are children smarter and more skilled than them, throw beauracratic temper-tantrum, track down said kids (well, some of 'em) and bust them, refuse leniency.
Feds realize this "internet thingy" is more important than they though, and worse, there are kids in other countries who not only have mad skillz, but also actively hate america. Feds shit bricks.
Gov't, realizing it has cut off it's left testicle, tries to fill the gap with "Ethical hackers", ie, tries to create what it had in the first place.
Jeezus F Kryst on a surfboard, why didn't you just train the @#(*&^*(@# hackers in ethics in the first place? You can't teach curiosity, autodidactism or problem solving.
Nature laughs, goes back to being inscrutable.
Way to go.
"A witty saying proves nothing." ~Voltaire
"d'Oh!" ~Homer
Yeah, I was thinking of all the math that's involved in cryptography. And to really know what you're talking about, you should probably understand the guts of networking, tcp/ip and ethernet inside and out. You should know machine language pretty well too.
The most difficult part about security is that you aren't learning how something is supposed to act. That's the easy part. That's what every programmer does (and what I do mostly). But to really do security, you have to know what could happen and how something might work if manipulated. That's really, really hard when you think about all the possibilities!
I just can't imagine squeezing that all in to a short certificate class.
Slashdot Syndrome: the sudden, extreme urge to correct someone in order to validate one's self.
Script kiddies don't need to know why symmetrical encryption is faster... they just need to know how to subscribe to Bugraq.
[/cynical]
Education is extremely important in this segment, no doubt. What concerns me is the "boot camp" format of these particular gigs, as well as the entry fee.
$4000 is an awful lot of money for a Common Body of Knowledge -- especially since its all available from the Internet.
I have nothing but encouragement for those who wish to enter the field. But save your money. Hell, drop sixty bucks and go to defcon.
trustedworlds.net - gaming, security, and the gunk that lives in between
Old news :(
Honestly please stop posting this crap. Not only is it old news, but its really alot of poo poo. Try reading Phrack or other underground zines. There are tons of entry level zines and zines that are for more advanced users (phrack). Save yourself $4000 and do it from the confort of your own home. If you want to know how hackers think, try speding some time on undernet. You get the feeling real quick :)
This is not a flame.
Hrrm... I usually just sign my name.
You WILL NOT learn hacking, even in the context that they're teaching (subverting the security of computer systems), in a class. You may learn about all kinds of tools; and about steps and techniques to attempt to break into computers, but the real work is not in a classroom. I still believe this after taking SANS Track 4; which was excellent training, but did not drop me back on the street with the ability to be pen tester extraordinaire. It's like the commercial says: you get good with practice. I think that's part of the reasoning behind SANS's practical papers for their certifications - so you research, and PRACTICE, and learn things by doing. Now, let me add yet another disclaimer to my posts - practicing does not mean going out and writing malicious code and breaking into sites. Practice means taking your own little air-gapped network and exploring every aspect of the art that you have time and aptitude to learn. Real hacking, the essence, and I'm not trying to start a definition war here; is trying everything you can and learning everything you can - for good or for evil now; but you get the point.
I think with the interesting people, their lives can't possibly be wrapped up into a nice little package.
Well, a smart but unpricipled cracker might take the course to learn how to "talk the talk" and make himself sound ethical. That would help him social engeneer himself into a security job where he can get paid to crack into systems and steal data while claiming to be looking for vulnerabilities to patch.
Good, inexpensive web hosting
after the Sept. 11, 2001, attacks on the World Trade Center and the Pentagon, the company expanded its focus to information security courses.
That makes no sense. I could see them expanding in the wake of some vicious worm or virus, but they might as well take their inspiration from Chechnya. It makes it seem like they are in the business to trade on fear-of-hackers rather than to provide real security. Not that that's a bad marketing angle, but just one I'd have moral issues using.
HIV Crosses Species Barrier... into Muppets
My take on courses is: yes, you can learn the same stuff if you take the time. However, your boss is unlikely to give you time during work hours to study. When the employer has to pay muchos buckos for it he gets a warm fuzzy feeling that you are doing something worthwhile.
I'm sorry if I haven't offended anyone
99% of the stuff I learned in a college classroom was available on the Internet. Putting it together right demands something more than just a Google search.
Other things I got from college:
Credibility
A class ring
Life experience (studied abroad, lived in a dorm)
Friends
Relationships with professors - having connections with people in your field is a good thing
I went to a school that runs around $30,000/year. It was worth every penny.
Things I have gotten from Working since I was 18:
Credibility, people KNOW I can do this for a living. They dont have to worry about weather I can actually do the work.
Several awards from my employer.
Real Life experience.
Friends
Proffesional contacts. Tons and Tons of them.
And I dont have 60k in debt, and wont be paying off school bills for the rest of my life. I have enough experience to walk into higher level jobs and skip the "entry" level BS.
Life is not lived on a Piece of paper that was givin to you by some organisation that is known as a "school".
"Two things are infinite: the universe and human stupidity; and I'm not sure about the the universe." --Albert Einstein
College can more useful in opening doors than it is as a tome of information. As you said, you may have learned quite a bit from your on the job training, are in contact with numerous people in your field, and do not suffer the financial hardships of a recent college graduate. Unfortunately you may have a hard time competing with those who have a higher education background, especially if they've worked while going to school (like many of us do).
Graduating from college with very good grades requires a lot of work, something any employer knows. If an applicant finishes with a 4.0 GPA, it can be safely assumed that they can "actually do the work."
What you say is a little alarming; your assumption that college is entirely worthless when compared to a high school job is entirely unfounded.
Oh, and before you apply anywhere in the future, work on that spelling and grammar ;)
LegendMUD
Credibility, people KNOW I can do this for a living. They dont have to worry about weather I can actually do the work. ;) :(
What a college degree gives you though is more flexibility. You have proven you can do a particular job and do it well, but it is much more difficult for you to find a job that might require things outside your current skillset. A college degree shows employers you are able to expand your knowledge outside your core competency.
Several awards from my employer.
In college you can get your name on publications, get rewards from companies in the form of scholarships, and research grants (and companies do keep in mind who they gave money to when they are hiring)
Real Life experience.
You can also get alot of experience in school if you're willing to put in the time. You have 16-20 hours a week of class, which leaves you plenty of time for hands on activities like helping grad students with research, taking a job running one of the campus networks, getting involved in a technical club (like solar powered car), etc.
Friends
You can get those in college too, and there are more women
Proffesional contacts. Tons and Tons of them.
You can get an excellent network in college, internships, co-ops (definately a foot in the door), contacts in companies who donate to your research, and alumni
And I dont have 60k in debt, and wont be paying off school bills for the rest of my life
Yes it is true
D6 63 0D 70 89 81 BB 8E 7B 7C 5F 5D 54 EA AB 73