Opentopia Directory Encyclopedia Tools

Script kiddie

Encyclopedia : S : SC : SCR : Script kiddie


In computing, a script kiddie (occasionally script bunny, script kitty, script kiddo or skiddie) is a derogatory term for inexperienced crackers who use scripts and programs developed by others, without knowing what they are or how they work, for the purpose of compromising computer accounts and files, and for launching attacks on whole computer systems (see DoS). In general, they do not have the ability to write these kinds of programs on their own. Such programs have included WinNuke applications, Back Orifice, NetBus, Sub7, and Metasploit.

Many Skiddies also enjoy cracking any website they can, just to prove their "superiority" in the underground hacker community.

Script kiddies, instead of attacking an individual system, often scan thousands of computers looking for vulnerable targets before initiating an attack. This is similar to wardialing and wardriving in which the attacker isn't looking at one specific system, but instead anything that is open and looks interesting. The term is also often used as a derogatory moniker for individuals who do not contribute to the development of new security-related programs, especially exploits, but rather benefit from the work of others.

Script kiddies can be a potential aid to more dangerous types of crackers who can encourage and manipulate them into being more destructive.

The term is a reference to Linux/Unix scripts, which are small simple-to-use applications that can accomplish a specific task with little more input than the target of the attack. To some however the term expresses considerable contempt, being meant to indicate that they are immature, and only use "scripts" and programs created by other people, in an act of uninspired vandalism.

Another use of the word refers to people who use a program to perform the bulk or all of the actual programming work for them and then portray themselves (often braggartly) as advanced computer programmers. This usage overlaps considerably with the jargon term code monkey.

Script kiddie scene

From around 1995 on, the widespread use of the Internet in the business and home computer field, and the full disclosure movement's policy of disclosing working exploitation tools has led to an enormous growth of the script kiddie scene.

Script kiddies often act out of boredom or a desire to 'play war' on the Internet. There are many organized script kiddie groups, who often meet in anonymous chat channels on IRC servers. NorthBay Crew and bay6-kr3w are examples of such script kiddie gangs.

Script kiddies often deface random sites and vulnerable targets. They misuse , and attack most sites available. For example, when an easy exploit is released, in a matter of minutes, script kiddie group join and start defacing.

Tactics

The characteristic approach of the Script Kiddie attack is to use Portsniffers. These programs can be given a designated IP range which identifies those systems that fall within the range. These often require little direct interaction by the Script Kiddie and can be executed easily. Once the systems are identified, he or she can scan the ports in an attempt to identify vulnerabilities. Then the ports are used in an attempt to connect to the computer terminal. If the attempt to connect succeeds (which is almost inevitable given the number of computer systems that can be automatically scanned), the Script Kiddie can upload a wide variety of viruses onto the host.

Tools

Script Kiddies have at their disposal a large number of effective, easily downloadable malicious programs capable of harassing even advanced computers and networks. These include…

A computer worm is not the same as a virus. A virus works by attaching to other programs within the computer program. For this reason, a virus is dependent on other programs within the target system. A computer worm is more dangerous, in that it is self sufficient and does not require attachment to another program. If a worm strikes a computer network, it can be sent throughout the entire system, often without the users realizing it. The purpose of a worm is to sap the computer or the network of bandwidth, thus slowing performance. Sometimes, however, a worm can be programmed to delete or encode files. Other commands can also be preprogrammed before releasing them into a host.

Denial-of-Service Attack

A Denial-of-Service Attack (DOS) is an attempt to shut down network activity in a target system by sapping the computer network of bandwidth. A number of distinct DOS attacks exist which pursue this goal through different means:

Indirect Programs

Other easily accessible programs offer indirect means of accessing target computers rather than simply overwhelming them with information:

Defense

A number of possibilities exist for defense against the threat of Script Kiddies. These malicious viruses, worms, and programs are available on the internet and can have devastating effects on unprepared systems. This means that network security is of the highest priority. The following steps are useful for system defense.

Implementing a system of worker education (or self education in dealing with personal computers) is essential for protection against malicious programs. Many of the DOS attacks, for example, require an action by the host before the program can take full effect (for example, opening an attachment). By informing knowledge workers about commonly used tactics and implementing safety protocol, the chances of a successful Script Kiddie attack is greatly reduced.

Firewalls are helpful in protecting a network. Firewalls attempt to provide boundaries for internet connection in order to reduce the chance of malicious programs being uploaded onto the computer system. Firewalls require administrators capable of managing them. By controlling and monitoring network traffic, the Firewall greatly reduces the chance of a Script Kiddie exploiting a network without IT security realizing it.

Anti-Virus software has also flooded the market in recent years. These automatically scan a computer in search of unwanted virus and automatically inform the user. These programs allow the easy deletion of unwanted programs. Often, anti-virus software scans emails automatically.

Updating the Operating System on a regular basis is often important, since methods of exploiting OS weaknesses are quickly and easily found on the internet. It is important to stay abreast of the latest software improvements.

Ensuring the security of passwords is also important to prevent unknown entry.

Famous Examples

Script Kiddies are often able to exploit vulnerable systems and strike with great success. The most famous examples include…

A 15 year old Script Kiddie called Mafiaboy was arrested in an upper class neighborhood in Montreal in 2000. Using downloaded DOS attacks, he struck famous websites such as Yahoo!, Dell, Inc., eBay, and CNN, causing roughly 1.7 billion dollars worth of damage. He pled guilty to 55 criminal charges and served 8 months in a youth detention center.

In 1999, NetBus was used to discredit a law student named Magnus Eriksson studying at the University of Lund. Child pornography was uploaded onto his computer from an unidentified location. He was later acquitted of charges in 2004 when it was discovered that NetBus had been used to control his computer.

Jeffrey Lee Parson was an 18 year old high school student from Minnesota responsible for using the B Variant of the famous Blaster Worm. The program was part of a DOS attack against computers using the Microsoft operating system. The attack took the form of a SYN flood which caused only minimal damage. He was sentenced to 18 months in prison in 2005.

Script Kiddies and Hacker Culture

In modern hacker and internet subcultures, Script Kiddies are widely considered novices or worse. For their failure or inability to create their own viruses (choosing instead to use easily available ones) they are seen as reputation seeking free-riders of the hacker community who take advantage of others’ work. Michael Fitzgerald ''Hackers, Crackers and Script Kiddies, Oh My! ; How to sort the good guys from the bad, in the Internet version of Spy vs. Spy.. They also scan large numbers of computers to find weaknesses rather than taking the time to find weaknesses in more advanced systems. The goal is typically to impress friends.Michael Fitzgerald ''Hackers, Crackers and Script Kiddies, Oh My! ; How to sort the good guys from the bad, in the Internet version of Spy vs. Spy. Portrayed as teenage technological dilettante, Script Kiddies are the subject of contempt among experienced hackers. In spite of this they are feared among network administrators for their ability to scan many computer systems automatically over the course of days or weeks to find weak points. The fact that very little technical knowledge is needed to download these programs is an added threat, since nearly any individual on the internet can obtain malicious viruses and the means to infect large numbers of computers, costing the owners up to millions of dollars in damage.

References

 


From Wikipedia, the Free Encyclopedia. Original article here. Support Wikipedia by contributing or donating.
All text is available under the terms of the GNU Free Documentation License See Wikipedia Copyrights for details.

Search Titles
0123456789
ABCDEFGHIJ
KLMNOPQRST
UVWXYZ?

E-mail this article to:

Personal Message: