top of page

1

駭客也分黑白?機器人帳號目的是什麼?網路安全工程師解惑網友疑問 Cybersecurity Expert Answers Hacking Questions|名人專業問答|GQ Taiwan

GQ Taiwan | 科普類 | Mar 21, 2022

此影片謄本由Sa製作

★非作商業用途,本檔案版權歸版權持有人獨有★

嗨!我是亞曼達盧梭,又名。我是一名攻擊端網路安全工程師。這是「駭客支援」。

這位推特用戶@cloud_opinion問說「此時此刻,駭客已經對我們每個人都無所不知,為甚麼我們現在還需要密碼?」反正你總是會死,為甚麼還一直去健身房?密碼有點像是一種必要之惡,而且駭客並不是對你無所不知,全都取決於你有沒有將那些資訊放在網路上。

「恭喜,我知道白帽是甚麼;我知道黑帽是甚麼,但甚麼是紅帽?氣噗噗的駭客?」我不覺得我聽過紅帽駭客這個名稱。如果你是白帽駭客,你是為了做好事而駭,很多在資安業界的人都是白帽駭客。而對於網路罪犯,我們稱他們是黑帽。還有另一個名稱叫作灰帽,這類人大白天可能是IT產業的系統管理員,但在晚上是兼職的黑帽。

下載檔案

下載檔案

1

1

所有資料非作商業用途,若有內容侵權,請即通知我們移除。

1

@hacker4life問說「@malwareunicorn你在這個領域是怎麼開始學習並成長的?我想要成為一名滲透測試員,需要一些提點。」滲透測試員有點像是攻擊者,負責檢查所有的外部通訊埠,檢查網路有沒有任何缺口。但如果你真的想成為滲透測試員,其實現在在網路上有許多相關內容,像是課程、工作坊。他們甚至會舉辦活動與研討會,你可以在這些地方認識這個領域的人。你可以找一位導師,向他們學習,他們會指引你正確方向。我感覺駭客圈還蠻開放且多元的,所以其實是有很多相關資訊的。

「惡意軟體真是爛透了,除了浪費我的時間,它到底還有甚麼目的?」通常惡意軟體的目標是金錢,而你可能是被當作附帶傷害。當惡意軟體被發佈時,他們通常是將惡意軟體盡量散佈給越多人越好,所以可能不是針對你而來。我把惡意軟體看作像是流行時尚,就好像每一季都會有不同的惡意軟體,而你必須保持時尚隨時跟上潮流。而有些比較舊的惡意軟體是在前幾年出現的,有時也會展開復古流行。

這位推特用戶@naima問說「潔西卡艾芭是個很有趣的被駭對象,駭客是如何決定他們的攻擊目標?」潔西卡艾芭是個美女也是位名人,因此她應該會是網路罪犯有興趣追逐的顯著戰利品。但很多駭客各自有不同的動機,可能是為了金錢,那應該是最常見的動機。另一個動機是名氣,他們會吹噓「哈哈我駭了這個人」。也可能是為了資訊,有點像是商業間諜。還有一種是為了破壞,那比較少見,基本上他們是想要破壞所有的系統,讓那間公司關門大吉。

@KyleeMinaj問說「為甚麼他們要把你學生貸款的登錄步驟弄得那麼困難又麻煩?要是有駭客想侵入我的帳戶幫我把學生貸款都付完,拜託別增加他們的困擾,你們會害到我,讓他們長驅直入吧。” Kylee,這些駭客是絕對不會幫你還貸款的。真要做的話,他們侵入系統也是為了清償他們自己的學費。很多這些控制機制之所以存在,是為了阻止那樣的駭客入侵你的帳戶。這是很不幸的一件事,但你知道,這是不得不做的事。

@AxelBlazen問說「談到狗屎事,這些機器人帳戶到底有甚麼意義?它們會追蹤你,然後就這樣了。不會發簡訊、不會發垃圾訊息,只是追蹤。真他媽的有夠蠢。」這些帳戶所做的事可能與你無關,我們稱之為帳號陳年。意思就是他們在嘗試繞過社群媒體為了尋找假帳號所設的許多自動化偵測。因此,藉著發推特文、傳簡訊或進行任何種類的動作,他們是為了繞過偵測,讓自己看起來更像是正常的帳戶。

這位 Twitter 用戶 @andrewcheeky 問說「他們接下來會想出甚麼?過去十年來,有甚麼有電線的東西是駭客還沒找出漏洞並成功製造破壞的嗎?」 要是你想像一下你家中能夠連接WIFI的冰箱,或是能連上你手機app的壓力鍋,很多這些裝置在研發時他們的目的是要竭盡可能以最低廉的成本製造出來。因此當他們進行到資安的部份時,通常會被當成次要的項目,所以在情況改變前,我們還是會在物聯網裝置上碰到這些問題。

Twitter 用戶@sifbaksh問說:「@malwareunicorn,學習偵錯的第一步應該是甚麼?難道就是找個檔案和一本課本就開始做?」 最好的方式就是直接開始做。把它想像成騎腳踏車,會需要時間,也需要練習,但最後你會學會怎麼做。每個作業系統都有不同的偵錯工具,但每種都不太容易學,除非你直接自己開始做,自己訓練自己和持續練習。像我也不記得偵錯工具中的每一個指令,我必須使用備忘單。

推特用戶@stormwuff_:「我超讚的老闆說,我可以要求將我在公司檔案中的職稱改成任何我想要的頭銜,很明顯要是適合工作場合。可以是隨便的任何名稱,像是寶可夢駭客或網絡安全巫師。你們覺得我該取甚麼名字?」我看到你說「很明顯要是適合工作場合」所以我認為你應該取名為「適合工作場合」。

這位 Twitter 用戶 @SuB8u 問道:「您的智能電視和影音串流app都在搜集與分享大量的資料,只因為它們可以這麼做。還要多久惡意軟體就能開始暗中操作內建攝影機?」 我有個不幸的消息要通知你。 這件事六年前就開始發生了,而且還會持續發生,所以你已經來不及了。

@Alessan82718685,名字有夠長:「你為什麼討厭 C#?」老天,他的使用者名稱看起來像是個機器人。我不討厭C#,是C#討厭我。

@theonlyoneofyou 問道「為甚麼駭客不能做些有意義的事,像是外流Taylor的Babe和Better Man?長大點,駭客們。」 要是你不知道的話,Taylor Swift有另一個我,我們稱之為@SwiftOnSecurity,她被認為是網絡安全行業的資安專家,因此沒有人會想要駭她。但如果你是行內人而且你知道她是誰,那麼你就知道她是誰了。

這位Twitter用戶@zer0wn問道︰「我們可不可以停止稱呼進行DDoS的人是他x的駭客?記者們,你們到底為甚麼要稱他們為駭客?希望能有個合理的答案,因為我真的超困惑。」讓我先澄清一下,駭客和網絡罪犯是不同的,所以要是我們指的是壞人,我會比較希望稱他們為網絡罪犯。有許多在資安產業工作的人都認為自己是駭客。有很多人是為了做好事而駭的。

@WMRamadan 問道︰「@malwareunicorn,我有個簡單但又大膽的問題。為甚麼你在做資安工作時用的是Mac?很多人都認為Linux才是最安全的。」 Mac與Linux很類似,可以把它們想成兩台不同廠牌的車子,它們外觀上看起來不一樣,但它們使用的底盤可能是一樣的。很少惡意軟體會針對Mac和Linux,當然還是有,但你知道,目前大部份的惡意軟件都是針對Windows。

The Bishop又名@JoshHarris25:「垃圾郵件的目的到底是甚麼?他們能因此賺錢嗎?他們能藉亂寄沒意義的電子郵件得到甚麼?」當他們寄送垃圾郵件時,他們會寄給成千上萬的目標。 假設寄出送了一百萬封,每封要求1美元。這些網絡罪犯的期待是其中的1%會中招。許多網絡罪犯會將垃圾郵件當作一門生意,因此對他們來說利潤非常豐厚。

@Cybor_Tooth:「@malwareunicorn,要是你要製作一份安全事件時間軸,看起來會是甚麼樣子?我只是好奇,因為你的設計能力超狂的。」 很多人不知道,但在我接觸電腦科學之前,我其實是想要攻讀平面設計學位的,因此許多我在那階段累積到的東西都帶到了我現在的工作中。之前我在國防部工作時,我會製作3D影片來描述不同種類的網路配置。我當時其實不懂3D設計,所以我花了一個週末自學,隔天我就開始製作內容了。要是你能夠把東西做得好看,並且能正確傳達出抽象的內容,那是很有幫助的。

@dontlook 問道:「很遜的撩妹台詞跟網絡釣魚有甚麼不一樣?不費功夫,使用簡單,而且都很難成功。」我真的覺得網絡釣魚比說撩妹台詞的成功率高。

@ivladdalvi:“我研究NHS醫院的WannaCry攻擊事件,看起來像是一場完全可以預防的災難。為甚麼他們不修補軟體?是因為偷懶?還是真蠢?」在這個攻擊事件中,一間位於英國的醫院遭受了勒索軟件的攻擊,發生的原因是因為他們沒有升級他們的伺服器或電腦,這就是為甚麼升級是那麼重要的原因。但當你仔細思考想,有些機構像是醫院或是發電廠,很多都是無法停工的。但當你進行升級時,你會必須把系統關閉一段時間。

@Tyro733 問道:「我不在資安產業工作,想知道甚麼是紅隊與藍隊?我猜紅隊指的是滲透測試員。」這些名稱其實源自於軍方,他們進行軍事演習時會分派一方是負責攻擊的紅隊,而藍隊則是防守的一方。類似的方式被應用在網路安全上,紅隊是駭客,藍隊是系統。紅隊進攻的目的是列舉出網路上的漏洞。我們希望能在為非作歹發現前找到漏洞,可以把我們想像成練拳的夥伴。所以我們的目的並不是要來令藍隊難看之類的,我們真正希望的是和藍隊一起工作。

@r00tzasylum︰「小駭客訪問了他的媽媽,討論在資安產業的工作發展。@defcon國際駭客年會爸媽常思索的事是:我們要怎麼啟發孩子進入這個領域,並讓他們看到其中有趣與有挑戰性之處?」當我年輕的時候,我完全沒想到我會做這份工作。我其實是發現了這個工作存在,才開始想從事這個工作。要是有機會在就業博覽會上能夠見到有人是以當駭客維生,我認為會是非常酷的事。你必須擁有正確的心態才有辦法待在這個產業。駭客的心態是必須能有創意地跳出框架思考,用非制式非常態的方式解決問題,不要遵從應該的執行方式。要是我們能將這樣的心態融入資訊內容或工作坊中,或是任何與這些孩子交流的場合上,我認為就會啟發他們想在這個領域解決問題。

這位Twitter用戶@Arfness問道︰「為甚麼圖庫中的駭客全部都戴著滑雪頭套和帽T?」我認為攝影師想捕捉的感覺其實是搶匪或是罪犯,但在頭上戴東西是有原因的。他們希望能遮住自己的臉,不讓攝影機或任何辨識系統捕捉到,以免因此而罪證確鑿。至於他們為甚麼要穿帽T,我能想像有些伺服器機房會超冷,他們會需要蓋住自己的耳朵。要是你還不知道的話,其實我們有些人真的會穿成這樣上班,其實我的每套服裝都會搭上滑雪帽。讓我為大家戴起來,這套打扮要戴上眼鏡才算完整。這樣就準備好了,開始駭吧。

以上就是亞曼達盧梭的「駭客支持」,你們在外面小心安全喔。




Hi, I'm Amanda Rousseau, aka @malwareunicorn and I'm an offensive security engineer and this is hacking support.

This twitter user @cloud_opinion asks, “at this point, hackers know everything there is to know about every one of us, why do we need passwords now?” why keep going to gym if you're going to die anyways? passwords are kind of a necessary evil, and hackers really don't know everything about you. it all depends if you put that information out there on the internet.

“Congrats, I know what a white hat it, I know what a black hat is, what is a red hat? …Angry hacker?” I don’t think I’ve heard the term red hat hacker before. When you are white hat hacker, you hack for good. A lotta people in the security industry are white hat hackers. And then, for the Cyber criminals, we will call them black hats. There is also this other term called a gray hat, where they could be a IT admin during the day, while moonlight as a black hat during the night.

@hacker4life asked “@malwareunicorn How did you begin learning and exceeding in this field? I'm trying to become a penetration tester, need inspiration.” So a pen tester is kind of like an attacker that goes and checks all of the external ports, any openings within someone's network. But if you really want to be a penetration tester, there's a lot of content out on the web right now Courses, workshops, they even have events and conferences
where you can meet other people in the field. You can find a mentor, learn from them, they would point you in the right direction. I feel like the hacker culture is pretty open and diverse,
so there's a lotta content out there.

"Malware's the worst. What is its purpose other than wasting my time?" Usually, malware is going after money. And, if anything, you're considered collateral damage. When malware is delivered, they're usually just spraying all the malware to many people as possible, so it may not be intended for you. I think of malware as a fashion trend. You know, there's different malware every season, every quarter, and you have to stay in fashion and on trend all the time. When you think about older malware that used to occur a couple years ago, sometimes it comes back in fashion.

This twitter user, @naima, asks,"Jessica Alba is an interesting choice for hacking. How do hackers decide who they're going to target?" Jessica Alba's a beautiful woman and she's also a celebrity, so she sounds like a great, shiny object for cyber-criminals to go after. But a lot of them have different motivations. It could include money, is probably the biggest one.
Another one would be reputation. They would be like, "Ha ha, I hacked this person." It could be information, kind of like corporate espionage. And then we have destruction, which is kind of rare. Basically what it is, they try to destroy all the systems to put that company out of business.

@KyleeMinaj asks, “Why do they make the login process for your student loan aid so difficult and tedious? If some hackers want to break into my account and pay off all my student loans, please don't make it difficult for them. Y'all are gonna ruin this for me. Let them run wild in there.” Kylee, these hackers are not gonna go and pay off your debt. If anything, they're gonna go into the system to pay off their tuition. So a lot of these controls are in place
to hinder hackers like that to get into your account. It's an unfortunate thing to do but, you know, it's necessary.

@AxelBlazen asks, “Speaking of shit, what is even the point of these bot accounts
that follow you but, well, that's it. No messaging or anything, no spam, just follow.
Like fucks sake, it's dumb.” Well, these accounts are doing something that may not pertain to you, what we call account aging. So what that means is they're trying to bypass a lot of automated detections from social media that they have in place to look for fake accounts.
And so, by tweeting or messaging or making any type of action, they're trying to bypass detection to look more like a legitimate account.

This Twitter user, @andrewcheeky, asks, "What will they think of next? Is there anything that has been corded in the last decade that hackers haven't found a vulnerability to do some damage?" If you think about your fridge at home being able to connect to the WiFi or your pressure cooker being able to connect to an app on your phone, a lot of these devices are developed in a way where they're looking for the lowest possible cost of manufacturing,
so when they get to the security part, it's kind of like an afterthought, so until things change, we're gonna still have these problems with IoT devices.

Twitter user @sifbaksh: "@malwareunicorn, what should my first step be in debugging? Should I just get a file and a book and start doing?" The best way is to just jump right in. Think about it as riding a bike. It takes time, it takes practice, but eventually, you'll get it.
There's a different debugger for every operating system but they're not easy to learn unless you start, you know, just doing it yourself and training yourself and practicing. Like, I don't remember every single command in a debugger. I have to use a cheat sheet.

Twitter user @stormwuff_: "My awesome boss says that I can request to change my job title to whatever I want it to be in our company profile [obviously safe for work]. Could anything random like Pokemon Hacker or Cybersecurity Wizard. What do you guys think it should be?" Well, I can see you just said, Obviously safe for work, so I think you should just name yourself Safe for Work.

This Twitter user, @SuB8u, asks, "Your smart TV and your video streaming apps are collecting and sharing tons of data, just because they can. How long before we can start having embedded cameras that malware triggers surreptitiously?" I have unfortunate news for you. This has been happening minus six years and it's gonna continue to happen, so too late for you.

@Alessan82718685, that's a mouthful: "Why do you hate C#?" Man, his handle looks like a bot. I don't hate C#, C# hates me.

@theonlyoneofyou asks, "Why can't hackers do anything useful like leak Taylor's recordings of Babe and Better Man? Grow up, hackers." Well, if you don't already know, Taylor Swift has an alter ego that we call @SwiftOnSecurity and she's considered a security pro in the cybersecurity industry, so no one actually wants to hack her. But if you're in the know and you know who that is, then you know who it is.

This Twitter user, @zer0wn asks, "Can we stop calling people who DDoS [beep] hackers? Journos, why the hell do you even call them hackers to begin with? Looking for legitimate answers as I am confused as hell." Well, let me set the record straight. There's a difference between hacker and a cyber-criminal, so if we were to refer to the bad guys, I would rather prefer to call them a cyber-criminal. There's a lotta people in the security industry that consider themselves hackers. There's a lotta people that hack for good.

@WMRamadan asks, "@malwareunicorn, I have a simple yet daunting question. Why do you use a Mac for your security work? I mean, a lot of people argue the fact that Linux is the way to go in terms of security." Mac is similar to Linux. Think about two different brands of cars. They look different on the outside but they could be sharing the same chassis underneath. There's not a lotta malware out there for Mac and Linux. I mean, it's there, but, you know, currently most of the malware is on Windows.

The Bishop, or @JoshHarris25:"What is the point of spam emails? Are they profiting from it? What do they gain from spending random unnecessary emails?" When people send out spam emails, they're sending it to thousands and thousands of targets. Say you had a million emails sent out and they're requesting $1. These cyber-criminals are expecting
that 1% will actually bite. A lotta these cyber-criminals will treat this as a business, so it becomes very lucrative for them.

@Cybor_Tooth: "@malwareunicorn, if you were to create a timeline for an incident, what would it look like? Just curious because your design skills are cray cray." Well, a lotta people don't know this, but before I got into computer science, I was actually pursuing a degree in graphic design, so a lot of it, from my time doing that, carries over into my work. Back when I used to work at the Department of Defense, I used to create these 3D videos to describe different type of network layouts. I didn't know 3D design at the time, so I spent a weekend, taught myself, and the next day, started, you know, making content. If you can make things look nice and be able to communicate the actual abstract content, it helps.

@dontlook asked, “Yeah, but bad pick up lines and phishing really any different? Low effort, easy reuse, and rarely do you get a success.” I really think phishing is more effective
than saying a pickup line.

@ivladdalvi: “I studied WannaCry case in NHS hospital. A disaster seemed totally preventable. Why didn't they patch? Were they lazy? Stupid?” In the case of this incident, a hospital in the UK was under a ransomware attack. It happened because they didn't upgrade their servers or their computers. And this is the whole reason why upgrading is really important, but when you think about it, some of these infrastructures like a hospital or a power plant, a lot of 'em cannot experience any downtime. So when you do do an upgrade, you have to shut down the systems for a little while.

@Tyro733 asks, “As someone who doesn't work in Infosec, what are red and blue team? I'm assuming red are the pen testers.” These terms actually come from the military where they would perform military operations, they have a team that acts as a red team doing the attacks and the blue team serves as the defense team. Similar to what we have in cybersecurity in that the red team is hacking the blue team's systems. The whole point of what the red team does is to enumerate holes within a network. We wanna find the holes before the bad actors do. Think of it like we're sparring partners. So, we're really not there to antagonize the blue team or anything like that, we really wanna work together with the blue team.

@r00tzasylum: “Hacker kid interviewed his mom about what it's like to build a career in Infosec. Something @defcon parents often think about: how do we inspire kids to go into this space and see it for the fun and challenge that it is?” Well, when I was young, I had no idea I was gonna be in this job. I actually had to know that this job existed in order to actually go into it. If there was a chance that, at a career fair, you would have someone who gets to hack for living, I think that would be a really cool thing to have. You have to have the correct mentality to be in this industry. The whole hacker mentality is creatively thinking outside the box, solving a problem that's out of the standards or norms of how it's supposed to execute. If we kind of use that type of mentality in some of the content or workshops or anything that we reach out to these kids with, it'll kind of inspire them to wanna solve problems in this field.

This Twitter user, @Arfness asks ”Why do stock image hackers exclusively wear ski masks and hoodies? Well, I think the photographer was going for a feel of an actual robber or a criminal, but there is a reason to wear something on your face. They're trying to hide their face from cameras or any type of identifier that will attribute them to a crime. And why they're wearing hoodies, I can imagine that some of these server rooms are super cold and they need to cover their ears. If you don't already know, you know, some of us actually dress like this to work and I actually have a ski mask for all of my outfits. Lemme put it on for you guys. And it's not complete without the glasses. We're good to go, it's time to hack.

This has been Hacking Support with Amanda Rousseau. You guys stay safe out there.

1

1

1

1

1

1

1

IMG_1410.PNG

牆內能夠接觸外間資訊的渠道寥寥可數,Youtube 機頂盒為每星期從 Youtube 上挑選不同種類的專題影片並製作成謄本、印刷成信件的長期計劃。

其他最新謄本

https-::www.youtube.com:watch?v=TSJwMZvw

💥腦筋急轉彎2片尾解析+12大彩蛋|小彬彬竟然出現?霹靂包原型?AC113?留言抽官方贈品

那些電影教我的事 Lessons from Movies | 電影類

https-::www.youtube.com:watch?v=TSJwMZvw

💥戰勝阿焦大作戰!腦筋急轉彎2最強指南|4招把阿焦變成神隊友|劇透|Inside Out 2|留言抽好書

那些電影教我的事 Lessons from Movies | 電影類

https-::www.youtube.com:watch?v=TSJwMZvw

💥腦筋急轉彎2無雷解析|小心你的情緒內戰!5招搞懂你的腦|留言抽好書|Inside Out 2

那些電影教我的事 Lessons from Movies | 電影類

https-::www.youtube.com:watch?v=TSJwMZvw

#MM|返工成日聽到「一代不如一代」 係源於心理偏見?社會學分析不同年代人特徵 點解00後會衝擊職場生態?|#Pantry有嘢斟 #4K

Mill MILK | 心理類

https-::www.youtube.com:watch?v=TSJwMZvw

#MM|00後擲廿萬創業開韓式自拍館 半年回本開分店 月打4份工返茶餐廳做樓面 拍Reels過900萬觀看次數 00後鍾意創業搵滿足感 抗拒朝9晚5?|#700萬種生活 #4K

Mill MILK | 社文類

0

bottom of page