Q&A

Why Johnny Long Hacks Stuff

By Katherine Walsh

November 26, 2007CSO — The Christian hacker talks about how he wrote No Tech Hacking, why he thinks social engineering is easier than hacking software, and how hes trying to get the hacking community to do charity work

Johnny Long has been hacking stuff for as long as he can remember. But Long, a professional hacker and security researcher at Computer Sciences Corporation, doesn’t fit the stigma. As a self-described Christian hacker who created an organization for the hacking community to do charity work, he says is goal is to improve the security of computer networks by exposing their vulnerabilities. He became the authority on search-engine hacking in 2005 when he wrote Google Hacking for Penetration Testers, the first book exploring how malicious hackers use Google features to unlock security flaws. In his new book, No Tech Hacking (which CSO has excerpted, LINK TK), he explains how hackers are using their curiosity and sense of perception to compromise security without the use of technology, and what security professionals need to know to get ahead of the game.

CSO: Explain the concept of “no-tech hacking.”

Johnny Long: Security is a race between the good guys and the bad guys. Everybody tried to get more technically advanced and smarter about what it is that they are doing. After being a professional hacker for a number of years, breaking into computer networks and breaking into physical buildings to get access to computer networks and data, I learned that the things I was able to do most successfully often had very little to do with technology. I could spend a week, a month or three months pounding on an Internet-connected network for some agency trying to sneak past their firewall, or in a matter of two days I could actually be inside the building through social engineeringmaybe by creating a fake badge that looked like an employee badge, pretending to be a telephone repairman, or even by entering through the smokers’ entrance. There’s a whole pile of stuff that doesn’t involve technology. (See CSO’s excerpt of No Tech Hacking for more on the problems with employee badges, LINK TK.)

CSO: Why does a good “no-tech hacker” also have to be a good social engineer?

Long: It’s all about being comfortable where you are. A lot of people assume it’s like acting, where you have to play a part, but really it’s just about coming across as someone who’s not up to something. Really good social engineers can pick up the phone and change their voice or their age. These days, you don’t even have to do thatyou just have to be comfortable and convince yourself that you’re in a place you belong, that you’re having a conversation that’s completely normal.

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WHITE PAPER
Discover whether hosting is your smartest choice for enterprise messaging.

GoogleTo host or not to host? Thats the question for many CIOs as the volume and complexity of enterprise messaging continues to skyrocket.

» Read the Paper

Featured Sponsors