Q&A

Why Johnny Long Hacks Stuff

The Christian hacker talks about how he wrote No Tech Hacking, why he thinks social engineering is easier than hacking software, and how hes trying to get the hacking community to do charity work

By Katherine Walsh

November 26, 2007CSO — The Christian hacker talks about how he wrote No Tech Hacking, why he thinks social engineering is easier than hacking software, and how hes trying to get the hacking community to do charity work

Johnny Long has been hacking stuff for as long as he can remember. But Long, a professional hacker and security researcher at Computer Sciences Corporation, doesn’t fit the stigma. As a self-described Christian hacker who created an organization for the hacking community to do charity work, he says is goal is to improve the security of computer networks by exposing their vulnerabilities. He became the authority on search-engine hacking in 2005 when he wrote Google Hacking for Penetration Testers, the first book exploring how malicious hackers use Google features to unlock security flaws. In his new book, No Tech Hacking (which CSO has excerpted, LINK TK), he explains how hackers are using their curiosity and sense of perception to compromise security without the use of technology, and what security professionals need to know to get ahead of the game.

CSO: Explain the concept of “no-tech hacking.”

Johnny Long: Security is a race between the good guys and the bad guys. Everybody tried to get more technically advanced and smarter about what it is that they are doing. After being a professional hacker for a number of years, breaking into computer networks and breaking into physical buildings to get access to computer networks and data, I learned that the things I was able to do most successfully often had very little to do with technology. I could spend a week, a month or three months pounding on an Internet-connected network for some agency trying to sneak past their firewall, or in a matter of two days I could actually be inside the building through social engineeringmaybe by creating a fake badge that looked like an employee badge, pretending to be a telephone repairman, or even by entering through the smokers’ entrance. There’s a whole pile of stuff that doesn’t involve technology. (See CSO’s excerpt of No Tech Hacking for more on the problems with employee badges, LINK TK.)

CSO: Why does a good “no-tech hacker” also have to be a good social engineer?

Long: It’s all about being comfortable where you are. A lot of people assume it’s like acting, where you have to play a part, but really it’s just about coming across as someone who’s not up to something. Really good social engineers can pick up the phone and change their voice or their age. These days, you don’t even have to do thatyou just have to be comfortable and convince yourself that you’re in a place you belong, that you’re having a conversation that’s completely normal.

RESOURCE CENTER
Loading...
WEBCAST
Gartner Video: Best Practices for Web Application Security and Compliance

Cenzic Faced with the growing threat of hacker attacks, how do you protect your data and your corporate reputation while increasing revenue?

» View this Webcast

WHITE PAPER
Email Continuity: Don't Know What You've Got Till it's Gone

MessageLabs Today, more email is being sent and attachment sizes are becoming larger. This means that security, archiving, and continuity systems must be able to scale easily. Learn to manage your email better…

» View this White Paper

Featured Sponsors