Hacker Terminology and Devices
Hacker Terminology and Devices
By the Wyoming SBDC Network Cybersecurity for Small Businesses Program
The realm of hackers has a lot of confusing terminology and devices that it can be hard to know what everyone is talking about. While we may not be the ones using or designing these tools and technology, it’s still important to be aware of them. Knowing what a pineapple is, or the purpose of a rubber duck, or even whatever a skiddie is, can help you identify risks, or just impress at your next IT meeting. This will not be a complete list of all devices, or terminology, but only what you are likely to encounter.
Devices:
Pineapple: a pineapple is a wi-fi router that is broadcasting a wi-fi signal meant to imitate a public wi-fi access. They are designed to let your computer access the internet while it gains access to your computer and steal information off of it.
Rubber Duck: This is a USB drive designed to connect to your computer and execute a series of commands faster than you can rip the drive out of your computer/phone. This is done by making the USB identify itself as a keyboard, allowing root level access to the drive and the ability to execute commands and send information to a cloud system or E-mail of the maker.
O.M.G. Cable: These are commonly seen as charging cables left in public places. These cables have internal hardware that operates similarly to a Rubber Duck, connect to a device, steal information, send to a cloud or E-mail, all before you can stop it.
RFID Spoofer: This is a device used to scan an RFID chip, save its data, and to rebroadcast it at a different time. This is commonly used to spoof credit cards or can be used to mimic company id cards used to scan into building and rooms.
Terminology:
Skiddie (Script Kiddie): These are hackers who don’t actually write code, but rather take other people’s code and run it to try and gain access to systems or to cause other harmful actions.
Root: This is a common computer term that’s meant to refer to the lowest level of a computer. This is what allows software/users direct access to the hardware of a computer and additional privileges that go above administrative powers.
Black Hat: These are the malicious hackers who are here for personal gain or to cause damage.
Grey Hat: These are hackers who operate in a grey area, they can cause damage just like black hats but can sometimes expose vulnerabilities to organizations just because.
White Hat: These are the good guys, ethical hackers who are hired to find, and patch vulnerabilities in software and systems.
Ransomware: This is when a malicious actor who gains access to your information and locks it down. This is done by Encrypting the data and keeping the password to un encrypt the data.
Encryption: This is the process of obfuscating data by changing addressing of the data or by changing how the data is meant to be read.
DDoS (Distributed Denial of Service): This is where a malicious actor sends lots of data/requests to your website/server to prevent users, customers, or employees from using the service.
Keylogger: This is software that runs in the background that watches your keyboard and records all the key presses. This can be used to obtain login details, passwords, and email contents.
Social Engineering: These are tactics people use to try and get others to expose personal information that can potentially password related, or used to impersonate a person.
Trojan: This is malicious software designed to imitate or appear as legitimate software while stealing or providing access to the system it’s installed on.