The dollars and cents of hacking
InfoWorld - SAN FRANCISCO -- I recently attended a local meeting of the Information Systems Audit and Control Association (ISACA) to hear a presentation by Mark Loveless, who heads up the Razor research team at BindView.
Besides talking about the many threats that face security administrators, Loveless also spoke about the changing nature of the hackers and groups that are causing security threats.
Many hackers are known as "black-hat" hackers, those who generally hack systems for personal gain or malicious reasons. Black-hat hackers either exploits these hacks for themselves or trade or sell that information.
A "gray-hat" hackers hack systems and software without the administrator's or developer's permission in order to uncover network or software problems. Many of these hackers used to operate alone but now work for organized crime, foreign governments, or spammers.
According to Loveless, the black-market price for exploit code for a known flaw -- such as some of the recently announced Internet Explorer flaws -- is between $100 and $500. That's the price if no exploit code is available; after the exploit code is made available on public forums, the price drops to zero.
Exploit code for an unknown flaw is -- not surprisingly -- considerably more valuable: Prices for unknown exploits range between $1,000 and $5,000. Among the buyers of those codes are various foreign governments, foreign and domestic organized crime groups, and iDefense, a company that buys the exploits then informs its clients of the flaw.
Want to know who has your e-mail address? Get in line. A list of 5,000 IP addresses of computers infected with spyware and ready and able to go into "bot" mode goes for $150 to $500.
If you're in the black market for a list of 1,000 working credit card numbers, expect to fork over between $500 and $5,000. Some sites even will send you a couple of free numbers to test drive prior to purchase, Loveless says, while others have rating services of the different credit card number sellers, much like eBay Inc.
Prices were even cheaper for those numbers, although the price has increased since the U.S. Secret Service began Operation Firewall, an investigation that targets underground hacker organizations known as Shadowcrew, Carderplanet, and Darkprofits.
What do these black-hat hackers working for spammers make for their trouble? According to Loveless, the annual salary of a top-end, skilled black-hat hacker working for spammers is between $100,000 and $200,000. Not bad, although if you're caught, legal costs will eat that up in a matter of weeks.
Apparently not all black-hathackers are making the big bucks, however. I spoke recently with Bill Hancock, Savvis Communications Corp.'s chief security officer and chairman of the FCC's National Reliability & Interoperability Council (NRIC) Homeland Security focus group on cybersecurity, who says some black-hat hackers are wearing their hats under protest.
Hancock had dinner with a hacker from Eastern Europe last year who said the Russian mafia threatened his family if he did not perform work for them. "I think it shows how serious and how difficult a problem this can be," he says.
Indeed, but it still pays to know your foe.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- Protecting Point of Sale Systems from Targeted Attack
- If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on...
- From the Frontline - Preventing APT
- Is your company's network secure? Are your endpoints and servers secured? Before you answer, read this case study on a US Military Command...
- Stop Hackers Before They Attack
- Hacktivism, Identify Theft, Financial Gain, Cyber War - regardless of motivation, stopping today's hackers requires a new proactive approach to protecting endpoints. Learn...
- The four rules of complete web protection
- As an IT manager you've always known the web is a dangerous place. But with infections growing and the demands on your time... All Cybercrime and Hacking White Papers
- WikiLeaks: How am I Affected?
- The latest WikiLeaks episode has raised questions about how organizations and governments protect their sensitive information. While this incident was isolated, it has...
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn... All Cybercrime and Hacking Webcasts