The Different Types of Hacking
Hacking is a malicious attack on a digital asset to cause damage, steal data or disrupt operations. It can be completely legal and ethical (white hat) as in penetration testing or completely illegal and unauthorized (black hat).
The term ‘hacking’ has been around for decades, but it gained popularity in the 1980s when personal computers became widely available to consumers. As a result, hackers diversified their skills and began to exploit vulnerabilities in telecommunications networks. This new breed of hackers, known as phreakers, achieved notoriety for exploiting operational characteristics in telephone switching networks to make free long-distance calls.
White hat hackers use their skills to test and improve security systems. This type of hacking is called penetration testing and is considered a vital part of modern cybersecurity. Black hat hackers have nefarious motives, ranging from stealing secrets from organizations to access their private information to selling it on the dark web. They may be motivated by a sense of achievement, such as gaining recognition from their hacking accomplishments on social media.
Opportunistic threat actors, also known as gray hat hackers, operate in a moral middle ground. They often scan the Internet for vulnerable machines, leveraging the knowledge of a vulnerability that has been exposed in news publications. Once they gain a foothold in a system, they can launch fileless attacks — running scripts directly in the memory of the targeted machine to avoid detection by security tools. For example, when the Heartbleed vulnerability was disclosed in news publications, opportunistic threat actors quickly scanned the Internet for vulnerable machines using OpenSSL and exploited those vulnerabilities.