Terminology



This is a list of some basic terminology you may find me using from time to time. It short right now, but I'll add more as I get the time. 
 
 

Ankle Biter - This is a term used to describe relatively new hackers, or expericenced hackers who "Just don't get it." They are somewhat successful in their hacking exploits simply because most site security is so pathetic. They are also referred to as Script Kiddies

BOHICA - An acronym that is short for: Bend Over Here It Comes Again. This generally refers to some situation or circumstance that results in your taking it up the ass. For system security there are a few system daemons that I consider instant BOHICA material, not because they are any worse than any other service (well the R-services do just plain suck), but because they tend to almost always be setup incorrectly or are inherently flawed: 

R*-Services (RSH, Rlogin)
Rexd
NFS
TFTP
Finger
NIS
X-Windows
 

BOGAHICA - From the root BOHICA, this is an acronym that is short for: Bend Over, Grab Ankles, Here It Comes Again. This his a saved for that heightened sense of knowing you are about to get screwed really badly. This word can be used interchangably with BOHICA, but proper form is to save it for the more serious situations. 

"Just Don't Get It." - A favorite term of mine that a friend of mine often used to describe people who, well, Just Don't Get It. This can apply to any number/types of people you run across in everyday life. For computer security professionals though, this is a hacker who repeatedly tries and fails to hack your network or, after having been discovered and kicked off, makes repeated attempts to gain re-entry and risk getting caught. 

An example of a person who "Just Don't Get It" is a system I set up once to lure hackers into trying out their IMAP exploits so I could see what they were doing. After having gotten the information I needed I put up a simple banner that would display "THIS PORT IS A TRIPWIRE. YOU ARE BEING WATCHED -- GO AWAY" anytime someone connected to the port. Much to my chagrin, I still had several people repeatedly try their exploits against the host and have them fail. They finally got the clue when I shut off the service altogether, but it wasn't for a lack of trying on my part I assure you. 

Script Kiddies - Hackers who run code and exploits that other people have written to gain access to hosts. They are often beginners and don't even know what the exploit does or what protocol flaws are being attacked. They are closely related to ankle biters







All Material Copyright ©1996-99 Craig H. Rowland and Psionic Software Systems
Contact Me
Site last updated: 1999/03/24