# What Exactly is hacking and how to do it?

**URL:** <https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852>\
**Category:** Factual Questions\
**Created:** [March 1, 2018, 8:36pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852 "2018-03-01T20:36:51Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![Clothahump](https://avatars.discourse-cdn.com/v4/letter/c/51bf81/32.png) [@Clothahump](https://boards.straightdope.com/u/Clothahump)\
**Post date:** [March 1, 2018, 10:39pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/21 "2018-03-01T22:39:46Z")

</div>

Read Steven Levy’s book [HACKERS](https://smile.amazon.com/Hackers-Heroes-Computer-Revolution-Anniversary-ebook/dp/B003PDMKIY/ref=sr_1_2?ie=UTF8&qid=1519943913&sr=8-2&keywords=hackers). Quite fascinating!

---

<div class="post-metadata">

**Author:** ![Francis\_Vaughan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/francis_vaughan/32/3093_2.png) [@Francis\_Vaughan](https://boards.straightdope.com/u/Francis_Vaughan)\
**Post date:** [March 1, 2018, 10:41pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/22 "2018-03-01T22:41:41Z")

</div>

> [@Clothahump](#):
>
> Read Steven Levy’s book [HACKERS](https://smile.amazon.com/Hackers-Heroes-Computer-Revolution-Anniversary-ebook/dp/B003PDMKIY/ref=sr_1_2?ie=UTF8&qid=1519943913&sr=8-2&keywords=hackers). Quite fascinating!

Yes, this is the real story of the true hackers - not the modern idea of people who break into things.

---

<div class="post-metadata">

**Author:** ![Doug\_K](https://avatars.discourse-cdn.com/v4/letter/d/b5ac83/32.png) [@Doug\_K](https://boards.straightdope.com/u/Doug_K)\
**Post date:** [March 1, 2018, 10:48pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/23 "2018-03-01T22:48:20Z")

</div>

[How to be a hacker.](http://www.catb.org/esr/faqs/hacker-howto.html)

> [@](#):
>
> There is another group of people who loudly call themselves hackers, but aren’t. These are people (mainly adolescent males) who get a kick out of breaking into computers and phreaking the phone system. Real hackers call these people ‘crackers’ and want nothing to do with them. Real hackers mostly think crackers are lazy, irresponsible, and not very bright, and object that being able to break security doesn’t make you a hacker any more than being able to hotwire cars makes you an automotive engineer. Unfortunately, many journalists and writers have been fooled into using the word ‘hacker’ to describe crackers; this irritates real hackers no end.
> 
> The basic difference is this: hackers build things, crackers break them.
> 
> If you want to be a hacker, keep reading. If you want to be a cracker, go read the alt.2600 newsgroup and get ready to do five to ten in the slammer after finding out you aren’t as smart as you think you are. And that’s all I’m going to say about crackers.

---

<div class="post-metadata">

**Author:** ![msmith537](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@msmith537](https://boards.straightdope.com/u/msmith537)\
**Post date:** [March 1, 2018, 10:58pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/24 "2018-03-01T22:58:34Z")

</div>

Broadly speaking, “hacking” involves gaining access to computer systems and networks that you are not authorized to access. It can also involve disrupting those systems, such as with a “denial of service” attack (which basically involves spamming a site with connection requests until you clog up the bandwidth)

The “how” it’s done consists of a number of techniques, including:  
-Social engineering - tricking a legitimate user into providing their credentials  
-Exploiting software vulnerabilities - using flaws in computer programs to gain access. For example, a “SQL injection” attack where you enter “or 1=1” as the user name for a login screen. If the code is badly written, the request “SELECT \* FROM usertable WHERE username = ‘’ or 1=1” will be sent to the database, possibly outputting a list of every user name. This is a simple example that pretty much every site should already account for.  
-Introducing “malware” (viruses, Trojans, bots, worms, etc) into a system. How they are introduced can vary from a simple email attachment or link to malicious software embedded within legitimate software. Once the software is installed, it can sit on the system for weeks or months waiting for an opportunity to do it’s thing.

The image of hacker dueling with his corporate cyber security counterpart to gain access to some system while illegible code streams by Matrix-like is largely a Hollywood fiction.

---

<div class="post-metadata">

**Author:** ![msmith537](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@msmith537](https://boards.straightdope.com/u/msmith537)\
**Post date:** [March 1, 2018, 11:02pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/25 "2018-03-01T23:02:31Z")

</div>

One edit. I don’t want to kick off a philosophical discussion on legitimate vs illegitimate hacking. Even more broadly speaking, “hacking” may also refer to “white hat” hackers who work to find security vulnerabilities or are asked to conduct penetration testing of corporate, government or other institutional systems.

So another term for illegal or malicious hacking might be “cyber criminal” or “cyber terrorist”.

---

<div class="post-metadata">

**Author:** ![Doug\_K](https://avatars.discourse-cdn.com/v4/letter/d/b5ac83/32.png) [@Doug\_K](https://boards.straightdope.com/u/Doug_K)\
**Post date:** [March 2, 2018, 12:47am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/26 "2018-03-02T00:47:05Z")

</div>

> [@msmith537](#):
>
> One edit. I don’t want to kick off a philosophical discussion on legitimate vs illegitimate hacking. Even more broadly speaking, “hacking” may also refer to “white hat” hackers who work to find security vulnerabilities or are asked to conduct penetration testing of corporate, government or other institutional systems.
> 
> So another term for illegal or malicious hacking might be “cyber criminal” or “cyber terrorist”.

Or “cracker”, which is the correct term.

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [March 2, 2018, 2:10am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/27 "2018-03-02T02:10:43Z")

</div>

> [@Francis\_Vaughan](#):
>
> Sadly the term “hacking” has been subverted from its initial meaning…

This battle was lost 20 years ago. Nobody who actually matters cares about this distinction anymore.

---

<div class="post-metadata">

**Author:** ![Francis\_Vaughan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/francis_vaughan/32/3093_2.png) [@Francis\_Vaughan](https://boards.straightdope.com/u/Francis_Vaughan)\
**Post date:** [March 2, 2018, 2:25am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/28 "2018-03-02T02:25:12Z")

</div>

> [@friedo](#):
>
> This battle was lost 20 years ago. Nobody who actually matters cares about this distinction anymore.

I know. But it remains true. Depends upon when you grew up in the field.

---

<div class="post-metadata">

**Author:** ![Doug\_K](https://avatars.discourse-cdn.com/v4/letter/d/b5ac83/32.png) [@Doug\_K](https://boards.straightdope.com/u/Doug_K)\
**Post date:** [March 2, 2018, 2:44am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/29 "2018-03-02T02:44:25Z")

</div>

> [@friedo](#):
>
> This battle was lost 20 years ago. Nobody who actually matters cares about this distinction anymore.

I hate this argument. What if that argument had been made about slavery?

Anyway, the distinction is important because it leaves us without a clear, concise way to refer to actual hackers. Or as I explained to some of my colleagues (I work in a public school now), what if there were a rash of people breaking into schools and destroying or stealing stuff and the press started referring to them as “educators”? Or any profession, for that matter? “An notorious researcher group managed to break into the labs at the Mayo Clinic and steal 5 years worth of important data. It was the biggest act of research to date.”

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [March 2, 2018, 3:48am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/30 "2018-03-02T03:48:34Z")

</div>

> [@](#):
>
> Quoth **Spiderman** :
> 
> Hacking simply means gaining unauthorized access to a computer.

Even more generally: Hacking means getting any computer system to do anything it wasn’t designed for. Letting in unauthorized users is one thing that computers weren’t designed for, true, but it’s far from the only one. All major advances in computing have been hacks, because the first person to do them was using systems to do things that they had never been designed for before.

Also of note, a lot of cracking nowadays is of the “monkey pushes a button” type: Someone gets a cracking program from somewhere that automatically does something-or-other, pushes a button on it, and lets the program do all of the work. This isn’t hacking, because you’re using that premade tool to do exactly what it was designed for. Now, the guy who created that tool, he probably is a hacker.

---

<div class="post-metadata">

**Author:** ![Projammer](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/projammer/32/559_2.png) [@Projammer](https://boards.straightdope.com/u/Projammer)\
**Post date:** [March 2, 2018, 5:13am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/31 "2018-03-02T05:13:23Z")

</div>

> [@Francis\_Vaughan](#):
>
> A little while ago a similar issue (heartbleed) allowed leaking of information over internet connections. [xkcd: Heartbleed Explanation](https://xkcd.com/1354/)

I remember reading about heartbleed when it was first publicly announced and thinking that was exactly the sort of cheesy exploit you’d expect to see in a mainstream hacker movie.

How was it not blindingly obvious to the person(s) coding up that handshake module?

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [March 2, 2018, 6:16am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/32 "2018-03-02T06:16:36Z")

</div>

> [@Projammer](#):
>
> How was it not blindingly obvious to the person(s) coding up that handshake module?

Buffer overflow errors are one of the most common security exploits because C does not have any automatic bounds checking on arrays. Good programming practices and more modern tools make this stuff easier to catch before it gets into the wild, but there’s a lot of old, crusty code out there that nobody looks at very closely.

---

<div class="post-metadata">

**Author:** ![Absolute](https://avatars.discourse-cdn.com/v4/letter/a/b2d939/32.png) [@Absolute](https://boards.straightdope.com/u/Absolute)\
**Post date:** [March 2, 2018, 6:40am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/33 "2018-03-02T06:40:37Z")

</div>

Google Project Zero is dedicated to finding and reporting security vulnerabilities in all computer systems (they were one of the groups that discovered the recent Meltdown and Spectre vulnerabilities).

Once a vulnerability has been reported to the vendor and fixed, they sometimes post a detailed explanation of how they found it and developed the exploit.

These posts are a great explanation of what actual, modern “hacking” consists of.

A few examples

> **[Exploiting the Linux kernel via packet sockets](https://googleprojectzero.blogspot.com/2017/05/exploiting-linux-kernel-via-packet.html)**
>
> Guest blog post, posted by Andrey Konovalov Introduction Lately I’ve been spending some time fuzzing network-related Linux kernel int...

> **[Over The Air: Exploiting Broadcom’s Wi-Fi Stack (Part 1)](https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html)**
>
> Posted by Gal Beniamini, Project Zero It’s a well understood fact that platform security is an integral part of the security of comple...

> **[Over The Air - Vol. 2, Pt. 1: Exploiting The Wi-Fi Stack on Apple Devices](https://googleprojectzero.blogspot.com/2017/09/over-air-vol-2-pt-1-exploiting-wi-fi.html)**
>
> Posted by Gal Beniamini, Project Zero Earlier this year we performed research into Broadcom’s Wi-Fi stack. Due to the ubiquity of Broa...

---

<div class="post-metadata">

**Author:** ![edwardcoast](https://avatars.discourse-cdn.com/v4/letter/e/cab0a1/32.png) [@edwardcoast](https://boards.straightdope.com/u/edwardcoast)\
**Post date:** [March 2, 2018, 6:53am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/34 "2018-03-02T06:53:35Z")

</div>

> [@DekaJay](#):
>
> 😕 In the movies; you normally see a 30-something year old with a computer tap the keyboard for a few seconds, have a little montage, then say “I’m In!” then everyone celebrates and moves on. but what happens between tapping the keyboard and getting “In”. and what kinds of things can you get into? How would I go about doing this? Is there someone who could teach me, or send me a link?:dubious:

What you see in the movies is complete bullshit. They make it look like any computer in the world is accessible by any other computer, without any security and passwords are zero protection. If all anyone had to do was tap on the keyboard for a few seconds to gain access we would stop using computers entirely, because they wouldn’t be secure at all.

As for the movies, it depends on their story lines, but overall, unless you know how development was done on a system it would take a long time even assuming you gained access to find what you’re looking for. It’s the same plot device on Star Trek, they come across a totally alien culture and somehow they instantly know how to work the equipment. Meanwhile in real life, most people can’t program their thermostats without studying the manually.

---

<div class="post-metadata">

**Author:** ![Riemann](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/riemann/32/3133_2.png) [@Riemann](https://boards.straightdope.com/u/Riemann)\
**Post date:** [March 2, 2018, 11:17am UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/35 "2018-03-02T11:17:55Z")

</div>

> [@Gorsnak](#):
>
> The girl with the uzi. Is she single?

It’s not about who’s got the most bullets. It’s about who controls the information!

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [March 2, 2018, 12:33pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/36 "2018-03-02T12:33:39Z")

</div>

> [@friedo](#):
>
> This battle was lost 20 years ago. Nobody who actually matters cares about this distinction anymore.

Actually it’s been doubly lost. I’m an ex-CS prof and at all the places I went to school and taught at a “hacker” was a _lousy_ programmer. A “hack” was a poorly done way of sort-of solving a problem. It means kind of the same thing as used in describing a hack writer.

The hacker = good programmer thing was basically an MIT thing. (Hence the only person I knew at any of these places who used it that way was from MIT.)

Note that it is a _lot_ more natural to derive the cracking meaning of hacking from this definition than the other since many cracks are quick and dirty jobs. How it could have been derived from the MIT meaning baffles me.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [March 2, 2018, 12:42pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/37 "2018-03-02T12:42:30Z")

</div>

“Hacker” has never quite precisely meant “good programmer”, even in the MIT sense. You could say “clever programmer”, but even that loses some of the nuance. The mark of a hack is that, if you tell someone what you did, they’d say “Wait, and that actually worked?”.

The difference in culture between MIT and the rest of the world is that MIT respected that.

---

<div class="post-metadata">

**Author:** ![Doug\_K](https://avatars.discourse-cdn.com/v4/letter/d/b5ac83/32.png) [@Doug\_K](https://boards.straightdope.com/u/Doug_K)\
**Post date:** [March 2, 2018, 4:29pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/38 "2018-03-02T16:29:41Z")

</div>

> [@Chronos](#):
>
> “Hacker” has never quite precisely meant “good programmer”, even in the MIT sense. You could say “clever programmer”, but even that loses some of the nuance. The mark of a hack is that, if you tell someone what you did, they’d say “Wait, and that actually worked?”.
> 
> The difference in culture between MIT and the rest of the world is that MIT respected that.

Not just an MIT thing. We certainly knew what a real hacker is at my small college in the midwest in the mid 80s. Some of the CS classes at Harvard still have a “hacker edition” of the coursework for students who want to dig into the subject more. (I never attended Harvard, I’ve just watched some of their podcasts of classes.) While it’s true that a piece of work that’s considered a hack is ugly and maybe just sheer luck that it works, a hacker isn’t someone who just throws stuff at the wall to see if it sticks, even if it looks like it. A hacker can reliably come up with unconventional solutions and know they’re going to work and be able to explain why. It’s part of the “first make it work, then make it pretty” philosophy.

---

<div class="post-metadata">

**Author:** ![Projammer](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/projammer/32/559_2.png) [@Projammer](https://boards.straightdope.com/u/Projammer)\
**Post date:** [March 2, 2018, 5:52pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/39 "2018-03-02T17:52:52Z")

</div>

> [@friedo](#):
>
> Buffer overflow errors are one of the most common security exploits because C does not have any automatic bounds checking on arrays.

Exactly. Buffer over/underflow has bitten my ass more times than I can count. The way this function was designed/written was textbook for a buffer read exploit. Literally “tell the remote server how much data to send back”

---

<div class="post-metadata">

**Author:** ![Blue\_Blistering\_Barnacle](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/blue_blistering_barnacle/32/3386_2.png) [@Blue\_Blistering\_Barnacle](https://boards.straightdope.com/u/Blue_Blistering_Barnacle)\
**Post date:** [March 2, 2018, 10:17pm UTC](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852/40 "2018-03-02T22:17:28Z")

</div>

> [@ftg](#):
>
> Actually it’s been doubly lost. I’m an ex-CS prof and at all the places I went to school and taught at a “hacker” was a _lousy_ programmer. A “hack” was a poorly done way of sort-of solving a problem. It means kind of the same thing as used in describing a hack writer.
> 
> The hacker = good programmer thing was basically an MIT thing. (Hence the only person I knew at any of these places who used it that way was from MIT.)
> 
> Note that it is a _lot_ more natural to derive the cracking meaning of hacking from this definition than the other since many cracks are quick and dirty jobs. How it could have been derived from the MIT meaning baffles me.

> [@Chronos](#):
>
> “Hacker” has never quite precisely meant “good programmer”, even in the MIT sense. You could say “clever programmer”, but even that loses some of the nuance. The mark of a hack is that, if you tell someone what you did, they’d say “Wait, and that actually worked?”.
> 
> The difference in culture between MIT and the rest of the world is that MIT respected that.

So, in the early evolution of the term “to hack”, did it mean “throwing stuff at the wall and seeing what sticks”?

Sometimes that describes my feeble attempts at programming. The rapid trial/debug/retry/debug/… thing that happens with incremental progress makes me sometimes feel that I’m “hacking away” at something.

[Previous page](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852.md?page=1)

[Next page](https://boards.straightdope.com/t/what-exactly-is-hacking-and-how-to-do-it/809852.md?page=3)
