https://www.americancityandcounty.com/wp-content/themes/acc_child/assets/images/logo/footer-logo.png
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcast
    • Latest videos
    • Product Guides
  • Resources & Events
    • Back
    • Resources
    • Webinars
    • White Papers
    • IWCE 2022
    • How to Contribute
    • Municipal Cost Index – Archive
    • Equipment Watch Page
    • American City & County Awards
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Privacy Statement
    • Terms of Service
American City and County
  • NEWSLETTER
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcasts
    • Latest videos
    • Product Guides
  • Resources/Events
    • Back
    • Webinars
    • White Papers/eBooks
    • IWCE 2022
    • How to Contribute
    • American City & County Awards
    • Municipal Cost Index
    • Equipment Watch Page
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Privacy Stament
    • Terms of Service
  • newsletter
  • Administration
  • Economy & Finance
  • Procurement
  • Public Safety
  • Public Works & Utilities
  • Smart Cities & Technology
  • Magazine
acc.com

Public Safety


Beware of Script Kiddies

Beware of Script Kiddies

Internet security experts call them a host of names: wannabe hackers, Internet vandals, criminals and nuisances. But the term may describe them best.
  • Written by Michael Fickes
  • 1st May 2003

Internet security experts call them a host of names: wannabe hackers, Internet vandals, criminals and nuisances. But the term “script-kiddies” may describe them best.

Last March, someone broke into a computer at the National Security Agency in Ft. Meade, Md., and made off with materials from the public affairs office including biographies and some unclassified e-mail correspondence.

Government officials did not appear to consider the breach a security threat. The hackers, however, posted the stolen materials around the Internet with a message boasting about the break-in.

The incident may have embarrassed the NSA, but then, who cares if information in the public affairs office is made public? After all, isn't that the goal?

Sounds like a script kiddie caper.

Maybe, says Chris Shutters, chief engineer with Polivec Inc., Mountain View, Calif., a company that helps businesses to automate information technology (IT) security policies. “That's the kind of thing script kiddies do,” Shutters says. “They want to perform an unauthorized or malicious act against a computer system but often don't have the technical skills to pull it off.”

Script kiddies are a hacker subset. They attack systems when they can, for bragging rights, or political reasons. Unlike their counterparts, script kiddies need technical help.

Skilled hackers often succeed in figuring out ways to break into computer systems. When successful, they sometimes produce scripts or software applications that automate their methods of attack and post them on Internet Web sites for anyone to use.

Script kiddies use these scripts but often don't understand everything the scripts will do, says William Orvis, senior security specialist with the Lawrence Livermore National Laboratory in Livermore, Calif. A script kiddie might want to break into a system and look around — in secret — but could end up shutting the system down by accident, thanks to an unnoticed feature in the script.

The NSA break-in in March had script kiddie fingerprints of a different sort. Whoever carried out that attack felt the urge to brag about it in the media despite the innocuous results.

“A good hacker is like a savvy car thief who can get past a ‘Club’ and other security systems,” says Bill Murray, a spokesperson for the FBI's cyber division. “A script kiddy is more like a car thief testing door handles to find the car that has been left unlocked.”

In other words, to counter script kiddies, system administrators must lock the doors to the computer system.

“We advocate firewalls, anti-virus protection, and strong passwords with more than eight characters combining upper and lower case letters, numbers, and symbols,” Murray says.

Orvis also recommends keeping up-to-date on system patches supplied by operating system vendors. “Suppose someone runs a program called Winnuke and types in the address of an un-patched Windows box on your network,” says Orvis. “The computer will go blue screen.”

Operating system vendors regularly issue patches or security updates designed to protect against specific kinds of attack programs such as Winnuke.

In fact, most of the newer operating systems can update patches on their own — Windows 2000, for example, will automatically check the Microsoft Web site for newly-issued security patches, and the computer can be set to download and install those patches as they become available.

“The fact that a company issues a security update means that someone knows how to do bad things to your system, and that's what leads to scripts,” Shutters says.

In addition to these basic script kiddie defenses, Shutters recommends turning off unnecessary Internet servers connected to a network. “If it's turned off, a script kiddie can't break into it.”

Shutters also points out that network software has grown so complex that system administrators may not know about all the portals a hacker might find to crawl through. “One of our clients built a network system, and the installation process added 14 network services that the administrator didn't know were there,” Shutters says.

Finally, Shutters suggests taking a hacker's view of a system and looking for ways to break in. Many script kiddies use software called vulnerability scanners, he says. By typing a computer's Internet address into the scanner, such a program will search for and report back on weaknesses of a particular server or a series of servers. “Then a script kiddie will launch scripts at those weak spots,” he says. “If a system administrator runs the vulnerability scanner first, it's possible to fix problems before script kiddies find them.”

Tags: Public Safety

Most Recent


  • public safety
    State and local leaders can alleviate the burden on public safety personnel by tackling three workforce trends
    Government officials and public safety leaders wear many different hats. They serve as sounding boards for constituent complaints and for new ideas that need vetting. They are change agents charged with improving the lives of citizens and colleagues and are tasked with keeping order. Their most daunting responsibility, however, is keeping members of their community […]
  • Building safety report can help local administrators evaluate security, determine and mitigate risk
    Driven by a slew of tragic shootings over the last few decades, the hardening of building safety features designed to protect inhabitants from active shooters have risen to the forefront of public discourse. As the latest contribution to this discussion, the International Code Council recently published a report on building safety and security that’s intended […]
  • NLC, lawmakers call for railway regulation in wake of Ohio hazardous materials derailment
    It’s been a little more than one month since the dramatic derailment in Ohio of a Norfolk Southern Railway train pulling 20 cars loaded with hazardous materials, which subsequently went up in toxic flames. Local lawmakers are calling for stricter government regulation. “With 140,000 miles of track in the U.S. crossing directly through many of […]
  • road safety
    Government can strike a calming balance between road safety and speed
    We live in a time of extremes that impact nearly every aspect of our lives. Even driving has become a hotly debated topic. Spurred by the rising death toll resulting from speeding and distracted driving, safe driving advocates are demanding implementation of so-called Vision Zero measures designed to force drivers to slow down and create […]

Leave a comment Cancel reply

-or-

Log in with your American City and County account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • How governments can keep employees safe as they return to work
  • Preventing cyber-attacks needs to be a priority for local governments
  • Building community and officer wellness through data sharing
  • California city combines advanced technology with dedicated public safety team for comprehensive emergency management

White papers


Digital Government Service Delivery – A Guide for Buyers

23rd February 2023

Modernizing government services for today’s resident expectations

24th January 2023

Preparing Your Community Now for the Next Generation of Older Adults

18th October 2022
view all

Webinars


Future-proof Your State and Local Government Finance: 5 Key Trends for 2023

6th February 2023

How To: Evaluate Digital Government Service Delivery Technologies

23rd January 2023

Using Technology to Enhance Communications

29th November 2022
view all

PODCAST


Young Leaders Episode 4 – Cyril Jefferson – City Councilman, High Point, North Carolina

13th October 2020

Young Leaders Episode 3 – Shannon Hardin – City Council President, Columbus, Ohio

27th July 2020

Young Leaders Episode 2 – Christian Williams – Development Services Planner, Goodyear, Ariz.

1st July 2020
view all

GALLERIES


Gallery: America’s top 10 bicycle-friendly cities

20th March 2023

Gallery: Top 10 hardest working American cities

8th March 2023

Gallery: Top 10 least expensive American metro areas

24th February 2023
view all

Twitter


AmerCityCounty

Overcoming worker shortages in public sector amidst growing demand dlvr.it/SlYssG

27th March 2023
AmerCityCounty

Report: Renters living at or below the poverty line face a ‘severe shortage of housing’ dlvr.it/SlR6rb

24th March 2023
AmerCityCounty

Report: Technology is encouraging unprecedented collaboration in local government organizations dlvr.it/SlNYqx

23rd March 2023
AmerCityCounty

Metal buildings can be a lifesaver for local governments needing to expand dlvr.it/SlMCV1

23rd March 2023
AmerCityCounty

Transportation department to invest $94M into projects promoting innovation, safety dlvr.it/SlKRf7

22nd March 2023
AmerCityCounty

How state and local CIOs can prioritize security, cloud and legacy systems dlvr.it/SlK7H1

22nd March 2023
AmerCityCounty

Addressing the housing crises requires creativity, collaboration dlvr.it/SlGTFz

21st March 2023
AmerCityCounty

St. Louis Communities Boost Great Energy Savings dlvr.it/SlFyV0

21st March 2023

Newsletters

Sign up for American City & County’s newsletters to receive regular news and information updates about local governments.

Resale Insights Dashboard

The Resale Insights Dashboard provides model-level data for the entire used equipment market to help you save time and money.

Municipal Cost Index

Updated monthly since 1978, our exclusive Municipal Cost Index shows the effects of inflation on the cost of providing municipal services

Media Kit and Advertising

Want to reach our digital audience? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • IWCE’s Urgent Communications
  • IWCE Expo

WORKING WITH US

  • About Us
  • Contact Us

FOLLOW American City and County ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.