Hacker Classes, Hacktivism and the Types of Hacking
Chapter Seven
Syllabus topic Module 1, "Foundations of Ethical Hacking and Cyber Terminology: Study core terminology including hacking types, hacker classes, hacktivism"
Pages 31 to 35 of 578
In one line
Hackers are classified by whether they have permission, not by how skilled they are. A white hat tests with authorisation; a black hat attacks without it; a grey hat acts without permission but usually without malice, which is well meant and still unlawful.
In examination wording: hackers are commonly classified by the lawfulness and intent of their activity. White-hat hackers (ethical hackers) test systems with the owner's authorisation to improve security; black-hat hackers gain unauthorised access for personal gain, damage or other criminal purpose; grey-hat hackers act without authorisation but typically without malicious intent, often disclosing what they find. Related categories include script kiddies, hacktivists, insiders and state-sponsored actors.
Why the popular classification is nearly useless, and how to fix it
The familiar "hat" scheme comes from old Western films, where the hero wore white and the villain black. As popular shorthand it is harmless; as a professional definition it fails, because it appears to classify people by character, and character is not something a court, a client or an examiner can assess.
The fix is the one the law already made for us in the previous chapters. Section 43 of the IT Act turns on a single fact: permission of the owner. So classify by that, and the scheme becomes precise, testable and consistent with the statute:
| Class | Permission? | Typical intent | Legal position |
|---|---|---|---|
| White hat | Yes, written and scoped | Improve the owner's security | Lawful |
| Black hat | No | Gain, damage, disruption | s.43 and, with dishonesty, s.66 |
| Grey hat | No | Curiosity, reputation, often to warn | s.43 applies; good motive is not a defence |
Read down the "permission" column and you have the whole distinction. Everything else, skill, tools, motive, is secondary detail.
White hat: the ethical hacker
A white hat tests systems with the owner's authorisation, within an agreed scope, to find weaknesses before somebody hostile does, and reports them to the owner rather than using or publishing them. This is the role this entire course trains you for, and its defining features are the three documents of the earlier chapter: an authorisation, a scope, and rules of engagement.
Two things a white hat is not. They are not necessarily more skilled than a black hat; the distinction is not competence. And they are not merely "a hacker who is nice about it"; the discipline is procedural, and a tester who strays outside scope is not a white hat who made a mistake, they are unauthorised for that system.
Black hat: the criminal attacker
A black hat gains unauthorised access for their own purposes: money, disruption, theft of information, damage, or occasionally simple vandalism. They are the threat actor the rest of this book teaches you to anticipate.
Hacker Classes, Hacktivism and the Types of Hacking
It is worth being precise about motive, because "for fun" is an outdated picture. Most serious attacks today are economically motivated and organised: ransomware operations, fraud, and the theft and sale of data are businesses with specialisation, tooling and support functions. A defender who imagines a lone teenager will build the wrong defences against an adversary that behaves like an industry.
Grey hat: the one the examiner asks about
A grey hat acts without authorisation but without clear malicious intent. The archetype probes a stranger's website out of curiosity, finds a flaw, takes nothing, and emails the owner to tell them.
This is the class worth thinking about carefully, because students instinctively feel it must be acceptable. It is not, and the reason is precisely the chapter on section 43: liability turns on the absence of permission, and the section does not ask about motive, damage or what you did afterwards. Good intent may matter to whether anyone pursues the matter, and it negates the dishonesty that section 66 requires, but it does not make the access lawful.
There is also a practical trap. A grey hat who reports a flaw has just told an organisation, in writing, that they accessed its systems without permission. Some organisations respond with thanks; some respond with lawyers. The finder has no contract, no scope, and no safe harbour.
The professional route to doing exactly what a grey hat wants to do is the bug bounty or a written scope: permission granted in advance, which converts the same activity into authorised testing. That chapter comes later, and this is the problem it solves.
The other categories worth naming
Script kiddie. Someone who uses tools written by others without understanding them. The term is dismissive about skill, and it should not be dismissive about risk: the tools are genuinely powerful, and an unskilled attacker running a working exploit against an unpatched server succeeds exactly as well as a skilled one. Defences are not improved by the attacker's ignorance.
Hacktivist. Someone who attacks or defaces systems to make a political or social point rather than for money. Common forms are website defacement (an integrity attack), denial of service as protest, and the leaking of documents. Legally there is nothing special about hacktivism: the acts are the same acts under section 43, and a cause does not supply permission. The category matters for a defender because it changes targeting: hacktivists choose targets for visibility and symbolism, so an organisation can become a target for what it represents rather than for what it holds.
Insider. Someone who already has legitimate access and abuses it, or exceeds it. Insiders are dangerous because most defences face outward, and because an insider's activity looks like ordinary work. They divide into the malicious (grievance, money, espionage) and the negligent, who cause harm without meaning to, and the second group is much larger. Controls are least privilege, separation of duties, monitoring of privileged actions, and a good leavers process.
Hacker Classes, Hacktivism and the Types of Hacking
State-sponsored actor (sometimes called an advanced persistent threat). A government-backed group pursuing espionage or strategic disruption. What distinguishes them is not glamour but resources and patience: they can afford unknown vulnerabilities, they can wait months, and they do not give up because a first attempt failed. Most organisations are not their target; those that are cannot expect ordinary controls to suffice.
Suicide hacker. A term found in the CEH literature for an attacker indifferent to being caught, typically ideologically driven. It matters only because deterrence, which assumes the attacker fears consequences, does not work on them.
Types of hacking, by target
The syllabus also says "hacking types", which is usually taught as classification by what is attacked. Know the list, because it maps onto the structure of this book:
- Network hacking: scanning, sniffing, man-in-the-middle, denial of service.
- Web application hacking: injection, broken access control, cross-site scripting, session attacks.
- System hacking: gaining access to a host, privilege escalation, persistence.
- Wireless hacking: attacks on Wi-Fi authentication and encryption, rogue access points.
- Social engineering: attacks on people rather than machines.
- Mobile and cloud: attacks on applications and configurations in those environments.
Each is a later section of this book, and each is bounded by the same authorisation rule.
A worked example: one flaw, four people
A shopping site has a flaw letting any logged-in user read another customer's order by changing a number in the address.
- Anita is engaged under a signed scope naming that site. She finds it, proves it with two test accounts, and reports it with a fix. White hat. Lawful, because she had permission for that system.
- Bala finds it uninvited and quietly orders goods against other people's accounts. Black hat. Section 43 applies at once, and his dishonest purpose brings in section 66.
- Chandni finds it uninvited, looks at two orders to be sure it is real, takes nothing and emails the company. Grey hat. Well meant, still unauthorised: section 43 is engaged by the access, and her good motive is not a defence, though it negates section 66's dishonesty.
- Dev reads about the flaw online and runs a ready-made script against the site without understanding it. Script kiddie, and legally a black hat: no permission, and the lack of skill changes nothing.
Same flaw, same technique, four positions, decided by permission and purpose.
What beginners get wrong
- Classifying by skill. The classes are about authorisation. A highly skilled unauthorised tester is a black hat; a modestly skilled authorised one is a white hat.
- Believing a grey hat is safe because they meant well. Section 43 does not ask about motive. Good intent may negate section 66's dishonesty and may influence whether anyone pursues it, but it does not make the access lawful.
- Thinking hacktivism is a legal category. It describes motive, not lawfulness. The acts are the same offences; the cause supplies no permission.
- Underestimating script kiddies. The tools work. Your unpatched server does not care how well the attacker understands them.
- Defending only against outsiders. Insiders already have access, and the negligent insider is the commonest of all. Least privilege and monitoring exist for them.
- Assuming state actors are everyone's problem. They are not, and building for them while ignoring phishing and patching is a misallocation.
Hacker Classes, Hacktivism and the Types of Hacking
Quick revision
- Classify by permission, not by character: white hat (authorised, scoped, reports to the owner), black hat (unauthorised, criminal purpose), grey hat (unauthorised, not clearly malicious, still liable under s.43).
- Also: script kiddie (others' tools, no understanding, still dangerous), hacktivist (political motive, no legal difference, changes targeting), insider (malicious or, more often, negligent; least privilege and monitoring), state-sponsored (resources and patience).
- Hacking types by target: network, web application, system, wireless, social engineering, mobile and cloud.
- The lawful way to do what a grey hat does is a bug bounty or a written scope: permission in advance.
Test yourself
- On what basis are hacker classes properly distinguished, and why is skill the wrong basis?
On authorisation: whether the person has the owner's permission. Skill is the wrong basis because it has no bearing on lawfulness; a highly skilled unauthorised tester is a black hat, and section 43 turns on permission, not competence.
- A grey hat finds a flaw uninvited, takes nothing, and reports it. What is their legal position?
Section 43 is engaged, because they secured access without the owner's permission and the section requires neither damage nor dishonest intent. Their good motive negates the dishonesty section 66 requires and may influence whether the owner pursues the matter, but it does not make the access lawful.
- Why is hacktivism not a separate legal category, and why does it still matter to a defender?
Because the acts are the same offences under the Act and a political cause supplies no permission. It matters to a defender because it changes targeting: hacktivists select targets for symbolism and visibility, so an organisation may be attacked for what it represents rather than what it holds.
- Why should a script kiddie not be dismissed?
Because the tools they run were written by capable people and work regardless of the user's understanding. An unpatched system is compromised just as effectively by an unskilled attacker using a working exploit.
Hacker Classes, Hacktivism and the Types of Hacking
- Which class of attacker do most outward-facing defences miss, and what controls address them?
Insiders, who already hold legitimate access and whose activity resembles ordinary work; the negligent insider is the most common. They are addressed by least privilege, separation of duties, monitoring of privileged actions, and a reliable leavers process.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.