ELEN

Hacking Attacks

A successful intrusion also depends on the attack methods (hacking attacks) used by hackers. Some attack methods are the following:

Watch a video describing the most common cybercrimes:

– Sniffer: One method of attack used by hackers involves the use of so-called sniffers (“bloodhounds”). A sniffer is a small program that infiltrates a system undetected, where it searches and analyses its files in order to collect specific information, which it then transmits to its user.

– Denial of service (DoS attack): hackers run multiple programs with automated transmission of messages and commands which bombard the network with data, thereby overloading it so that it is unable to respond.

– Distributed denial of service (DDoS attack): Hackers, by using Trojan horses, gain control of many computers belonging to unsuspecting users. At a given moment, they coordinate all the computers to demand data and services from a specific system, which of course, after the excessive demand it faces, collapses.

– DNS Spoofing: In this case, the hacker modifies the Domain Name Code, which is the numerical, binary-digitised address of the site, so that the computer recognises it and responds to the command. Thus, users requesting a webpage with an altered numerical address will automatically be redirected to another webpage. This may mean a loss of revenue for the website that the user ultimately failed to visit, and also, by creating an exact copy of a webpage (mirror site), the hacker may extract sensitive personal data which the user believes he is providing to the genuine website he requested.

– Packet Sniffers for hacking attacks: these are essentially programs that allow the user to capture and interpret packets of information circulating on the internet. Every piece of information communicated on a computer network (username, login password, e-mail, etc.) is translated into packets, which are sent across the network. The Internet operates mainly with the Ethernet transmission protocol. So when someone sends a packet over Ethernet, every machine on the network sees the packet. Every packet sent over the internet has an Ethernet header/numerical address, to ensure that the correct machine receives the correct information. Each machine identifies the data packets bearing its own address. However, the Ethernet packet sniffer is software that allows the hacker or network administrator to intercept information that is not intended for its address.

– Trojan Horses (Trojans): These programs are backdoors into a computer system. The hacker disguises the Trojan as another program, such as a game, so that the user is deceived into downloading and installing the program. Once the Trojan is installed on the victim’s computer, the hacker gains access to the user’s hard drive or e-mail. By concealing programs to run later, the hacker can also gain access to other systems or carry out DDoS attacks. The simplest Trojan replaces the messages displayed when a password is requested from the user. Users provide their usernames and passwords believing that they are logging into the system, when in fact these are recorded by the Trojan for the hacker’s use.

– Viruses and Worms for hacking attacks: Worms and viruses are self-replicating programs that can spread on a wide scale across the internet. They usually lead to the destruction and malfunction of systems and files. Worms copy themselves from computer to computer without requiring the involvement of any other program or file.

FREQUENTLY ASKED QUESTIONS ABOUT HACKING ATTACKS

1. I am being charged with a hacking attack — what sentence am I facing?

Attack methods (sniffers, DoS/DDoS, DNS spoofing, Trojan horses, viruses, worms) typically fall under Articles 370B–370D of the Penal Code (PK) (unauthorized access to a system, breach of confidentiality, piracy) and Article 386A of the Penal Code (computer fraud), with sentences ranging from imprisonment (misdemeanor) to imprisonment (felony) where serious damage or organised activity is involved. In practice, the sentence may be substantially reduced through the recognition of mitigating circumstances (prior honest life, subsequent good conduct, Article 84 PK), suspension of sentence (Article 99 PK), conversion into a monetary penalty (Article 80 PK), or community service. The defence strategy depends on the legal characterisation of the act and the role attributed to the defendant.

2. How is it proved that I carried out the attack?

Identification of the perpetrator in hacking cases is based on IP addresses, provider logs, digital fingerprints on the computer, and analyses by the Cybercrime Prosecution Division. Many of these elements are open to challenge: an IP address may correspond to a network of multiple users, an unsecured wireless router, a VPN, or a computer that was itself infected by a Trojan horse and used as a “zombie” in a DDoS attack. Evidence collected unlawfully (without a prosecutorial order or in breach of communications confidentiality) is excluded from the case file and may overturn the charge. In case of doubt, the principle in dubio pro reo applies.

3. What should I do if I am summoned to the Cybercrime Prosecution Division?

From the very first moment, the presence of a lawyer is required, before any defense statement or testimony is given. The defendant has the right to silence and the right to have access to the case file before making a defense statement. It is advisable not to hand over passwords, devices, or remote access without legal guidance, nor to make spontaneous statements to police officers. If equipment is seized, a copy of the relevant report should be requested, and the sealing procedures (chain of custody) should be examined, as they often present deficiencies that can be exploited by the defence.

4. How long does criminal proceedings for hacking last?

Cybercrime cases are among the most time-consuming, due to the technical expert examination involved. From the criminal complaint to the preliminary investigation, several months may pass; the main investigation (where conducted) may last over a year, and the trial hearing often takes place two to four years after the act was committed. At second instance, a further one to two years are added. In certain cybercrime misdemeanors, the completion of the statute of limitations may also be examined, an element carefully considered by the defence.

5. What documents and evidence does the lawyer need?

The summons or indictment, the criminal complaint and the case file (after copies have been granted), any expert reports of the Cybercrime Division, the report on the seizure of electronic equipment, as well as technical evidence available to the defendant (logs, copies of devices, provider data, connection history, antivirus files) are gathered. Evidence of lawful use is also used (professional capacity, employment with a cybersecurity firm, lawful penetration tests under contract), which can rule out intent.

6. What is the role of the lawyer in hacking cases?

The defence in hacking attack cases requires a combination of criminal law and in-depth knowledge of digital technology. The firm examines the lawfulness of evidence collection, challenges the technical identification of the perpetrator, cooperates with digital forensic experts, raises standalone pleas for mitigating circumstances, and seeks the most lenient treatment (suspension, conversion, community service). At the same time, it represents the defendant at every stage — from the preliminary investigation and the defense statement to the trial hearing and legal remedies — with the aim of avoiding conviction or maximally reducing the consequences.