Sejarah Hacker — Dari MIT Tahun 1950-an hingga Era Modern
Sejarah lengkap budaya hacker dari Tech Model Railroad Club MIT (1950-an), phreaking telepon, era Unix, hacker etis, hingga dark web dan bug bounty modern.
From: LLM Wiki URL: llm-wiki.pages.dev/articles/sejarah-hacker Created: June 21, 2026 Updated: June 21, 2026 Read time: 33 min
Sejarah Hacker
“The best way to predict the future is to invent it.” — Alan Kay
Pendahuluan
Hacker adalah istilah yang memiliki makna ganda dalam sejarah teknologi. Awalnya bermakna positif — seseorang yang ahli dalam memahami dan mengeksplorasi sistem komputer, menyelesaikan masalah dengan cara kreatif. Seiring waktu, media massa menggunakan istilah ini untuk pelaku cybercrime (cracker), meskipun komunitas hacker sendiri membedakan keduanya.
Artikel ini menelusuri sejarah lengkap budaya hacker dari Tech Model Railroad Club MIT (1950-an), phreaking telepon, era Unix, hingga era modern bug bounty, CTF, dan AI security.
Era 1: Pra-Sejarah & MIT (1940-1960)
Istilah “Hack” Sebelum Komputer
- Hack (1880-an) — kata Inggris untuk “memotong” atau “mengepak”
- Mischief — kebrutalan muda
- Hatchet — kapak, memotong
- “Hack” di MIT — 1940-an — berarti “lelucon teknis”, “karya brilian”, “solusi kreatif”
- “I hacked it together” — “saya membuatnya dengan cara yang cepat dan cerdik”
TMRC — Tech Model Railroad Club (1946)
- 1946 — TMRC didirikan di MIT oleh kelompok mahasiswa teknik
- Fungsi — mendesain, membangun, dan mengoperasikan sistem kereta api model di MIT
- Kompleksitas — sistem persinyalan, switcher, waktu
- Akhir — pindah ke komputer (1960-an)
Budaya “Hack” TMRC
- Hacks — proyek luar biasa, “lelucon teknis”
- Whiz Kids — kelompok termuda
- Konsultasi — untuk semua hal teknis
- 1962 — “hacking” pindah ke komputer (TX-0, PDP-1)
TX-0 & PDP-1 (1958-1961)
- TX-0 (1958) — komputer pertama MIT, transistor
- PDP-1 (1961) — komputer DEC, lebih cepat
- Spacewar! (1962) — game komputer pertama, dibuat oleh Steve Russell dan tim TMRC
- AI Lab — tempat hacking MIT menjadi terkenal
- Richard Greenblatt, Bill Gosper, Tom Knight — hackers generasi pertama
Kode Etik (Kode Etik Hacker)
- Akses komputer harus unlimited dan total
- Semua informasi harus gratis
- Tidak percaya otoritas — decentralization
- Hacks harus dihargai dengan kualitas bukan latar belakang
- “Hands-on” — akses langsung ke sistem
Era 2: Hacker Komputer Awal (1960-1970)
ARPANET (1969)
- 1969 — ARPANET lahir — jaringan paket-switching pertama, cikal bakal Internet
- UCLA, SRI, UCSB, Utah — 4 node pertama (Oktober 1969)
- BBN — kontraktor, hardware
- Larry Roberts — arsitek
UNIX & C (1970-1971)
- 1970 — Ken Thompson (Bell Labs) membuat Unix dari Multics
- 1971 — Dennis Ritchie membuat bahasa C
- 1973 — Unix ditulis ulang dalam C — portability
- Unix philosophy — Do one thing and do it well
414 Gang (1982) — Hacker Pertama yang Ditangkap
- 414 Gang — kelompok hacker muda (usia 15-21) dari Milwaukee
- 1982-1983 — membobol 60+ komputer termasuk:
- Sloan-Kettering Cancer Center (New York)
- Los Alamos National Laboratory (New Mexico)
- Diancam penjatuhan bom nuklir
- Nama dari kode area 414 (Milwaukee)
- 1983 — FBI menangkap 9 orang
- Dihukum — ringan, masa depan di IT (?)
- 1983 — film War Games — meningkatkan paranoia
414s Setelah
- Neidorf — penulis Phrack Magazine
- Trey — kemudian bekerja di FBI
- Sarcee — keamanan kemudian
Tone Loc & Phreaking (1970-1980)
- Phreaking — hacking sistem telepon
- Blue box — alat untuk membuat panggilan gratis
- 2600 Hz — frekuensi tertentu untuk mengontrol telepon
- Captain Crunch (John Draper) — pelopor
- Loki & Woz — Steve Wozniak dan Steve Jobs menjual blue boxes
- Evan Doorbell (TAP) — komunitas phreaking
414 & War Games (1983)
- Film War Games (1983) — Michael Douglas, Matthew Broderick
- WOPR — komputer yang hampir memulai perang nuklir
- Film ini mempengaruhi pemerintah AS untuk membuat Computer Fraud and Abuse Act (1986)
- Buku “Cyberpunk” (Hafner & Markoff, 1991)
Homebrew Computer Club (1975)
- 1975 — Steve Wozniak & Steve Jobs di Palo Alto
- Kumpul mingguan — penggemar komputer
- Apple I (1976), Apple II (1977) — terkenal
- Budaya — berbagi, eksplorasi, do-it-yourself
Ai Wei Wei & YIPL/TAP (1971)
- YIPL (Youth International Party Line) — 1971
- TAP (Technical Assistance Program) — 1973
- Berkeley Barb — surat kabar underground
- Al Bell — pendiri
- Box — schematics untuk blue box, black box, dll
Era 3: Film Cyberpunk & Manifesto (1980-1990)
The Hacker Manifesto (1986)
- 8 Januari 1986 — dipublikasikan di Phrack #7
- The Mentor (Loyd Blankenship) — penulis
- Isi — “Hacker adalah orang yang mengeksplorasi… yang diminta untuk melakukannya oleh hack, bukan otoritas”
- Diterjemahkan ke banyak bahasa
- Manifesto paling penting budaya hacker
Kutipan Manifesto
“Hari ini saya membuat kesalahan. Saya dihukum.”
“Saya hacker… Saya adalah sebuah janji yang dibuat oleh orang.”
“Jelajahi, temukan, dan buatlah.”
— The Mentor, 1986
Movie War Games (1983)
- 1983 — film
- Matthew Broderick — David Lightman
- WOPR (War Operation Plan Response)
- Joshua — nama yang dipakai (Joshua Lockwood, anak LSSM)
- Pengaruh — peningkatan paranoia
- Senator Biden — membantu CFAA (1986)
Buku Steven Levy — Hackers (1984)
- Hackers: Heroes of the Computer Revolution (1984)
- 3 generasi hacker:
- Generasi 1 (MIT 1950-1960) — TMRC, AI Lab
- Generasi 2 (1970-an) — Homebrew, Apple, Altair
- Generasi 3 (1980-an) — game, BBS, Xanadu
- Kode Etik Hacker — didokumentasikan
Computer Fraud and Abuse Act (1986)
- CFAA — disahkan 1986
- 18 U.S. Code § 1030 — hukum federal AS
- Bentuk pelanggaran — akses tanpa izin
- Hukuman — hingga 20 tahun penjara
- Kontroversial — terlalu luas, digunakan berlebihan
The LEGION of DOOM (1990)
- LOD — kelompok hacker 1990-1994
- Chris Goggans (Erik Bloodaxe), Scott Chasin (Doc Holiday)
- Phiber Optik (Mark Abene) — dipenjara 1990
- Emmanuel Goldstein (Eric Corley) — pendiri 2600: The Hacker Quarterly
- Acid Phreak (James Bayhack)
- Pengaruh — BBS, ‘zine (zine), file sharing
2600: The Hacker Quarterly (1984-)
- 1984 — pertama kali diterbitkan
- Emmanuel Goldstein (Eric Corley) — pendiri
- Bell — AT&T bell sebagai logo
- Subtitle — “The Hacker Quarterly”
- Fokus — teknik, komunitas, berita
- Sekarang — masih aktif, online
Phrack Magazine (1985-)
- Phrack — ‘zine hacker
- 1985 — dipublikasikan
- Editor — Knight Lightning, Taran King, Erik Bloodaxe, Grim Mage
- Artikel — virus, telepon, jaringan
- CireM00n — komunitas
The Russian Hacker (1990-1995)
- Boris Floricic (1990) — CCC (Chaos Computer Club) Jerman
- Stasi — bisa di-hack
- KLH — DeCSS, DVD cracking (1999)
- “Beigewagen” — buku 1994
8LGM (8-Light-Group)
- 8LGM — kelompok hacker tahun 1990
- Mad hacker — ‘hack the planet’ slogan
- Chad Davis (Jarkko Oikarinen)
- W3C — Web standards
- Pengaruh — World Wide Web
Chaos Computer Club (CCC, 1981-)
- 1981 — Berlin, Jerman
- Chaos Knoten — jurnal hacker
- Aktivis — kebebasan informasi
- Wau Holland (1981) — founder
- Pentesting — konsep formal
YIPL → TAP → 2600
- YIPL (1971) — Youth International Party Line
- TAP (1973) — Technical Assistance Program
- 2600 (1984) — majalah hacker
Era 4: Jaringan & Internet (1990-2000)
Internet Komersial (1990-1995)
- 1990 — World Wide Web (Tim Berners-Lee, CERN)
- 1993 — Mosaic browser (NCSA)
- 1995 — Internet Explorer, Netscape
- 1996 — ISDN, modem 56k
- 1998 — Google Search
L0pht Heavy Industries (1992)
- L0pht — hackerspace Boston
- 1992-2000 — aktif
- Anggota — Mudge, Kingpin, Weld Pond, dll
- 1998 — L0pht di depan Kongres AS — “kami bisa mematikan internet dalam 30 menit”
- Mudge (Peiter Zatko) — kemudian Google, Pentagon, Twitter
- 2000 — dibeli @stake
- Warisan — bug bounty, vulnerability disclosure
Master of Deception (MoD, 1991-1995)
- MoD — kelompok hacker New York
- Phiber Optik — sebelumnya LOD
- Acid Phreak, Scorpion, Blue Adak — anggota
- L0pht rival
- 1992 — perang hack dengan LOD
- 1995 — menangkap 3 anggota
1990 — Cyber Wars
- Operation Sundevil (1990) — Secret Service AS menggerebek LOD
- Steve Jackson Games — game cyberpunk digerebek
- EFF (Electronic Frontier Foundation) — didirikan 1990
- John Perry Barlow, Mitch Kapor — pendiri
- Mikael Kapor — pendiri Lotus
- Lembaga — kebebasan digital
Electronic Frontier Foundation (1990-)
- 1990 — didirikan
- Mark Pesce — co-founder
- John Perry Barlow — “Declaration of the Independence of Cyberspace” (1996)
- Mikael Kapor, John Gilmore
- Bekerja — kebebasan digital
- Kasus — United States v. Craig — membela
- Matt Blaze — EFF Prize
- Aktivis — open source, privasi, transparansi
Operation Eligible Receiver (1997)
- 1997 — simulasi cyber attack oleh NSA ke Pentagon
- Target — militer AS
- Tujuan — menguji kerentanan
- Hasil — berhasil meretas banyak sistem
AOL Hacks (1998-2000)
- AOL — America Online
- 1998 — CD gratis dikirim ke banyak orang
- Phishing — nama samaran
- Hacks — beberapa kasus
ILOVEYOU Worm (2000)
- 4 Mei 2000 — worm di email
- “I LOVE YOU” — subject email
- Penulis — Onel de Guzman, Filipina
- Dampak — 10 juta PC, 5-10 miliar dolar
- Tidak dihukum — Filipina tidak punya hukum
- Dampak — memperkuat cyberlaw di banyak negara
Mafiaboy (2000)
- 15 Februari 2000 — DDoS attack
- Target — Yahoo!, eBay, CNN, Amazon, Dell
- Dampak — kerugian $1.7 miliar
- Penangkap — Michael Calce (Mafiaboy), 15 tahun
- Kanada — divonis 8 bulan
- Sekarang — bekerja di keamanan siber
Era 5: Era LulzSec, Anonymous, dan WikiLeaks (2010-2015)
Anonymous (2003-)
- 2003 — Imageboard 4chan
- Topeng Guy Fawkes — simbol (V for Vendetta)
- Tujuan — kebebasan, anti sensor
- 2008 — Project Chanology (Scientology)
- 2010-2012 — dukungan WikiLeaks
- #OpPayback (2010) — DDoS Mastercard, Visa, PayPal
- #OpTunisia (2011) — revolusi Tunisia
- Anon — kolektif
- Ciri — tidak ada pemimpin
Project Chanology (2008)
- Januari 2008 — DDoS Church of Scientology
- Video — Tom Cruise (leaked, viral)
- Anonymous — pilih target
- Protes jalanan — di seluruh dunia
- The Message — viral YouTube
WikiLeaks (2006-)
- 2006 — didirikan
- Julian Assange — pendiri
- 2010 — Collateral Murder (video militer AS)
- 2010 — Afghan War Diary
- 2010 — Cablegate
- Chelsea Manning — sumber
- Bradley Manning — nama lahir
- 2013 — Edward Snowden → Rusia
- Asylum — Ekuador (2012-2017), London (2017-)
- Vault 7 (2017) — CIA hacking tools
- Cryptocurrency — donasi
LulzSec (2011)
- Mei 2011 — kelompok hacker muncul
- Sabu, Kayla, Topiary, Pwnsauce, tflow, avunit
- Target — PBS, Sony Pictures, CIA, FBI, Arizona DPS
- “Lulz” — tawa
- Sabu (Hector Xavier Monsegur) — nara sumber
- Ditangkap — Juni-Agustus 2011
- Kayla (Ryan Ackroyd) — divonis 30 bulan
AntiSec (2011-2013)
- LulzSec + Anonymous — Anti Security
- Hacking Team (Italia) — diretas 2015
- HBO — Game of Thrones bocor
- Stratfor — diretas 2011 (Anonymous)
- “Operation Anti-Security” — Manifesto
Edward Snowden (2013)
- 2013 — Snowden bocor dokumen NSA
- “PRISM” — program surveillance
- “XKeyscore” — alat analitik
- Guardian, Washington Post — media
- Snowden — Rusia (asylum)
- Permanent record — buku 2019
- Apple, Google — desakan enkripsi
- Akhirnya — memperkuat gerakan privasi
Heartbleed (2014)
- April 2014 — bug di OpenSSL
- CVE-2014-0160 — buffer over-read
- 17% dari server internet — rentan
- 2 tahun — tersembunyi
- Codenomicon — ditemukan
- Google Security — ditemukan terpisah
- Memperkuat — bug bounty
Target (2013)
- November-Desember 2013 — retas Target
- 70 juta kartu kredit
- “BlackPOS” — malware
- Kehilangan — $200 juta
- CEO Gregg Steinhafel — mundur
Sony Pictures (2014)
- 2014 — “Guardians of Peace” attack
- 100+ terabytes bocor
- Film — belum tayang dibocor
- Aktor — informasi gaji, email
- FBI — tuding Korea Utara
- “The Interview” — film tentang Kim Jong-un
Ashley Madison (2015)
- Juli 2015 — diretas
- Avid Life Media — dimiliki
- 37 juta user — data dibocor
- “Impact Team” — grup
- “Mal hari” — beberapa bunuh diri
- $1.7 miliar — kerugian
- Tagline — “Life is Short. Have an Affair.”
Era 6: Deep Web, Cryptocurrency, dan Nation State (2015-2020)
Dark Web
- Tor Network — anonymous browsing
- 2002-2004 — Tor dikembangkan
- 2008-2010 — Firefox + Tor bundle
- Hidden Service (.onion) — server tersembunyi
- 2011 — Silk Road (Ross Ulbricht, Dread Pirate Roberts)
- 2013 — FBI menutup Silk Road
- 2013 — 2.0 (sebelum tutup)
- Hudud — banyak
- FPN Forum — fraud
- Hansa — Belanda
- AlphaBay — pengguna besar
Silk Road (2011-2013)
- 2011 — Ross Ulbricht (DPR — Dread Pirate Roberts)
- 2013 — ditangkap
- Hukuman — seumur hidup (2 kali)
- Passport — “Dread Pirate Roberts”
- Bitcoin — digunakan
- “DPR” — karakter
Mt. Gox (2014)
- Februari 2014 — diretas
- $450 juta Bitcoin — hilang
- Penutupan — Mt. Gox
- Mark Karpeles — CEO
- Paling terkenal — hack bitcoin
Bitfinex Hack (2016)
- Agustus 2016 — retas
- 120.000 BTC — hilang
- $72 juta saat itu
- Ilya Lichtenstein & Heather Morgan — ditangkap 2022
- “Razzlekahn” — alias Morgan
- “Defiant Damsel” — Lichtenstein
DAO Hack (2016)
- 17 Juni 2016 — The DAO diretas
- $50 juta — ETH dicuri
- Hard fork — Ethereum pecah jadi 2
- Ethereum (ETH) — tetap
- Ethereum Classic (ETC) — tidak ada fork
WannaCry (2017)
- 12 Mei 2017 — ransomware
- 230.000+ komputer — di 150 negara
- $4-8 miliar — kerugian
- EternalBlue — exploit NSA
- Shadow Brokers — kelompok
- Marcus Hutchins — “MalwareTech” — temukan kill switch
- 23 tahun — Inggris
- Lazarus Group — Korea Utara (FBI tuding)
NotPetya (2017)
- Juni 2017 — wiper malware
- Ukraina — target pertama
- $10 miliar — kerugian
- Maersk, Merck, FedEx, dll — diretas
- GRU — Rusia (tuding)
- Sandworm Team — Rusia
- Not ransomware — wiper (hapus data)
Colonial Pipeline (2021)
- Mei 2021 — ransomware DarkSide
- $4.4 juta — tebusan
- Penutupan — pipa AS
- BBM — kelangkaan
- FBI — pulihkan sebagian bitcoin
SolarWinds (2020)
- 2020 — supply chain attack
- SolarWinds Orion — software update
- 18.000+ organisasi — diretas
- Microsoft, Pentagon — juga
- APT 29 / Cozy Bear — Rusia
- 9 bulan — tidak terdeteksi
SolarWinds (lanjutan)
- Konfirmasi oleh Microsoft (12/2020)
- Dampak — government, Fortune 500
- Kritik — kelalaian keamanan
- Joe Biden — “hacking war”
- $100 miliar — estimasi kerugian
Russia & Ukraine Cyber War (2014-)
- 2014 — Crime annexation
- 2015 — BlackEnergy di Ukrainian power grid
- 2016 — Industroyer Crash Override
- 2022 — perang penuh
- Sandworm Team — GRU (Rusia)
- Wiper malware — HermeticWiper, FoxBlade, dll
- IT Army of Ukraine — volunteer
North Korea Crypto Theft (2017-)
- Lazarus Group (KPA)
- 2017-2024 — $3 miliar+ dalam crypto
- 2017 — WannaCry
- 2022 — Ronin Network ($625M)
- 2023 — Harmony Bridge ($100M)
- 2024 — WazirX ($235M)
- 2025 — Bybit ($1.5 miliar — terbesar)
Ransomware Era (2019-)
- Maze (2019) — “double extortion”
- REvil (Sodinokibi) — 2021
- DarkSide (Colonial Pipeline)
- Conti — 2021-2022
- LockBit — 2022-2024 — grup terbesar
- BlackCat/ALPHV — 2023-2024
- Cl0p (MOVEit) — 2023
- Ransomware-as-a-Service (RaaS) — model bisnis
Era 7: Modern (2020-2026)
SolarWinds (lanjutan, déjà vu)
- 2020-2024 — beberapa large-scale supply chain
- Log4j (2021) — bug di Java logging
- Polyfill.io (2024) — supply chain JavaScript
- xz Utils (2024) — backdoor di tool Linux
Log4Shell (Desember 2021)
- CVE-2021-44228 — bug di Log4j
- Kritikalitas — 10.0/10
- “Log me” — eksploitasi sederhana
- Apple, Amazon, IBM, dll — rentan
- Chen Zhaojun (Alibaba) — temukan
MOVEit Transfer (2023)
- Mei 2023 — Cl0p ransomware
- MOVEit — file transfer
- 2.500+ organisasi — rentan
- BBC, Shell, American Airlines — rusak
- $10 miliar — kerugian
Microsoft Storm-0558 (2023)
- Juli 2023 — token signing key dicuri
- Outlook.com, Microsoft 365 — disusupi
- China — dituding
- Mitigation — ganti key
MOVEit & GoAnywhere (2023-2024)
- Cl0p — ransomware dengan zero-day
- Banyak korban — bisnis besar
- Kurangnya — patch lambat
23andMe (2023)
- Oktober 2023 — data breach
- 6.9 juta user — diretas
- Info genetik — dipublikasikan
- “Gedmatch” — terkait
- Reconnaissance attack — credential stuffing
CrowdStrike Outage (2024)
- 19 Juli 2024 — 8.5 juta Windows
- Bug di update — Falcon Sensor
- $5.4 miliar — kerugian (?)
- Maskapai, bank, RS — terganggu
XZ Utils Backdoor (2024)
- Mei 2024 — backdoor ditemukan
- Andres Freund (Microsoft) — temukan
- Jia Tan (Jia Cheong Tan) — backdoor maker
- CVE-2024-3094 — kerentanan
- Supply chain attack — hampir seperti SolarWinds
- 2 tahun — ditanam
Era 8: AI Security (2024-2026)
AI sebagai Senjata dan Pertahanan
- 2024-2025 — era AI security
- AI untuk offensive — phishing otomatis, deepfake
- AI untuk defensive — deteksi ancaman
- AI red team — Microsoft, Google, OpenAI
- AI untuk vulnerability detection — GitHub Copilot, Snyk
LLM & Phishing
- Generative AI — phishing yang convincing
- Deepfake suara — CEO voice scam
- CEO $243M Deepfake (2024) — Arup engineering
- Multimodal — gambar, audio, video
- $1+ miliar kerugian — AI scams
AI Jailbreaks
- DAN (Do Anything Now) — jailbreak ChatGPT
- Prompt injection — risiko
- Jailbreak dalam 1-2 bulan — setiap model baru
- Red teaming — penting
- OpenAI, Anthropic, Google — semua diretas
North Korea Crypto (2025)
- 21 Februari 2025 — Bybit diretas
- $1.5 miliar — ETH dicuri (terbesar)
- Lazarus Group — tuding
- Safe{Wallet} — disusupi
Ransomware Modern (2025-2026)
- AI-generated ransomware — GPT-4, Claude
- LockBit 4.0 (2024) — bangkit lagi
- Ransomware-as-a-Service — mature
- Average payment — $200K-$1M
- FBI IC3 Report 2024 — $12.5 miliar kerugian
HackerSpaces (2007-)
- Hacker Dojo (Mountain View, 2009)
- NYC Resistor (Brooklyn, 2007)
- Noisebridge (San Francisco, 2007)
- HacDC (Washington DC, 2007)
- “Hack”-oriented — electronics, programming
- “Make” movement — DIY
- 300+ hackerspaces global
DEF CON (1993-)
- 1993 — pertama
- Las Vegas — setiap tahun
- The Dark Tangent (Jeff Moss) — pendiri
- 15.000+ hackers — pertemuan
- Hardware Hacking Village — populer
- DEF CON 31 (2023) — rekor
- Vendor Village — sponsor
Black Hat (1997-)
- 1997 — DEF CON terpisah
- Las Vegas — setiap tahun
- Defcon vs Black Hat — DEF CON lebih underground
- Black Hat Briefings — teknis
- Briefings + Trainings — edukasi
Chaos Communication Camp (2003-)
- CCC — Jerman
- Tiap 4 tahun (?)
- Lectures, Workshops — teknis
- “Security, Hacker, Nerd” — etos
HOPE (Hackers on Planet Earth, 1994-)
- 2600 Magazine — sponsor
- Tiap 2-3 tahun — New York
- Speaker — kelas dunia
- HOPE XI (2016) — besar
DEF CON vs HOPE vs CCC
- DEF CON — Vegas, USA
- HOPE — NYC, USA
- CCC — Hamburg, Jerman
- DEF CON — paling banyak peserta
- CCC — paling elit
White, Gray, Black Hat Hacker
White Hat (Etis)
- Definisi — hacker yang beretika, membantu organisasi
- Kode — tidak merusak, hanya untuk pertahanan
- Bug Bounty — model kerja
- Contoh — Kevin Mitnick (setelah), Dan Kaminsky
Gray Hat (Abu-abu)
- Definisi — antara white dan black
- Menembus — tanpa izin, tapi melaporkan
- Motif — kadang publisitas, kadang uang
- Contoh — beberapa peretas telepon 1970-an
Black Hat (Jahat)
- Definisi — cracker, motif jahat
- Aktivitas — malware, ransomware, data breach
- Hukum — dipenjara
- Contoh — Mafiaboy, Mafiaboy, dll
Hacktivist (Aktivis)
- Definisi — hacker untuk tujuan politik/sosial
- Contoh — Anonymous, WikiLeaks
- Metode — DDoS, deface, leak
Etika Hacker
Kode Etik Hacker (Levy, 1984)
- Akses komputer harus unlimited dan total
- Semua informasi harus gratis
- Tidak percaya otoritas — decentralization
- Hacks dihargai dengan kualitas, bukan latar belakang
- “Hands-on” — akses langsung
Christiania Hacker (Modern)
- Open source — source code terbuka
- Bug bounty — menemukan bug, dapat hadiah
- Responsible disclosure — laporkan dengan bertanggung jawab
- Patching — perusahaan harus perbaiki
Gray Areas
- Penetration testing — tanpa izin, tapi atas permintaan
- Bug bounty — sah
- “Hacktivism” — kadang ilegal
- IoT hacking — keamanan publik
Subkultur & Komunitas
BBS (Bulletin Board Systems)
- 1978 — Ward Christensen (CBBS)
- 1990-an — ribuan BBS
- Door games — Trade Wars, LORD
- “Leased lines” — long distance
- Diubah oleh — Internet
4chan (2003-)
- 2003 — didirikan Christopher “moot” Poole
- /b/ — random
- Anonymous — gerakan
Reddit
- 2005 — Steve Huffman & Alexis Ohanian
- /r/netsec — network security
- /r/privacy — privasi
- /r/ReverseEngineering — RE
- /r/Malware — diskusi malware
Hackerspaces (lebih dari 1.000 global)
- Makerspace — fokus pada hardware
- Hackerspace — fokus pada software
- Biohacking — biologi
- Lockpicking — keamanan fisik
- CryptoParty — kriptografi
- XMPP, Mumble, Discord — komunikasi
Jenis Hacker Spesialisasi
1. White Hat Hacker (Etis)
- Penetration Tester — menyewa untuk uji sistem
- Bug Bounty Hunter — temukan bug, dapat hadiah
- Security Researcher — publikasi, presentasi
- Reverse Engineer — analisis malware
- Forensik Digital — investigasi
2. Black Hat Hacker (Jahat)
- Malware Developer — virus, ransomware
- Phisher — social engineering
- Botnet Operator — jaringan bot
- Data Trader — jual data di dark web
- Cryptojacker — mining ilegal
- Carder — kartu kredit
3. Gray Hat Hacker
- Vulnerability Disclosure — temukan, publik
- Hacktivist — tujuan politik
- White Hat Bounty Hunter — dapat hadiah
- Penetration Tester — disewa
4. Script Kiddie
- Definisi — menggunakan tool orang lain, tanpa paham
- Skill — rendah
- Motif — vandalisme, perhatian
- Tool — Metasploit, sqlmap, Burp Suite, Kali Linux
5. Phisher / Social Engineer
- Target — manusia
- Metode — email, telepon, SMS
- ROI — tinggi
- AI — semakin convincing
6. Insider Threat
- Karyawan — saat ini/kelak
- Akses — sudah ada
- Deteksi — sulit
- Edward Snowden — contoh
7. Nation State
- APT (Advanced Persistent Threat)
- APT 28 (Fancy Bear) — Rusia
- APT 29 (Cozy Bear) — Rusia
- APT 1 (Comment Crew) — China
- Lazarus Group — Korea Utara
- Muddy Water — Iran
- Equation Group — AS (?)
- Kimsuky — Korea Utara
8. Hacktivist
- Anonymous — kolektif
- LulzSec — grup
- WikiLeaks — publish
- Misi — kebebasan, transparansi, anti-korupsi
9. Red Team / Blue Team
- Red Team — menyerang (simulasi)
- Blue Team — bertahan
- Purple Team — kolaboratif
- CTF — latihan
10. Bug Bounty Hunter
- Platform — HackerOne, Bugcrowd, Intigriti
- Reward — $100-$1M+
- Top hunters — earn $1M+ per tahun
- PicoCtf, Google VRP, Apple SRD
Komunitas & Konferensi
DEF CON
- 1993 — Las Vegas
- 15.000+ hackers
- Topics — semua
- Villages — banyak (Hardware, Wireless, dll)
- August — setiap tahun
- “The Dark Tangent” — Jeff Moss
Black Hat Briefings
- 1997 — Las Vegas
- Black Hat USA, EU, Asia
- Trainings — 2-3 hari
- Briefings — presentasi
- Topi hitam — profesional
DEF CON vs Black Hat
- Black Hat — lebih “resmi”
- DEF CON — lebih underground
- Beda — budaya, tiket
- Bisa — pergi ke keduanya
Chaos Communication Camp (CCC)
- 2003 — Hamburg, Jerman
- Tiap 4 tahun (?)
- Lecture, Workshop, Village
- Hackcenter, C-base
- Currywurst — penting
2600 Meetings
- Setiap bulan — first Friday
- New York City — kantor 2600
- Seluruh dunia — 100+ chapter
Local Hackathons
- Hackathon — sprint coding 24-48 jam
- MLH (Major League Hacking) — student
- Startup Weekend — 54 jam
- NASA Space Apps — global
- Devpost — platform
ToorCon
- 1999 — San Diego
- West Coast — hacker
- “Toor” — Java reverse engineering
- “Toorcon” — Arctan Group
LayerOne
- 2010 — California
- Komunitas — hacking
DEF CON China
- 2013 — Beijing (?)
- Komunitas — China hacking
- YoC — tahun ini
DEF CON India (2018-)
- 2018 — DEF CON India
- Komunitas — India
Hack in the Box (HITB)
- 2003 — Malaysia
- HackInTheBox — Amsterdam, Dubai
- CFP, training
BruCON
- Belgia — Belgia
- Topi Putih — hacking profesional
Troopers (Jerman)
- Telco — keamanan telekomunikasi
- Enterprise — bisnis
Nullcon
NorthSec
- Kanada — Quebec
- Capture the Flag (CTF)
- Topi Putih — keamanan
DefCamp (Romania)
- 2011 — Bucharest
- BSS, BBA — Bucharest
- Bounty Programs
Pacific Rim (PHDays)
- Moskow — Rusia
- Positive Technologies
Sejarah Bug Bounty
Asal Usul
- 1995 — Netscape Communication Corporation
- Netscape — bug-bounty
- “Bounty” — software bug
- 1,000$ — hadiah per-bug
Modern Bug Bounty (2010-)
- 2010 — Google Vulnerability Reward Program
- 2012 — Facebook Bug Bounty
- 2013 — Microsoft Bug Bounty
- 2015 — HackerOne didirikan
- 2016 — Bugcrowd didirikan
HackerOne (2012-)
- 2012 — San Francisco
- Mårten Mickos — CEO
- Alex Rice, Jobert Abma, Michiel Prins — pendiri
- 1.000.000+ bug dikirim
- $300M+ total bounty
- $1M+ — top earners
- Pentagon, Microsoft, Google, Apple, Toyota — program
Top Earners (Bug Bounty)
- $1M+/tahun — beberapa
- HackerOne — top 50+ earn $100K+/tahun
- Top countries — AS, India, Indonesia, China, Brazil
Top 10 Bug Bounty Programs (2024)
- Microsoft — $80,000+ per bug
- Google — $1M+ for critical
- Apple — $1M+
- Meta (Facebook, Instagram, WhatsApp) — $40K+
- Apple Security Bounty — $1M for Lockdown Mode bypass
Sejarah Capture the Flag (CTF)
Asal
- 1993 — DEF CON CTF (pertama)
- Kelvin — kelompok
- “Capture the Flag” — permainan keamanan
- Jeopardy style — challenge-based
- Attack-Defense — defend while attacking
- King of the Hill — pertahankan
DEF CON CTF
- DEF CON 1 (1993) — dimulai
- 2014 — dari “ctf” (kelompok legendaris) ke “Order of the Overflow”
- 2017 — serangan vendor besar (legendaris)
Top CTF Tim
- PPP (Plaid Parliament of Pwning) — CMU
- Shellphish — UCSB
- H4x0r — Berlin
- Binja — Pittsburgh
- Eindbazen — Belanda
CTF Time
- 2011 — platform ranking global
- Per tahun — top teams
- CTF kompetitif — dengan hadiah
CTF Lokal
- Indonesia — COMFEST, IDC, Cyber Jawara
- Hindia — HackerRank, Leetcode
- Global — Google CTF, Facebook CTF, picoCTF
- Asia — HITB, NUS
Scanning & Recon
- Nmap (1997-) — Fyodor Vaskovich
- Masscan — Robert David Graham
- ZMap — University of Michigan
Vulnerability Scanning
- Nessus (1998) — Renaud Deraison
- OpenVAS (Open Vulnerability Assessment System)
- Nuclei — ProjectDiscovery
- Nikto (Perl, 2001)
Exploitation
- Metasploit (2003-) — HD Moore
- Cobalt Strike — Raphael Mudge
- Empire (Python)
- BeEF (Browser Exploitation Framework)
- SQLmap (Miroslav Stampar)
Sniffing
- Wireshark (1998-) — Gerald Combs
- tcpdump — Van Jacobson
- Burp Suite (2004-) — Dafydd Stuttard
- mitmproxy
Password Cracking
- John the Ripper (1996-) — Solar Designer
- Hashcat (2009-) — atom (Jens Steube)
- Hydra (THC-Hydra)
Wireless
- Aircrack-ng (2006-)
- Wifite — Reaver, WPS
- Kismet — Mike Kershaw
- Wireshark (juga wireless)
OSINT
- Maltego (Paterva)
- Shodan (John Matherly)
- theHarvester — Christian Martorella
- Recon-ng
Web
- Burp Suite (2004-)
- OWASP ZAP (2010-)
- Nuclei (2019-)
- sqlmap
- XSStrike
Reverse Engineering
- Ghidra (2019) — NSA, gratis
- IDA Pro (1991-) — Hex-Rays, komersial
- Ghidra vs IDA — Ghidra gratis
- Binary Ninja — Vector 35
- x64dbg (Windows debugger)
- GDB (GNU Debugger)
Mobile
- Frida (dynamic instrumentation)
- Objection (Frida wrapper)
- MobSF (Mobile Security Framework)
- apktool (Android)
- class-dump (iOS)
Web App
- Burp Suite
- ZAP
- ffuf (web fuzzer)
- wpscan (WordPress)
- joomscan (Joomla)
Distro Linux Pentest
Kali Linux (2013-)
- Mati Aharoni, Devon Kearns, Raphael Hertzog — Offensive Security
- BackTrack — versi sebelumnya
- 600+ tool — built-in
- Terbaik — umum, beginner-friendly
- Rolling release — update konstan
Parrot Security OS (2013-)
- Frozenbox — developer
- Ringan — lebih ringan dari Kali
- AnonSurf — built-in
- MATE Desktop — default
BlackArch (2013-)
- Arch-based
- 2000+ tool — sangat banyak
- Rolling release
- Untuk profesional — advanced
Wifislax (2004-)
- Wireless — khusus
- Pengganti — Wifiway
- Untuk — pentest WiFi
Pentoo (2005-)
SamuraiWTF (2012-)
- Web pentest — fokus
- Web Application Testing Framework
DEFT (2010-)
- Digital Evidence & Forensic Toolkit
- Digital Forensics
Caine (2008-)
Bahasa Pemrograman Hacker
Assembly (x86, x64, ARM)
- x86 — Intel, AMD
- ARM — smartphone, IoT
- RISC-V — open source
C dan C++
- C — bahasa sistem
- C++ — OOP untuk sistem
- Kernel — ditulis dalam C
Python
- Sintaks — sederhana
- Library — besar
- Exploit development — pwntools
- Automation — scripting
- AI/ML — modern
JavaScript
- Web — client & server
- XSS, CSRF — vektor
- Node.js — server
- Bug Bounty — populer
SQL
- Database — hampir semua
- SQL injection — serangan klasik
- SQLite, MySQL, PostgreSQL, MSSQL — semua
Bash / Shell
- Linux — automation
- Scripting — powerful
- Reverse shell — exploit
Ruby
- Metasploit — ditulis dalam Ruby
- Rails — web
Go
- Modern — cepat
- Malware — semakin banyak
- C2 (Cobalt Strike clone)
Rust
- Memory safe — penting untuk security
- Linux kernel — Rust 2nd language
Network
- Wireshark — packet analysis
- Nmap — port scanning
- Aircrack-ng — WiFi
Web
- Burp Suite — web proxy
- OWASP ZAP — alternatif Burp
- sqlmap — SQL injection
- Nuclei — vulnerability scanner
OSINT
- Shodan — IoT search engine
- Censys — Internet scan
- Maltego — OSINT
- theHarvester — email/subdomain
Reverse Engineering
- Ghidra — NSA, gratis
- IDA Pro — commercial
- x64dbg — Windows
- GDB — Linux
Mobile
- MobSF — Mobile Security Framework
- Frida — dynamic instrumentation
- apktool — Android decompile
Exploitation
- Metasploit — exploit framework
- Cobalt Strike — commercial
- Searchsploit — exploit-db search
Defense
- OSSEC (HIDS)
- Snort (IDS)
- Suricata (IDS)
- Wazuh (modern HIDS)
- Splunk — enterprise
- ELK Stack — Elasticsearch, Logstash, Kibana
- Wazuh — open source
- IBM QRadar — enterprise
- Microsoft Sentinel — cloud
Bahasa untuk Hacker Pemula
Python (Recommended)
- Mudah dipelajari
- Library — banyak
- pwntools, requests, scapy — hacking tools
- AI/ML — modern
- Fungsi — automasi, exploit
C
- Memori — langsung
- Buffer overflow — penting
- Kernel — Linux
- Sistem — embedded
JavaScript
- Web — hampir semua situs
- Node.js — server
- Bug Bounty — populer
- Browser — XSS, CSRF
Bash
- Linux — automation
- CTF — flag hunting
- Tool integration — pipe, xargs, sed
SQL
- Database — standar
- SQL injection — perlu dipahami
- CTF — banyak challenge
Bahasa Etis Hacker
Penetration Testing Steps
- Reconnaissance — kumpulkan info
- Scanning — Nmap, OpenVAS
- Vulnerability Analysis — Nessus
- Exploitation — Metasploit
- Post-Exploitation — pivot
- Reporting — dokumentasi
- Kali Linux — distribusi
- Metasploit — exploit
- Nmap — scanning
- Burp Suite — web
Laporan
- Executive Summary
- Technical Findings
- Reproduction Steps
- Recommendations
- Severity — CVSS
Komunitas & Forum
Online
- Reddit — /r/netsec, /r/hacking, /r/ReverseEngineering
- Stack Exchange — Security, IT
- HackerOne Hacktivity — disclosed reports
- Bugcrowd Crowdstream — disclosed reports
- Twitter — security researchers
- Mastodon — infosec.exchange
Forum Lokal
- Indonesian — IDC, Hacker Indonesia, dll
- Malaysia — Hack In The Box
- Singapura — DEF CON Singapore
- Thailand — IDC ASEAN
Wiki
- OWASP — web security
- CWE — common weakness
- CVE — common vulnerabilities
- ATT&CK — MITRE
- CAPEC — attack patterns
Hacker & Hukum
Computer Fraud and Abuse Act (1986)
- 18 U.S. Code § 1030 — federal AS
- Akses tanpa izin — federal crime
- Hukuman — 5-20 tahun
- Snowden, Mafiaboy, Sabu — dikenai
Computer Misuse Act (UK, 1990)
- UK — setelah Guildford Four
- 3 pasal utama:
- 1 — akses tidak sah
- 2 — akses dengan maksud merusak
- 3 — modifikasi tidak sah
UU ITE (Indonesia, 2008)
- Undang-Undang Informasi dan Transaksi Elektronik
- Pasal 30-37 — cybercrime
- Hukuman — 6-12 tahun
- Kontroversial — Pasal 27 (penghinaan, pencemaran nama baik)
CFAA & Hukuman
- Van Buren (2021) — Supreme Court batasi CFAA
- Aaron Swartz (2011-2013) — bunuh diri setelah didakwa
- Meredith L. Patterson — bunuh diri setelah didakwa
Peretas Penting yang Dihukum
- Kevin Mitnick (1995) — 5 tahun
- Mafiaboy (2000) — 8 bulan
- Sabu/LulzSec (2011) — 1 tahun + 5 tahun kurungan rumah
- Chelsea Manning (2010) — 35 tahun (commuted)
- Aaron Swartz (2011) — bunuh diri
- Reality Winner (2017) — 5 tahun + 3 masa pengawasan
- Joshua Schulte (Vault 7) — 40 tahun
- Marcus Hutchins (Kronos) — waktu dilayani
Hacker yang Berakhir Bagus
Kevin Mitnick
- Awal — Black Hat (penjara 5 tahun)
- Setelah — White Hat, penulis, konsultan
- Waktu — 2 tahun parlemen
- Buku — The Art of Deception (2002)
- “Ghost in the Wires” (2011)
- Meninggal 2023
Chelsea Manning
- Awal — 35 tahun
- Setelah — commuted (2017)
- Sekarang — aktivis, security engineer
Marcus Hutchins (MalwareTech)
- Awal — penulis Kronos (2014-2015)
- Setelah — 1 tahun kurungan rumah
- WannaCry (2017) — temukan kill switch
- Sekarang — content creator security
Adrian Lamo (1950-2018)
- Awal — Manning, NYTimes, Yahoo!, dll
- “Homeless Hacker” — berkeliaran
- Bipolar — akhir hayat
- Bunuh diri (2018)
Kaitlyn Siracuse (Pompompurin)
- “pompompurin” — administrator RaidForums
- Arrest — 2022
- 21 tahun — FBI raid
- “Hack the planet” — slogan
Hector Xavier Monsegur (Sabu)
- LulzSec — 2011
- FBI informant — 1 tahun
- Sekarang — keamanan, bug bounty
- Twitter — “@anonymouSabu”
Hacker Ikonik
Phineas Fisher (2014-)
- Gamma Group (2014) — Inggris
- Hacking Team (2015) — Italia
- “HackBack” — manifesto
- Anonim — tidak pernah tertangkap
- Symbol — hacktivisme
Pwnie Express, Radare2
- pwnie — panics, vulnerabilities
- radare2 — RE framework
Crypto AG (2020)
- Operasi Rubicon — Thyrus (Swiss)
- CIA, BND — operasi tersembunyi
- Min G. WikiLeaks — dokumen
LulzSec (2011) — sudah dibahas
Komputer sebagai Alat Sosial
Critical Engineering Manifesto
- Critical Engineering Working Group
- 2011 — manifesto
- “The Strangest People as the Centre” — hacker
- Sensor, Data, Network — kritik
Crypto Wars (1990-an)
- Clipper Chip — pemerintah AS
- 1993 — White House Clipper
- Matt Blaze (AT&T) — temukan kelemahan
- Phil Zimmermann — PGP
- EFF — legal battle
PGP (Pretty Good Privacy)
- 1991 — Philip Zimmermann
- Email encryption — pertama
- Investigasi — pemerintah AS
- PGP — open source, 1997
- OpenPGP — standar
Snowden & Privacy (2013-)
- NSA Prism — Snowden bocor
- Apple, Google — akhirnya encryption
- Signal — приложения pesan
- Tor — anonymous browsing
- End-to-end encryption — standar
Sumber & Referensi
Buku Penting
- Hackers: Heroes of the Computer Revolution (Steven Levy, 1984)
- The Cuckoo’s Egg (Cliff Stoll, 1989)
- Cyberpunk (Katie Hafner & John Markoff, 1991)
- The Art of Deception (Kevin Mitnick, 2002)
- Ghost in the Wires (Kevin Mitnick, 2011)
- The Cuckoo’s Egg (Cliff Stoll)
- The Mentor Manifesto (1986)
Film/Dokumenter
- War Games (1983) — Matthew Broderick
- Hackers (1995) — Angelina Jolie, Jonny Lee Miller
- The Social Network (2010) — Facebook
- Citizenfour (2014) — Snowden
- Mr. Robot (2015-2019) — TV series
- The Great Hack (2019)
- Halt and Catch Fire (2014-2017)
- Silicon Valley (2014-2019)
- Dark Net (2016-)
Podcast & YouTube
- Darknet Diaries (Jack Rhysider)
- Security Now (Steve Gibson, Leo Laporte)
- Hacking Exposed — berbagai
- LiveOverflow — YouTube
- Computerphile — YouTube
- Null Byte — YouTube
- John Hammond — YouTube
- Hak5 — YouTube & YouTube
- LiveOverflow — YouTube
- InsiderPhD — YouTube
Masa Depan
Quantum Cryptography (2025+)
- Post-quantum cryptography — NIST standardisasi
- Lattice-based — Kyber, CRYSTALS
- Hash-based — SPHINCS+
- Code-based — McEliece
- Multivariate — Rainbow
AI Security (2025+)
- AI untuk defensive — deteksi, response
- AI untuk offensive — phishing, deepfake
- AI jailbreak — masalah
- Prompt injection — risiko baru
- AI governance — penting
Cloud Security (2025+)
- Cloud misconfiguration — kesalahan #1
- S3 bucket leaks — contoh
- IAM privilege escalation — umum
- Container security — Kubernetes
- Serverless security — new challenges
IoT Security (2025+)
- Mirai botnet — 2016
- Default password — masalah
- Medical devices — risiko
- Connected cars — kerentanan
Hardware Security (2025+)
- Side-channel attacks — Spectre, Meltdown
- Rowhammer — bit flip
- Firmware backdoors — xz Utils
- Supply chain — rentan
Threat Intelligence (2025+)
- MISP — platform
- MITRE ATT&CK — framework
- STIX/TAXII — standar
- OSINT — bagian penting
Kesimpulan
Sejarah hacker adalah sejarah inovasi, pemberontakan, dan kekuatan. Dari kereta api model MIT hingga bug bounty modern, dari buku telepon komunitas ke AI security — hacker selalu ada di garis depan perubahan.
- Budaya — berbagi, eksplorasi, transparansi
- Teknik — seni memecahkan masalah
- Etika — debat terus
- Masa depan — AI, quantum, cloud
“Hack the planet.” — tagline hacker