Penetration Tester's Open Source Toolkit: 2
|
| List Price: | £40.99 |
| Price: | £29.49 & eligible for FREE Super Saver Delivery on orders over £5. Details |
Availability: Usually dispatched within 24 hours
Dispatched from and sold by Amazon.co.uk
37 new or used available from £19.93
Average customer review:Product Description
Penetration testing a network requires a delicate balance of art and science. A penetration tester must be creative enough to think outside of the box to determine the best attack vector into his own network, and also be expert in using the literally hundreds of tools required to execute the plan. This second volume adds over 300 new pentesting applications included with BackTrack 2 to the pen tester's toolkit. It includes the latest information on Snort, Nessus, Wireshark, Metasploit, Kismet and all of the other major Open Source platforms.
. Perform Network Reconnaissance
Master the objectives, methodology, and tools of the least understood aspect of a penetration test.
. Demystify Enumeration and Scanning
Identify the purpose and type of the target systems, obtain specific information about the versions of the services that are running on the systems, and list the targets and services.
. Hack Database Services
Understand and identify common database service vulnerabilities, discover database services, attack database authentication mechanisms, analyze the contents of the database, and use the database to obtain access to the host operating system.
. Test Web Servers and Applications
Compromise the Web server due to vulnerabilities on the server daemon itself, its unhardened state, or vulnerabilities within the Web applications.
. Test Wireless Networks and Devices
Understand WLAN vulnerabilities, attack WLAN encryption, master information gathering tools, and deploy exploitation tools.
. Examine Vulnerabilities on Network Routers and Switches
Use Traceroute, Nmap, ike-scan, Cisco Torch, Finger, Nessus, onesixtyone, Hydra, Ettercap, and more to attack your network devices.
. Customize BackTrack 2
Torque BackTrack 2 for your specialized needs through module management, unique hard drive installations, and USB installations.
. Perform Forensic Discovery and Analysis with BackTrack 2
Use BackTrack in the field for forensic analysis, image acquisition, and file carving.
. Build Your Own PenTesting Lab
Everything you need to build your own fully functional attack lab.
Product Details
- Amazon Sales Rank: #49369 in Books
- Published on: 2007-11-22
- Original language: English
- Number of items: 1
- Binding: Paperback
- 592 pages
Editorial Reviews
About the Author
Chris Hurley is a Senior Penetration Tester in the Washington, DC area. He has more than 10 years of experience performing penetration testing, vulnerability assessments, and general INFOSEC grunt work. He is the founder of the WorldWide WarDrive, a four-year project to assess the security posture of wireless networks deployed throughout the world. Chris was also the original organizer of the DEF CON WarDriving contest. He is the lead author of WarDriving: Drive, Detect, Defend (Syngress Publishing, ISBN: 19318360305). He has contributed to several other Syngress publications, including Penetration Tester's Open Source Toolkit (ISBN: 1-5974490210), Stealing the Network: How to Own an Identity (ISBN: 1597490067), InfoSec Career Hacking (ISBN: 1597490113), and OS X for Hackers at Heart (ISBN: 1597490407). He has a BS from Angelo State University in Computer Science and a whole bunch of certifications to make himself feel important.
Customer Reviews
Take the "Open Source" with a pinch of salt
It's slightly ironic that this book has "open source toolkit" in its title when quite a few of the footprinting tools that are mentioned in the book are scripts and tools from Sensepost - which crucially, appear not to be on an open source licence. The book mentions some of the pay-for tools that sensepost supply, e.g. BidiBlah (which isn't "free" nor open source)
from sensepost's website:
"The evaluation of BiDiBLAH is limited to a 60 minute run time, and saving of data has been disabled. The full version is licensed for 1 year, and costs $500"
Apart from that, The book isn't that bad and has some good suggestions of how to proceed through the stages of a pen test and there are good work through examples with regard web applications. The wireless section is a bit lightweight for me but is a good overview. Forensics information relies heavily on the use of the accompanying Backtrack 2 CD, but none-the-less is OK, but is weak on the procedural/bureaucratic side of forensic investigation.
Useful book to have on a shelf to help you prepare a pre-engagement plan if you find yourself in unfamiliar territory during a pen test - but is let down by the quasi or non open source tools referenced in the book.
Poor
This book tends to describe what to do, without really explaining why it works. As such it does not educate the reader.
It is rather annoying just how many times they manage to mention SensePost, which according to the biography just happens to employ a number of the authors.
One to avoid. Just download the open source software yourself and read the man pages - just as good and will save you money.



