Title | Content |
---|---|
Title | Gray Hat Hacking The Ethical Hackers Handbook |
Type | E-Book |
Language | English |
Author | Allen Harper |
Description |
INTRODUCTION I have seen enough of one war never to wish to see another. —Thomas Jefferson I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones. —Albert Einstein The art of war is simple enough. Find out where your enemy is. Get at him as soon as you can. Strike him as hard as you can, and keep moving on. —Ulysses S. Grant The goal of this book is to help produce more highly skilled security professionals who are dedicated to protecting against malicious hacking activity. It has been proven over and over again that it is important to understand one’s enemies, including their tactics, skills, tools, and motivations. Corporations and nations have enemies that are very dedicated and talented. We must work together to understand the enemies’ pro- cesses and procedures to ensure that we can properly thwart their destructive and mali- cious behavior. The authors of this book want to provide the readers with something we believe the industry needs: a holistic review of ethical hacking that is responsible and truly ethical in its intentions and material. This is why we are starting this book with a clear defini- tion of what ethical hacking is and is not—something society is very confused about. We have updated the material from the first and second editions and have attempted to deliver the most comprehensive and up-to-date assembly of techniques, procedures, and material. Nine new chapters are presented and the other chapters have been updated. In Part I of this book we lay down the groundwork of the necessary ethics and ex- pectations of a gray hat hacker. This section: • Clears up the confusion about white, black, and gray hat definitions and characteristics • Reviews the slippery ethical issues that should be understood before carrying out any type of ethical hacking activities • Reviews vulnerability discovery reporting challenges and the models that can be used to deal with those challenges • Surveys legal issues surrounding hacking and many other types of malicious activities • Walks through proper vulnerability discovery processes and current models that provide direction In Part II, we introduce more advanced penetration methods and tools that no other books cover today. Many existing books cover the same old tools and methods that have xxiiiGray Hat Hacking, The Ethical Hacker’s Handbook, Third Edition xxiv been rehashed numerous times, but we have chosen to go deeper into the advanced mech- anisms that real gray hats use today. We discuss the following topics in this section: • Automated penetration testing methods and advanced tools used to carry out these activities • The latest tools used for penetration testing • Physical, social engineering, and insider attacks In Part III, we dive right into the underlying code and teach the reader how specific components of every operating system and application work, and how they can be ex- ploited. We cover the following topics in this section: • Program Coding 101 to introduce you to the concepts you will need to understand for the rest of the sections • How to exploit stack operations and identify and write buffer overflows • How to identify advanced Linux and Windows vulnerabilities and how they are exploited • How to create different types of shellcode to develop your own proof-of- concept exploits and necessary software to test and identify vulnerabilities • The latest types of attacks, including client-based, web server, VoIP, and SCADA attacks In Part IV, we go even deeper, by examining the most advanced topics in ethical hacking that many security professionals today do not understand. In this section, we examine the following: • Passive and active analysis tools and methods • How to identify vulnerabilities in source code and binary files • How to reverse-engineer software and disassemble the components • Fuzzing and debugging techniques • Mitigation steps of patching binary and source code In Part V, we have provided a section on malware analysis. At some time or another, the ethical hacker will come across a piece of malware and may need to perform basic analysis. In this section, you will learn about the following topics: • Collection of your own malware specimen • Analysis of malware, including a discussion of de-obfuscation techniques If you are ready to take the next step to advance and deepen your understanding of ethical hacking, this is the book for you. We’re interested in your thoughts and comments. Please send us an e-mail at book@grayhathackingbook.com. Also, for additional technical information and re- sources related to this book and ethical hacking, browse to www.grayhathackingbook .com or www.mhprofessional.com/product.php?cat=112&isbn=0071742557. |
Views: | 2083 |
Publish time |
6 years ago
2018-06-11 08:30:00
|
Download |
|
AcTioN |
|
Please login/register to Leave a Reply