Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice Review

The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice
Average Reviews:

(More customer reviews)
Are you a beginning security professional; as well as, a network and system administrator? If you are, then this book is for you! Author Jason Andress, has done an outstanding job of writing a book that can be used to develop a better understanding of how to protect information assets and defend against attacks; as well as, how to apply these concepts practically.
Andress, begins by covering some of the most basic concepts of information security. In addition, the author covers the security principles of identification and authentication. He then discusses the use of authorization and access control. The author then, discusses the use of auditing and accountability. He continues by discussing the use of cryptography. In addition, the author covers operational security. He then discusses physical security.
The author then shows you how to protect networks from a variety of different angles. Then, he explores hardening as one of the primary tools for securing the operating system and the steps that might be taken to do so. Finally, he shows you different ways in which to secure applications.
This most excellent book, provides the reader with a basic knowledge of information security in both theoretical and practical aspects. Perhaps more importantly, the concepts discussed in this book can be used to drive security projects and policies, in order to mitigate some of the issues discussed.

Click Here to see more reviews about: The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice



Buy NowGet 40% OFF

Click here for more information about The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice

Read More...

Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry Review

Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry
Average Reviews:

(More customer reviews)
After having read the subtitle -- Advanced Digital Forensic Analysis of the Windows Registry' -- I was a bit surprised to find that this book seems to have its roots in 'the number of analysts ... [who] have no apparent idea of the forensic value of the Windows Registry' as the Preface mentions. This suggests the book is not so much for the advanced analyst, but more of an introduction to the area for those who are not yet proficient in analysing Registry information.
Other areas of the book, such as the description of some of the internal structures of the registry, tend to support this. An advanced book would probably not have omitted a description of the security descriptors on registry keys, for example.
This is probably not obvious to the buyer -- who is likely to go by the subtitle. I bought the book largely on the strength of the title, myself, and while I'm not disappointed, it's not quite the book I hoped for.To the presumed reader, then, the main value is probably to be found in the two chapters of Case Studies. Here is where the value of the registry in a forensic analysis is most clearly described. These chapters are what beginning registry analysts want to read.
The focus of these chapters, though, is on the information in the registry, not where it is located, or to what extent it can be relied on. This is a deliberate decision of the author, and may be sound enugh. It means, though, that the reader is more drawn into using the author's tools, and less into being able to locate the actual keys and values himself with regedit or other tools. In a text for more advanced users, it would have been been a serious error to omit full key/value descriptions; in this type of book, it may lead to more complexity than is strictly warranted.
So, this is not quite the book for me. I don't mind buying it, but I will not be able to rely on it for reference, so it will end up in the bookshelf. I'd rate it at 3.5, but I do hesitate to round that up to an even four stars, as that is slightly too much, in my opinion.What would have made me give a higher score?* Better source references -- as it is, the source references are largely web links to Microsoft's support web site. If there are any references to printed works, I have not noted them. For example:
The author refers to earlier analysis by himself and Cory Altheide on USB artifacts, but so far I have been unable to find a single reference to that. As it's clear from the text that it was published, omitting this reference seems a little odd.
A couple of theses are mentioned: one by Jolantha Thomassen and one by Peter Norris, but none of these are properly referenced. The one by Ms. Thomassen, I was able to find a web link to in a "TIP" sidebar, and the one by Mr. Norris is mentioned in the text as another web link.
And Mark Russinovich's article 'Inside the Registry' mentioned in the text, is not cited either. (It was published in Windows NT Magazine.)
All of these may be available on the web, but as long as such presence is not guaranteed, I feel the proper source references to make are to the actually published texts.
For an introductory book, however, such references may be thought to be a little to academical and over the top -- though in that case, many of the existing references to Microsoft's support web site could not improbably be dropped as well.* A road map for further studies -- assuming that this particular book is an introduction to the topic, additional sources for continued studies would have been welcome. The preface hints of a wealth of information about the registry, and it is not clear that all aspects have been covered.
I expected to find a mention of Jerry Honeycutt's bok 'Microsoft Windows Registry Guide, 2. ed.' (Microsoft Press, 2005) mentioned, mainly because it describes the practical workings of the registry, and deploying techniques, as well as how to identify what registry settings a particular program modifies. It also documents many registry settings that may be of interest at an investigation, though it's focus is on computer management, not investigations, and it does go into many areas that were not included in the present book, such as registry access rights, and registry auditing.Additionally, I can't rid myself of a feeling that the book tries t be a little more than just an introduction. Some of the information is not on an introductory level. For example, the note on NoInstrumentation on p. 190 is not obviously of any practical value, as it raises the question what exact information is affected by this setting. To the researcher, though, it is probably the starting point for further experiments. And I must also admit that some terminological vagueness, spelling errors (the first is on the first text page of the book) and general grammatical and typographical fuzziness helps pull down the score a bit. The book uses '...' which normally indicates deliberate omissions, but here seems to be used instead of dashes -- this is very confusing at first. Proper typography as well as text polishing is generally the job of the publisher, but as the present publisher, Syngress, does not have much of a reputation in this area, it probably should be considered to be part and parcel of buying a Syngress book in the first place, and so not affect the score of any particular title. Still, the presence of it grates.
Additionally, in a book of reference the index would have been diaster. In an introductory book ... well, it may serve some purpose, but it's pretty clear that I can't use it to find anything important. There is, for example, an index entry 'Master boot record) MBR', but as the text it references only covers how to find drive signatures/volume IDs in the MBR, that entry is clearly not specific enough to be useful. More useful would have been to have index entries on 'drive signature' and 'volume ID', but there are none.


Click Here to see more reviews about: Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry



Buy NowGet 47% OFF

Click here for more information about Windows Registry Forensics: Advanced Digital Forensic Analysis of the Windows Registry

Read More...

Beautiful Security: Leading Security Experts Explain How They Think Review

Beautiful Security: Leading Security Experts Explain How They Think
Average Reviews:

(More customer reviews)
This collection of essays is a very clearly written introduction to a number of current topics and techniques in computer security. It is not a how-to book, but it includes several case studies and gives you a good idea of what is happening in the field. For the most part the book does not assume prior knowledge in the field, although occasionally a bit of hacker or security jargon is used without being defined.
For me the most interesting chapters were the one with case studies. In this book you will learn how to steal people's credit card numbers at airports (run a cut-rate WiFi access point), how to scan for malicious websites without getting infected (harder than it looks, and a constant battle of measures and countermeasures), and the true history of Pretty Good Privacy, as told by its inventor, Phil Zimmermann (not as lurid as the versions you have probably heard, but still full of twists and turns). You'll learn the going rates for stolen personal and financial information (not that much, so if you're going to steal it, you need to steal a lot) and how to run your own cyber money-laundering network (which seems to be where most of the money and the risk is). Microsoft plays a prominent role in the book, sometimes as hero, sometimes as chump.
The layout and production of the book are very good, and it has a good index (a glossary would have been nice, too). I have a couple of minor gripes: the book is set in itty-bitty type (I measured it at 8 points on 12 point line spacing); and although the book has two editors, the preface is written in the first person singular (apparently by Oram, but this is not stated).
The book's title, "Beautiful Security", was probably modeled on Oram's previous collection Beautiful Code: Leading Programmers Explain How They Think (Theory in Practice (O'Reilly)), but it doesn't really fit the content of this book. Some of the essays mention beauty in the body or the title, but this is usually a token appearance, or is explained as meaning that security should be built in rather than tacked on. The preface states that the purpose of the book is to convince the reader that security is not bureaucratic drudgery but is an exciting career, and I think the book is successful at this.

Click Here to see more reviews about: Beautiful Security: Leading Security Experts Explain How They Think



Buy NowGet 17% OFF

Click here for more information about Beautiful Security: Leading Security Experts Explain How They Think

Read More...

Computer and Information Security Handbook (The Morgan Kaufmann Series in Computer Security) Review

Computer and Information Security Handbook (The Morgan Kaufmann Series in Computer Security)
Average Reviews:

(More customer reviews)
Wow! This is the most comprehensive book on information security out there! I keep it handy in my office at all times and have bought copies for all my employees, who refer to it on a near-daily basis. This really is a must-have for anyone in the industry to keep on top of the latest state-of-play for infosec. 5 stars!!

Click Here to see more reviews about: Computer and Information Security Handbook (The Morgan Kaufmann Series in Computer Security)


This book presents information on how to analyze risks to your networks and the steps needed to select and deploy the appropriate countermeasures to reduce your exposure to physical and network threats. It also imparts the skills and knowledge needed to identify and counter some fundamental security risks and requirements, inlcuding Internet security threats and measures (audit trails IP sniffing/spoofing etc.) and how to implement security policies and procedures.

In addition, this book also covers security and network design with respect to particular vulnerabilities and threats. It also covers risk assessment and mitigation and auditing and testing of security systems.

From this book, the reader will also learn about applying the standards and technologies required to build secure VPNs, configure client software and server operating systems, IPsec-enabled routers, firewalls and SSL clients.

Chapter coverage includes identifying vulnerabilities and implementing appropriate countermeasures to prevent and mitigate threats to mission-critical processes. Techniques are explored for creating a business continuity plan (BCP) and the methodology for building an infrastructure that supports its effective implementation.

A public key infrastructure (PKI) is an increasingly critical component for ensuring confidentiality, integrity and authentication in an enterprise. This comprehensive book will provide essential knowledge and skills needed to select, design and deploy a PKI to secure existing and future applications.

This book will include discussion of vulnerability scanners to detect security weaknesses and prevention techniques, as well as allowing access to key services while maintaining systems security.

Chapters contributed by leaders in the field cover theory and practice of computer security technology, allowing the reader to develop a new level of technical expertise.
This book's comprehensive and up-to-date coverage of security issues facilitates learning and allows the reader to remain current and fully informed from multiple viewpoints.
Presents methods of analysis and problem-solving techniques, enhancing the readers grasp of the material and ability to implement practical solutions.


Buy NowGet 24% OFF

Click here for more information about Computer and Information Security Handbook (The Morgan Kaufmann Series in Computer Security)

Read More...

Hacking: The Next Generation (Animal Guide) Review

Hacking: The Next Generation (Animal Guide)
Average Reviews:

(More customer reviews)
I'm always skeptical about books that propose to cover such a vast spectrum of subjects, the book in question however does a wonderful job at explaining in plain english what is happening behind an attack, it unveils the possible motives and end result, and I personally found it a superb manuscript on what is happening today in the fields of hacking and social engineering.
On a more technical side it covers XSS attacks and blended exploits, again in plain english. Though the authors also throw some code in there to keep the techiest of us entertained, personally I found the inclusion of code somewhat unnecessary. 'Plain english' would suffice especially because I found that this would otherwise be the perfect book to hand to someone less techy who wants to know what is happening out there in the wild and to some extent what they need to look out for if they intend to be security conscious. Could they ignore the code? sure! will they? depends on the individual and his/her aversion to programming. It still keeps its five stars though, I cant fault a book for having too much information. The book also covers phishing attacks, that chapter was a very worth wile read. I hold no interest or curiosity in phishing attacks and after reading it I was surprised on what I had learned.
The chapters on social engineering and information gathering were very interesting as well. The authors made a clear effort to mention current online tools that attackers can use to acquire information on a target (may that be a person or a corporate entity) and go into deeper detail on how such an attack can develop into face to face contact with a target. The way the book is written makes it feel like a story, like one attack unfolds into another and that is really why this book is such good fun to read.
If there's something I can fault in this book its really its life span. You have to get it now for it to matter. In 2 years time all this will be old, stale news and at the speed things change in the IT/IS world its really quite inevitable. Social engineering will always be social engineering but the tools used to gather information will surely change.

Click Here to see more reviews about: Hacking: The Next Generation (Animal Guide)



Buy NowGet 38% OFF

Click here for more information about Hacking: The Next Generation (Animal Guide)

Read More...

Network Security Bible Review

Network Security Bible
Average Reviews:

(More customer reviews)
This is a great book; it goes in great detail about security in all aspects of the computer industry. However it lacks one critical aspect, how do I do that? Like all network and computer professionals, I do not know everything, so when you tell me I should do something a certain way I'd hope that you will also tell me how to do it. With this book I found myself saying, maybe they will tell me what to do later, over and over, never happens. If you want to buy a book that's a reference manual, this is the one to get. If you are looking for a "how to" as well as a "what to look for" book, consider looking elsewhere.

Click Here to see more reviews about: Network Security Bible



Buy NowGet 39% OFF

Click here for more information about Network Security Bible

Read More...

CISSP: Certified Information Systems Security Professional Study Guide Review

CISSP: Certified Information Systems Security Professional Study Guide
Average Reviews:

(More customer reviews)
I must admit a soft spot for Sybex (and Ed Tittel) study guides, having used them extensively for Microsoft exams. This book follows in that tradition, providing a good balance between detailed explanation and comprehensive coverage of the exam topics.
The bundled CD is useful. I raced through the 250 flash cards in an hour, which is good for jogging the memory. The four bonus exams, of 75 questions each, are good, but are not as difficult as the real thing. These exams provide grades broken down by each CISSP exam domain, which is excellent for identifying topics for revision.
One book can not guarantee coverage of all CISSP exam topics, particularly given the long list of references on the CISSP suggested reading list. I also skimmed through a friend's copy of Shon Harris's "All-in-One" exam guide. I would still rate this book higher, but Harris's book covers some topics in more detail then the Sybex book. The "All-in-One" practice exams are more difficult, though some of the questions are not clearly worded.
The biggest disappoint I have with the exam preparation experience is with the CISSP's ten domains. The examination questions are based on 'good exam fodder' from topics in the ten domains. The topics lean towards an academic approach to security, rather then knowledge needed by a working security professional.
The other references I would strongly suggest to help to gain a security brain, as well as a high exam score include: Stephen Northcutt's `Inside Network Perimeter Security', Ross Anderson's `Security Engineering', and Syngress's `Special Ops'. Maybe I should take one of the SANS security exams, which are much more practical in nature.
And best of luck with the exam!

Click Here to see more reviews about: CISSP: Certified Information Systems Security Professional Study Guide



Buy NowGet 41% OFF

Click here for more information about CISSP: Certified Information Systems Security Professional Study Guide

Read More...

CompTIA Security+ SYO-201 Cert Guide Review

CompTIA Security+ SYO-201 Cert Guide
Average Reviews:

(More customer reviews)
This is a review for the CompTIA Security+ Cert Guide.
I am a trainer/course developer for a technical school and am in charge of developing a new Security+ course to begin in 2011. I reviewed this and several other books (along with other study materials) to use in the course.
This is a very nicely laid out book. The organization is exactly what I need to base my course around. The book starts small with basic subjects, and progressively builds on them.
Doesn't waste time, gets to the core of Security+ objectives quickly. But, there are also real-word examples, plus hands-on labs and videos. There are lots of questions which are an excellent prep for the actual CompTIA Security+ test. Two practice exams are at the end of the book, with a third on the disc. The disc also has videos that compliment the hands-on labs. Great glossary and index. Plus there are extras for instructors like me that can be downloaded for free. This book made it very easy for me to design my course, whereas I was struggling with other books, trying to match them up to our schedule and timeframe.
I always recommend a second (and perhaps even a third) test preparation source. It's always good to get two viewpoints when studying for an exam.
Accordingly, I plan to use this book along with the Security+ Exam Cram for the course. I use Mr. Prowse's materials for the A+ course as well, and Mr. Harwood's guides for the Net+. They all work very well together, and allow for the student to progress quickly from course to course.
While I am using this book for a technical class, it would work very well for the person who is studying on their own also. I highly recommend it.

Click Here to see more reviews about: CompTIA Security+ SYO-201 Cert Guide

CompTIA® Security+ SY0-201 Cert GuideDavid L. ProwseDVD Features Complete Practice ExamMaster every topic on CompTIA's new Security+ SY0-201 exam.Assess your knowledge and focus your learning.Get the practical workplace knowledge you need!Start-to-finish Security+ SY0-201 preparation from computer security consultant, Security+ trainer, and author David L. Prowse.Master every Security+ SY0-201 topic!Core computer system security conceptsOS hardening and virtualizationApplication securityNetwork design elements and threatsPerimeter securityNetwork media and devices securityPhysical security and authentication modelsAccess control methods and modelsVulnerability and risk assessmentMonitoring and auditingCryptography, including PKI Redundancy and disaster recoveryPolicies, procedures, and peopleTest your knowledge, build your confidence, and succeed!Two practice exams in the book, and an additional exam on the DVD, help you prepare and assess your readinessPacked with visuals to help you learn quicklyKey topics are highlighted to focus your studyExam preparation tasks include a review of key topics, memory table exercises, key terms, hands-on labs, and review questionsDVD Features Complete Practice ExamDetailed explanations of both correct and incorrect answersMultiple test modesRandom questions and order of answersDVD also features complete video solutions to the Hands-On Labs in the bookShelving Category: CertificationCovers: CompTIA Security+

Buy NowGet 38% OFF

Click here for more information about CompTIA Security+ SYO-201 Cert Guide

Read More...

CISSP Study Guide Review

CISSP Study Guide
Average Reviews:

(More customer reviews)
Obviously I am biased since I am a fellow SANS instructor, but will try to support my thoughts with data. I agree with another poster that the one star ratings are unfair, especially the guy that had not read the book; too funny. Well I have read the book, cover to cover on airplanes and some sections I have read twice. Why four stars? I am concerned that if this is the only CISSP prep you have, you will not be fully prepared for the exam. On the other hand, if you have taken a CISSP review course or read another book, this will be a great supplemental tool. I am a big fan of the Shawn Harris CISSP prep book as well, but you really can't take that monster with you on a trip, this book fit right in my carry on outside pocket.
OK, let's drill down into the book:
Ch 1: How to pass the exam, 5*s, clear and practical
Ch 2: Information Security Governance, 5*s, complete, concise, nothing missing that I can see
Ch 3: Access Control: 4*s, this chapter gets a bit muddy, the authors chose to cover some of the data flow access models in Ch 6 which is fine. First half of the chapter is true to the spirit of the book, the types of attackers section seems to be a touch superficial, thought the Metasploit "Point, click and root" was a chuckle.
Ch 4:Cryptography, 5*s, in my view this is the strongest chapter in the book, clearest explanations I have ever seen with one exception, in 2nd edition I would rework the Vienere Cipher section.
Ch 5: Physical Security, 5*s, complete, concise, let's you review the material in the shortest amount of time
Ch 6:Security Architecture, 4*s, I think there is a risk that the exam could cover more virtualization than the book prepares the candidate for. Not that I have knowledge of what is on the exam, but it is one of the most important topics in security right now and it only gets three paragraphs. I would also rework polyinstantiation, most of the sections are crystal clear, but this is a bit muddy.
Ch 7: Business Continuity, 4*s, I think this chapter could have been a touch shorter to be true to the spirit and approach of the book, all the information is there, but I had to force myself to read it, in second edition, suggest a do over.
Ch 8: Telecommunications, 5*s, authors are true domain experts, so they are able to concisely explain the material
Ch 9: Application Development Security, 5*s, same comment as above, since the authors know this stuff cold, they can make it very clear
Ch 10: Operations Security, 5*s, I do wish ISC2 would get on board with the better incident response model, but that is not the author's fault, this chapter is also true to the spirit of the book.
Ch 11: Legal regulations, 5*s, authors did a better job overall than I do with my course ( I will start the rewrite this week). I would suggest adding the concept of attestation to Chain of Custody.
The remainder of the book is a self test and the authors have additional practice testing on their web site. The Glossary is complete and also concise.


Click Here to see more reviews about: CISSP Study Guide


The CISSP Study Guide is aligned to cover all of the material included in the exam, complete with special attention to recent updates. The10 domains are covered completely and as concisely as possible with an eye to passing the exam thr first time. Each of the 10 domains has its own chapter that includes specially-designed pedagogy to aid you in passing the exam.

Clearly Stated Exam Objectives
Unique Terms / Definitions
Exam Warnings
Helpful Notes
Learning By Example
Stepped Chapter Ending Questions
Self Test Appendix
Detailed Glossary
Web Site (http://booksite.syngress.com/companion/conrad) Contains Two Practice Exams and Ten Podcasts-One for Each Domain




Buy NowGet 37% OFF

Click here for more information about CISSP Study Guide

Read More...

Build Your Own Security Lab: A Field Guide for Network Testing Review

Build Your Own Security Lab: A Field Guide for Network Testing
Average Reviews:

(More customer reviews)
I'll be completely honest. I went through this in about two hours, and I plan on returning it. It simply didn't have anything new for me. I was expecting it to be more along the lines of setting up a virtual network, attempting to hack the VMs, and then checking the procedures to see if you did it right.
Instead, this book covers things like how to install OSes into VMs, gives basic overviews of tools, etc. However, this is a great book if you're at the appropriate level for it. I think this makes a good follow-up to CompTIA's Security+ certification. It'll help novices get their feet wet with actual hands-on activities. I've done nearly everything in this book on my own, and that's really the only problem with it. While I didn't pay a great deal of attention to every bit of text, it seemed to be technically accurate and free from errors.
I wish I could give a more detailed review, but I thought I'd at least post this since no one has reviewed it yet. Just take your skill level into account when considering this title. If you want more advanced books, check out the Hacking Exposed series, Grey Hat Hacking, and the Penetration Tester's Open Source Toolkit.

Click Here to see more reviews about: Build Your Own Security Lab: A Field Guide for Network Testing

If your job is to design or implement IT security solutions or if you're studying for any security certification, this is the how-to guide you've been looking for. Here's how to assess your needs, gather the tools, and create a controlled environment in which you can experiment, test, and develop the solutions that work. With liberal examples from real-world scenarios, it tells you exactly how to implement a strategy to secure your systems now and in the future.
Note: CD-ROM/DVD and other supplementary materials are not included as part of eBook file.

Buy NowGet 40% OFF

Click here for more information about Build Your Own Security Lab: A Field Guide for Network Testing

Read More...

Hands-On Information Security Lab Manual Review

Hands-On Information Security Lab Manual
Average Reviews:

(More customer reviews)
There was no revision number listed on the website for this book. I purchased incorrect revision for this book (should have been rev 2). I had to returned it with extra return fee.

Click Here to see more reviews about: Hands-On Information Security Lab Manual



Buy NowGet 34% OFF

Click here for more information about Hands-On Information Security Lab Manual

Read More...

Wireshark Network Analysis: The Official Wireshark Certified Network Analyst Study Guide Review

Wireshark Network Analysis: The Official Wireshark Certified Network Analyst Study Guide
Average Reviews:

(More customer reviews)
I was a little nervous when I started reading this book. Chapter 1 provided an overview of network analysis, but had a lot of "personality." When I read, "Wait...more data is coming in...and more...and...SCREECH!" I wasn't too sure if I was going to finish the book. At over 700 pages, I was hoping that each page contained only "meat and potatoes," without a lot of dry humor and meaningless analogies. Thankfully, a few pages later I began what turned into a great read -- full of solid content.
Wireshark Network Analysis goes well beyond Wireshark functionality. Although the first several chapters outline how to best use Wireshark -- examining the settings, filters, and other configurations -- I think the true value of the book is in the detailed explanations of network traffic analysis. For instance, pg. 304 delves into DNS. This section tells the reader exactly what DNS is used for and provides an analysis of normal and abnormal DNS traffic. It also shows screenshots of the packet, displays and describes its contents. This type of analysis is provided throughout the book and covers all forms of network traffic (including suspect traffic -- my personal favorite).
Page 563 resonated with me, as I'm a firm believer in baselining network traffic. In this section, Wireshark Network Analysis details the importance of baselining and the types of traffic to focus on. Like other sections, this section also provides screenshots and shows how to analyze traffic and packet statistics.
There were minimal grammar errors, and it does seem like the case studies were not tech edited by the book editor -- many of them contained several grammar mistakes. Although, it does appear that the case studies were all submitted by third parties and probably used as-is. Nevertheless, I can provide plenty of other examples as to why Wireshark Network Analysis is a great book. There are plenty of screenshots, review questions with answers on the next page (instead of making the reader turn to the back of the book), and links to tons of packet captures for analyzing on your own. Overall, the book is well-written and, in my opinion, the best network analysis book on the market today.


Click Here to see more reviews about: Wireshark Network Analysis: The Official Wireshark Certified Network Analyst Study Guide

Wireshark is rated #2 in the Top 100 Network Security Tools by sectools.org. Wireshark is the world's most popular network analyzer tool. This book is the ultimate resource on Wireshark which is a MUST HAVE tool used by network IT professionals to troubleshoot, secure and optimize networks. Readers learn to capture wired and wireless traffic, focus on the cause of slow web browsing, identify why applications don't run properly across the network, locate the cause of poor VoIP call quality, determine why WLANs are plagued with problems and more. The author, Laura Chappell is the founder of Wireshark University and Chappell University and has been analyzing networks for over 20 years - the book is written in a clear manner with hundreds of screenshots for the visual learner. The foreword was written by Gerald Combs, creator of Wireshark.Wireshark Network Analysis covers the test objectives for the Wireshark Certified Network Analyst Exam and includes test questions and answers for all topics covered. Filled with 45 real-life case studies, Wireshark Network Analysis takes you inside small, medium and large corporations to see how they solved network problems in a more efficient, accurate way using Wireshark. Book supplements are available online at www.wiresharkbook.com.

Buy Now

Click here for more information about Wireshark Network Analysis: The Official Wireshark Certified Network Analyst Study Guide

Read More...

Dissecting the Hack: The F0rb1dd3n Network, Revised Edition Review

Dissecting the Hack: The F0rb1dd3n Network, Revised Edition
Average Reviews:

(More customer reviews)
I personally have never seen a book like this one. I think it has created a genre of its own, and I liked it. I hope that other authors might be able to build off this real life hacking, explanatory fiction. The story kept my attention, and the only con I can think of is that I just wished it was a little longer. I have already recommended this book to friends of mine, and they're planning on reading it too.

Click Here to see more reviews about: Dissecting the Hack: The F0rb1dd3n Network, Revised Edition


Dissecting the Hack is one heck of a ride! Hackers, IT professional, and Infosec aficionados (as well as everyday people interested in security) will find a gripping story that takes the reader on a global trip through the world of computer security exploits. One-half thriller, one-half reference, each provides context for the other. Together they will show you how to see the digital world just below the surface of daily life.

Yes, the security threats are real! In this revised edition the Part 2 content is completely NEW. Read more about the tactics that you see executed throughout the story in the second half of the book where you will learn to recon, scan, explore, exploit, and expunge with the tools and techniques shown in the story.

Revised edition includes a completely NEW STAR Section (Part 2)
Utilizes actual hacking and security tools in its story- helps to familiarize a newbie with the many devices and their code
Introduces basic hacking techniques in real life context for ease of learning
Presented in the words of the hacker/security pro, effortlessly envelops the beginner in the language of the hack
Check out the companion site at www.dissectingthehack.com complete with an interactive forum!
Exclusive interviews in this revised edition include thoughtful insights into security issues and hacking culture from industry leaders Dan Kaminsky, Johnny Long, Jeff Moss and Marcus Ranum






Buy NowGet 37% OFF

Click here for more information about Dissecting the Hack: The F0rb1dd3n Network, Revised Edition

Read More...

CISSP All-in-One Exam Guide, Fifth Edition Review

CISSP All-in-One Exam Guide, Fifth Edition
Average Reviews:

(More customer reviews)
There is no simple formula to prepare for the CISSP certification, and no single resource which can guarantee success on the certification exam since every applicant's background is unique. However, this book (fifth edition) was my only resource in preparing for the exam and I passed on my first attempt (April 24, 2010).
I spent 60+ hours in preparation for the exam... that's 60+ hours of DEDICATED individual study using this book and CD, not 60+ hours spent web surfing during lunch hours or commercial breaks. My recent background is in middle management, with 20 years experience in network architecture and data security, so I already had a firm technical foundation for the test areas dealing with protocols and encryption variations. I also have an MS in Computer Science. Nonetheless, the exam was so broad, with topics covering general principles and concepts, that I could have prepared twice as long and still left the exam with questions about the outcome.
My personal opinion is that formal classroom instruction, through one of the many organizations offering CISSP preparation courses, is a worthwhile companion to Shon Harris' book. A study group is also a good idea. You will not obtain CISSP certification if you take the exam without preparation. This book (fifth edition) was sufficient, but not 100% comprehensive, to prepare me for passing the CISSP test.
Note: Some reviewers do not appreciate Shon's frequent analogies and humor. Most of her analogies helped me internalize the complex topics, but that's my personal learning style. The efforts at humor were generally awful, but every once in a while she was subtle and brilliant enough to make me laugh out loud. Working through Shon's unique writing style was not a problem for me... I actually found it refreshing.

Click Here to see more reviews about: CISSP All-in-One Exam Guide, Fifth Edition

Get complete coverage of the latest release of the Certified Information Systems Security Professional (CISSP) exam inside this comprehensive, fully updated resource. Written by the leading expert in IT security certification and training, this authoritative guide covers all 10 CISSP exam domains developed by the International Information Systems Security Certification Consortium (ISC2). You'll find learning objectives at the beginning of each chapter, exam tips, practice exam questions, and in-depth explanations. Designed to help you pass the CISSP exam with ease, this definitive volume also serves as an essential on-the-job reference.
COVERS ALL 10 CISSP DOMAINS:
Information security and risk management
Access control
Security architecture and design
Physical and environmental security
Telecommunications and network security
Cryptography
Business continuity and disaster recovery planning
Legal regulations, compliance, and investigations
Application security
Operations security

THE CD-ROM FEATURES:
Hundreds of practice exam questions
Video training excerpt from the author
E-book

Shon Harris, CISSP, is a security consultant, a former member of the Information Warfare unit in the Air Force, and a contributing writer to Information Security Magazine and Windows 2000 Magazine. She is the author of the previous editions of this book.

Buy NowGet 48% OFF

Click here for more information about CISSP All-in-One Exam Guide, Fifth Edition

Read More...

Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems Review

Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems
Average Reviews:

(More customer reviews)
First of all if you consider yourself an expert in packet analysis don't read this book to learn advanced techniques in packet analysis. Instead read this book as a teaching tool to help better explain packet analysis to others. I found myself reading this book and going "hey I wish someone would have explained it to me that way when I started" and "why didn't I explain it that way."
This book is written for people who have little to no experience with packet analysis. It is also a good read for those who might have been out of the packet analysis game for a little while and need a quick read to brush up the skill-set. The book is well written and Sanders does an excellent job explaining things in a manner that is well understood. He eases the reader into explanations by going from layman to more technical jargon. The examples in the book match the title, they are practical and likely to be experienced in the real world. I would highly recommend this book to those who have little to no experience with packet analysis and are looking for a solid book to help them understand what many of the other books tend to explain in a lofty manner.

Click Here to see more reviews about: Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems


It's easy to capture packets with Wireshark, the world's most popular network sniffer, whether off the wire or from the air. But how do you use those packets to understand what's happening on your network?

With an expanded discussion of network protocols and 45 completely new scenarios, this extensively revised second edition of the best-selling Practical Packet Analysis will teach you how to make sense of your PCAP data. You'll find new sections on troubleshooting slow networks and packet analysis for security to help you better understand how modern exploits and malware behave at the packet level. Add to this a thorough introduction to the TCP/IP network stack and you're on your way to packet analysis proficiency.

Learn how to:

Use packet analysis to identify and resolve common network problems like loss of connectivity, DNS issues, sluggish speeds, and malware infections
Build customized capture and display filters
Monitor your network in real-time and tap live network communications
Graph traffic patterns to visualize the data flowing across your network
Use advanced Wireshark features to understand confusing captures
Build statistics and reports to help you better explain technical network information to non-techies

Practical Packet Analysis is a must for any network technician, administrator, or engineer. Stop guessing and start troubleshooting the problems on your network.


Buy NowGet 40% OFF

Click here for more information about Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems

Read More...

CompTIA Security+: Get Certified Get Ahead: SY0-201 Study Guide Review

CompTIA Security+: Get Certified Get Ahead: SY0-201 Study Guide
Average Reviews:

(More customer reviews)
perfect! i love this book. i had the original microsoft security+ book for class, and this book covered WAY more than what that book did, and alot less pages. i'm going to take my security+ certification exam on the 18th of December. i'm feeling very confident, as this book says it covers 100% of the exam. i'm just hoping there's no scenarios on the test =p, just questions about what i learned in the book, lol.
EDIT: Passed my exam with a 865/900 with this book! About 2-3 tricky questions throughout the entire test but it was ALL familiar. There was absolutely NOTHING unfamiliar on this test that the book didn't cover! Thank you :)

Click Here to see more reviews about: CompTIA Security+: Get Certified Get Ahead: SY0-201 Study Guide



Buy NowGet 25% OFF

Click here for more information about CompTIA Security+: Get Certified Get Ahead: SY0-201 Study Guide

Read More...

Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition Review

Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition
Average Reviews:

(More customer reviews)
Hardly a week goes by that CNN does not report a high-profile Web site being defiled or an e-commerce site being penetrated. While most people know why these incidents occurred, Hacking Exposed explains how they occurred and, more important, how to prevent them from occurring.
The cover of Hacking Exposed announces that "Network security is Y2K without the deadline." That alarmist statement, however, is the only hype in the book. The work is packed with real-world examples and links to tools needed to assess the security of any type of client/server and Web system. As they detail the myriad vulnerabilities in different types of systems, the authors provide countermeasures for each of them.
Well organized, the book progresses in an orderly fashion. It methodically goes through the process of exploiting a target to penetrate a system--from identification and enumeration to actual penetration. The authors provide detailed instructions and explanations for many security features and flaws in Unix, Linux, Windows, NetWare, routers, firewalls, and more. Topics covered include state-of-the-art computer and network penetration, as viewed by both the attacker and the defender; remote system identification; vulnerability identification; war dialers; firewall circumvention; and denial-of-service attacks. An appendix explores the security characteristics of Windows 2000.
Some may argue that books such as this one only serve to motivate and educate hackers. The truth is that hackers are already aware of the book's contents. This book is designed for system administrators and managers who need to know their systems' risks and vulnerabilities and how to address them. When they are done with this book, system administrators and managers will be familiar with such critical topics as back channels, port redirection, banner grabbing, and buffer overflows. Hacking Exposed is a must-read for anyone who wants to know what is really happening on their network....

Click Here to see more reviews about: Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition



Buy NowGet 37% OFF

Click here for more information about Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition

Read More...