Showing posts with label penetration testing. Show all posts
Showing posts with label penetration testing. Show all posts

Unauthorised Access: Physical Penetration Testing For IT Security Teams Review

Unauthorised Access: Physical Penetration Testing For IT Security Teams
Average Reviews:

(More customer reviews)
Unauthorised Access is nothing short of a manual for corporate espionage. Author Wil Allsopp, is a "penetration tester", a hired gun brought in by companies to find out how effective the security defences protecting their premises are.
While conventional penetration testing ("pentesting") involves remote hacking, typically through software vulnerabilities, physical pen-testers gain access to a company's offices or data centre with the goal of connecting to a restricted network, planting a bug or even an imitation explosive device
With ten years experience as a pen-tester, Allsopp offers superb insight into common methods used by criminals to manipulate employees, from phone calls to outright espionage. The chapter on social engineering, in particular, is guaranteed to spark paranoia and sleepless nights among even the most grizzled chief security officers.
Specific tactics he reveals include employing politeness, inducing fear, faking supplication, invoking authority, ingratiation and deference, and even sexual manipulation.
Another chapter details several successful pen-tests conducted by Allsopp and his team, including attacks on a UK power plant and a supercomputing facility conducting spatial modelling of nuclear explosions for the military. He also describes the antics of a pentester who bypassed the security of a large corporate by observing the uniform of the firm's security guard, then showing up the next day in identical costume, pulling rank and relieving the man of duty
The enjoyment Allsopp clearly derives from his work is reflected in his book; he writes with that particular tone of repressed glee common among white hat hackers. This, together with his tendency to adopt a Boy's Own adventure narrative style, makes the book very readable but occasionally somewhat glib. And at times it is hard to tell whether Allsopp is offering advice to the CSO, helping the reader start their own pen-testing company or trying to prove to a less salubrious readership how clever he is.
Indeed, many of the techniques described in Unauthorised Access are open to abuse. Allsopp gives the excuse that "the bad guys already know", before urging the reader to consider taking up lock picking as a rewarding hobby.

Click Here to see more reviews about: Unauthorised Access: Physical Penetration Testing For IT Security Teams

The first guide to planning and performing a physical penetration test on your computer's security
Most IT security teams concentrate on keeping networks and systems safe from attacks from the outside-but what if your attacker was on the inside? While nearly all IT teams perform a variety of network and application penetration testing procedures, an audit and test of the physical location has not been as prevalent. IT teams are now increasingly requesting physical penetration tests, but there is little available in terms of training. The goal of the test is to demonstrate any deficiencies in operating procedures concerning physical security.
Featuring a Foreword written by world-renowned hacker Kevin D. Mitnick and lead author of The Art of Intrusion and The Art of Deception, this book is the first guide to planning and performing a physical penetration test. Inside, IT security expert Wil Allsopp guides you through the entire process from gathering intelligence, getting inside, dealing with threats, staying hidden (often in plain sight), and getting access to networks and data.
Teaches IT security teams how to break into their own facility in order to defend against such attacks, which is often overlooked by IT security teams but is of critical importance
Deals with intelligence gathering, such as getting access building blueprints and satellite imagery, hacking security cameras, planting bugs, and eavesdropping on security channels
Includes safeguards for consultants paid to probe facilities unbeknown to staff
Covers preparing the report and presenting it to management

In order to defend data, you need to think like a thief-let Unauthorised Access show you how to get inside.

Buy NowGet 43% OFF

Click here for more information about Unauthorised Access: Physical Penetration Testing For IT Security Teams

Read More...

Dissecting the Hack: The F0rb1dd3n Network, Revised Edition Review

Dissecting the Hack: The F0rb1dd3n Network, Revised Edition
Average Reviews:

(More customer reviews)
I personally have never seen a book like this one. I think it has created a genre of its own, and I liked it. I hope that other authors might be able to build off this real life hacking, explanatory fiction. The story kept my attention, and the only con I can think of is that I just wished it was a little longer. I have already recommended this book to friends of mine, and they're planning on reading it too.

Click Here to see more reviews about: Dissecting the Hack: The F0rb1dd3n Network, Revised Edition


Dissecting the Hack is one heck of a ride! Hackers, IT professional, and Infosec aficionados (as well as everyday people interested in security) will find a gripping story that takes the reader on a global trip through the world of computer security exploits. One-half thriller, one-half reference, each provides context for the other. Together they will show you how to see the digital world just below the surface of daily life.

Yes, the security threats are real! In this revised edition the Part 2 content is completely NEW. Read more about the tactics that you see executed throughout the story in the second half of the book where you will learn to recon, scan, explore, exploit, and expunge with the tools and techniques shown in the story.

Revised edition includes a completely NEW STAR Section (Part 2)
Utilizes actual hacking and security tools in its story- helps to familiarize a newbie with the many devices and their code
Introduces basic hacking techniques in real life context for ease of learning
Presented in the words of the hacker/security pro, effortlessly envelops the beginner in the language of the hack
Check out the companion site at www.dissectingthehack.com complete with an interactive forum!
Exclusive interviews in this revised edition include thoughtful insights into security issues and hacking culture from industry leaders Dan Kaminsky, Johnny Long, Jeff Moss and Marcus Ranum






Buy NowGet 37% OFF

Click here for more information about Dissecting the Hack: The F0rb1dd3n Network, Revised Edition

Read More...

Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems Review

Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems
Average Reviews:

(More customer reviews)
First of all if you consider yourself an expert in packet analysis don't read this book to learn advanced techniques in packet analysis. Instead read this book as a teaching tool to help better explain packet analysis to others. I found myself reading this book and going "hey I wish someone would have explained it to me that way when I started" and "why didn't I explain it that way."
This book is written for people who have little to no experience with packet analysis. It is also a good read for those who might have been out of the packet analysis game for a little while and need a quick read to brush up the skill-set. The book is well written and Sanders does an excellent job explaining things in a manner that is well understood. He eases the reader into explanations by going from layman to more technical jargon. The examples in the book match the title, they are practical and likely to be experienced in the real world. I would highly recommend this book to those who have little to no experience with packet analysis and are looking for a solid book to help them understand what many of the other books tend to explain in a lofty manner.

Click Here to see more reviews about: Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems


It's easy to capture packets with Wireshark, the world's most popular network sniffer, whether off the wire or from the air. But how do you use those packets to understand what's happening on your network?

With an expanded discussion of network protocols and 45 completely new scenarios, this extensively revised second edition of the best-selling Practical Packet Analysis will teach you how to make sense of your PCAP data. You'll find new sections on troubleshooting slow networks and packet analysis for security to help you better understand how modern exploits and malware behave at the packet level. Add to this a thorough introduction to the TCP/IP network stack and you're on your way to packet analysis proficiency.

Learn how to:

Use packet analysis to identify and resolve common network problems like loss of connectivity, DNS issues, sluggish speeds, and malware infections
Build customized capture and display filters
Monitor your network in real-time and tap live network communications
Graph traffic patterns to visualize the data flowing across your network
Use advanced Wireshark features to understand confusing captures
Build statistics and reports to help you better explain technical network information to non-techies

Practical Packet Analysis is a must for any network technician, administrator, or engineer. Stop guessing and start troubleshooting the problems on your network.


Buy NowGet 40% OFF

Click here for more information about Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems

Read More...

Security In Wireless LANS And MANS (Artech House Computer Security) Review

Security In Wireless LANS And MANS (Artech House Computer Security)
Average Reviews:

(More customer reviews)
When wireless LANS were beginning to be developed, security was a concern. But as the systems were developed and marketed security became less important than getting to market quickly and of course price. As a result, the seurity features built into the initial systems was fairly weak. While the home user typically didn't care about security, the enterprise user was very concerned. After security flaws were discovered and published the widespread use at the enterprise level was halted. The IEEE standards community completed the revision of the security related components of the 802.11 standard in 2004, and equipment meeting the new standard is just becoming available.
This book covers the security aspects of WLANS, first discussing the initial designs and then how they were corrected in the new protocols.
The last part of the book is on the 802.16 Wireless Metropolitan Area Networks which have the promise, or perhaps the hope of dramatically increasing broadband access in areas not covered by cable systems and at distances too great for DSL service.

Click Here to see more reviews about: Security In Wireless LANS And MANS (Artech House Computer Security)



Buy NowGet 5% OFF

Click here for more information about Security In Wireless LANS And MANS (Artech House Computer Security)

Read More...

WarDriving and Wireless Penetration Testing Review

WarDriving and Wireless Penetration Testing
Average Reviews:

(More customer reviews)
Disclaimer: I know the guy who wrote the forward, although I don't think in any way this has influenced my review of this book.
I'm not a wireless hacker, although I've dabbled some in examining networks and some of the software in the book. That said, I think I learned quite a bit by reading this book. I didn't know what to expect with "Wardriving & Wireless Penetration Testing", but what I found was a focused, well prepared book with clear examples. Now, this book is very heavy on network discovery and mapping and not as complete on wireless attacks, although this topic does get coverage in a full chapter and parts of others.
What I like about the book is that it's comprehensive without being exhaustive. It covers WiFi hacking from Windows and Linux, which you would expect, and also from OS X (not so common) and also from, very pleasantly, handheld devices. The software covered is mainly using Kismet/Kismac and the NetStumbler family of software, which is not unexpected. These are premier tools and offer everything you would want. Several minor tools are also discussed.
Various attacks covered include breaking the security mechanisms of WEP, WPA and LEAP, not surprisingly, and how to commit MITM attacks. In all of these, the instructions are clear and straightforward with clear illustrations.
Lest you think this book is all about software, there's good coverage of hardware, both wireless cards and adapters as well as antennas. Also, some GPS software and its integration with wireless mapping efforts is also covered in detail. Another surprise is the coverage of the OpenWRT software kit for the WRT54G device, which can easily be loaded into a functional, dedicated wireless pentest and attack tool. The authors provide valuable tips and insights along the way. A short "bonus" chapter on wireless video device hacking is also included. Appendix B covers driver static analysis and testing, which is becoming a hot topic right now in vulnerability research.
Screenshots, examples, and images were generally well done. A handful of Linux-specific screenshots (ie for the kernel configuration) were poorly reproduced, unfortunately.
While I'm not an expert at wireless (either the security protocols, the auth protocols, or the physics) I didn't spot any obvious mistakes in their background material.
I found "Wardriving & Wireless Penetration Testing" to be well written and full of useful information, all clearly and well presented. The authors have prepared a good, timely book on the subject, and cover the topic in full, sharing insights and tips along the way.

Click Here to see more reviews about: WarDriving and Wireless Penetration Testing



Buy NowGet 33% OFF

Click here for more information about WarDriving and Wireless Penetration Testing

Read More...