Hacking For Dummies
Book information
Description
Title Page Copyright Page Table of Contents Introduction About This Book Foolish Assumptions Icons Used in This Book Beyond the Book Where to Go from Here Part 1 Building the Foundation for Security Testing Chapter 1 Introduction to Vulnerability and Penetration Testing Straightening Out the Terminology Hacker Malicious user Recognizing How Malicious Attackers Beget Ethical Hackers Vulnerability and penetration testing versus auditing Policy considerations Compliance and regulatory concerns Understanding the Need to Hack Your Own Systems Understanding the Dangers Your Systems Face Nontechnical attacks Network infrastructure attacks Operating system attacks Application and other specialized attacks Following the Security Assessment Principles Working ethically Respecting privacy Not crashing your systems Using the Vulnerability and Penetration Testing Process Formulating your plan Selecting tools Executing the plan Evaluating results Moving on Chapter 2 Cracking the Hacker Mindset What You’re Up Against Who Breaks into Computer Systems Hacker skill levels Hacker motivations Why They Do It Planning and Performing Attacks Maintaining Anonymity Chapter 3 Developing Your Security Testing Plan Establishing Your Goals Determining Which Systems to Test Creating Testing Standards Timing your tests Running specific tests Conducting blind versus knowledge assessments Picking your location Responding to vulnerabilities you find Making silly assumptions Selecting Security Assessment Tools Chapter 4 Hacking Methodology Setting the Stage for Testing Seeing What Others See Scanning Systems Hosts Open ports Determining What’s Running on Open Ports Assessing Vulnerabilities Penetrating the System Part 2 Putting Security Testing in Motion Chapter 5 Information Gathering Gathering Public Information Social media Web search Web crawling Websites Mapping the Network WHOIS Privacy policies Chapter 6 Social Engineering Introducing Social Engineering Starting Your Social Engineering Tests Knowing Why Attackers Use Social Engineering Understanding the Implications Building trust Exploiting the relationship Deceit through words and actions Deceit through technology Performing Social Engineering Attacks Determining a goal Seeking information Using the Internet Dumpster diving Phone systems Phishing emails Social Engineering Countermeasures Policies User awareness and training Chapter 7 Physical Security Identifying Basic Physical Security Vulnerabilities Pinpointing Physical Vulnerabilities in Your Office Building infrastructure Attack points Countermeasures Utilities Attack points Countermeasures Office layout and use Attack points Countermeasures Network components and computers Attack points Countermeasures Chapter 8 Passwords Understanding Password Vulnerabilities Organizational password vulnerabilities Technical password vulnerabilities Cracking Passwords Cracking passwords the old-fashioned way Social engineering Shoulder surfing Inference Weak authentication Cracking passwords with high-tech tools Password-cracking software Dictionary attacks Brute-force attacks Rainbow attacks Cracking Windows passwords with pwdump3 and John the Ripper Cracking Unix/Linux passwords with John the Ripper Cracking password-protected files Cracking files Countermeasures Understanding other ways to crack passwords Keystroke logging Weak password storage Network analyzer Weak BIOS passwords Weak passwords in limbo General Password Cracking Countermeasures Storing passwords Creating password policies Taking other countermeasures Securing Operating Systems Windows Linux and Unix Part 3 Hacking Network Hosts Chapter 9 Network Infrastructure Systems Understanding Network Infrastructure Vulnerabilities Choosing Tools Scanners and analyzers Vulnerability assessment Scanning, Poking, and Prodding the Network Scanning ports Ping sweeping Using port scanning tools Countermeasures against ping sweeping and port scanning Scanning SNMP Vulnerabilities Countermeasures against SNMP attacks Grabbing banners Telnet Countermeasures against banner-grabbing attacks Testing firewall rules Testing Countermeasures against firewall rulebase vulnerabilities Analyzing network data Network analyzer programs Countermeasures against network protocol vulnerabilities The MAC-daddy attack ARP spoofing Using Cain & Abel for ARP poisoning MAC address spoofing Countermeasures against ARP poisoning and MAC address Spoofing attacks Testing denial of service attacks DoS attacks Testing Countermeasures against DoS attacks Detecting Common Router, Switch, and Firewall Weaknesses Finding unsecured interfaces Uncovering issues with SSL and TLS Putting Up General Network Defenses Chapter 10 Wireless Networks Understanding the Implications of Wireless Network Vulnerabilities Choosing Your Tools Discovering Wireless Networks Checking for worldwide recognition Scanning your local airwaves Discovering Wireless Network Attacks and Taking Countermeasures Encrypted traffic Countermeasures against encrypted traffic attacks Wi-Fi Protected Setup Countermeasures against the WPS PIN flaw Rogue wireless devices Countermeasures against rogue wireless devices MAC spoofing Countermeasures against MAC spoofing Physical security problems Countermeasures against physical security problems Vulnerable wireless workstations Countermeasures against vulnerable wireless workstations Default configuration settings Countermeasures against default configuration settings exploits Chapter 11 Mobile Devices Sizing Up Mobile Vulnerabilities Cracking Laptop Passwords Choosing your tools Applying countermeasures Cracking Phones and Tablets Cracking iOS passwords Taking countermeasures against password cracking Part 4 Hacking Operating Systems Chapter 12 Windows Introducing Windows Vulnerabilities Choosing Tools Free Microsoft tools All-in-one assessment tools Task-specific tools Gathering Information About Your Windows Vulnerabilities System scanning Testing Countermeasures against system scanning NetBIOS Hacks Countermeasures against NetBIOS attacks Detecting Null Sessions Mapping Gleaning information net view Configuration and user information Countermeasures against null-session hacks Checking Share Permissions Windows defaults Windows 2000/NT Windows XP and later Testing Exploiting Missing Patches Using Metasploit Countermeasures against missing patch vulnerability exploits Running Authenticated Scans Chapter 13 Linux and macOS Understanding Linux Vulnerabilities Choosing Tools Gathering Information About Your System Vulnerabilities System scanning Countermeasures against system scanning Finding Unneeded and Unsecured Services Searches Vulnerabilities Tools Countermeasures against attacks on unneeded services Disabling unneeded services Access control Securing the .rhosts and hosts.equiv Files Hacks using the hosts.equiv and .rhosts files hosts.equiv .rhosts Countermeasures against .rhosts and hosts.equiv file attacks Disabling commands Blocking access Assessing the Security of NFS NFS hacks Countermeasures against NFS attacks Checking File Permissions File permission hacks Countermeasures against file permission attacks Manual testing Automatic testing Finding Buffer Overflow Vulnerabilities Attacks Countermeasures against buffer overflow attacks Checking Physical Security Physical security hacks Countermeasures against physical security attacks Performing General Security Tests Patching Distribution updates Multiplatform update managers Part 5 Hacking Applications Chapter 14 Communication and Messaging Systems Introducing Messaging System Vulnerabilities Recognizing and Countering Email Attacks Email bombs Attachments Connections Automated email security controls Banners Gathering information Countermeasures against banner attacks SMTP attacks Account enumeration Relay Email header disclosures Capturing traffic Malware General best practices for minimizing email security risks Software solutions Operating guidelines Understanding VoIP VoIP vulnerabilities Scanning for vulnerabilities Capturing and recording voice traffic Countermeasures against VoIP vulnerabilities Chapter 15 Web Applications and Mobile Apps Choosing Your Web Security Testing Tools Seeking Out Web Vulnerabilities Directory traversal Crawlers Google Countermeasures against directory traversals Input-filtering attacks Buffer overflows URL manipulation Hidden field manipulation Code injection and SQL injection Cross-site scripting Countermeasures against input attacks Default script attacks Countermeasures against default script attacks Unsecured login mechanisms Countermeasures against unsecured login systems Performing general security scans for web application vulnerabilities Minimizing Web Security Risks Practicing security by obscurity Putting up firewalls Analyzing source code Uncovering Mobile App Flaws Chapter 16 Databases and Storage Systems Diving Into Databases Choosing tools Finding databases on the network Cracking database passwords Scanning databases for vulnerabilities Following Best Practices for Minimizing Database Security Risks Opening Up About Storage Systems Choosing tools Finding storage systems on the network Rooting out sensitive text in network files Following Best Practices for Minimizing Storage Security Risks Part 6 Security Testing Aftermath Chapter 17 Reporting Your Results Pulling the Results Together Prioritizing Vulnerabilities Creating Reports Chapter 18 Plugging Your Security Holes Turning Your Reports into Action Patching for Perfection Patch management Patch automation Commercial tools Free tools Hardening Your Systems Assessing Your Security Infrastructure Chapter 19 Managing Security Processes Automating the Security Assessment Process Monitoring Malicious Use Outsourcing Security Assessments Instilling a Security-Aware Mindset Keeping Up with Other Security Efforts Part 7 The Part of Tens Chapter 20 Ten Tips for Getting Security Buy-In Cultivate an Ally and a Sponsor Don’t Be a FUDdy-Duddy Demonstrate That the Organization Can’t Afford to Be Hacked Outline the General Benefits of Security Testing Show How Security Testing Specifically Helps the Organization Get Involved in the Business Establish Your Credibility Speak on Management’s Level Show Value in Your Efforts Be Flexible and Adaptable Chapter 21 Ten Reasons Hacking Is the Only Effective Way to Test The Bad Guys Think Bad Thoughts, Use Good Tools, and Develop New Methods IT Governance and Compliance Are More Than High-Level Audits Vulnerability and Penetration Testing Complements Audits and Security Evaluations Customers and Partners Will Ask How Secure Your Systems Are The Law of Averages Works Against Businesses Security Assessments Improve Understanding of Business Threats If a Breach Occurs, You Have Something to Fall Back On In-Depth Testing Brings Out the Worst in Your Systems Combined Vulnerability and Penetration Testing Is What You Need Proper Testing Can Uncover Overlooked Weaknesses Chapter 22 Ten Deadly Mistakes Not Getting Approval Assuming That You Can Find All Vulnerabilities Assuming That You Can Eliminate All Vulnerabilities Performing Tests Only Once Thinking That You Know It All Running Your Tests Without Looking at Things from a Hacker’s Viewpoint Not Testing the Right Systems Not Using the Right Tools Pounding Production Systems at the Wrong Time Outsourcing Testing and Not Staying Involved Appendix: Tools and Resources Bluetooth Certifications Databases Denial of Service (DoS) Protection Exploits Firewall Rulebase Analyzers General Research and OSINT Tools Hacker and Security Testing Publications Internet of Things Keyloggers Laws and Regulations Linux Live Toolkits Log Analysis Messaging Miscellaneous Mobile Networks Password Cracking Patch Management Security Education and Learning Resources Security Frameworks Security Reports and Statistics Social Engineering and Phishing Source Code Analysis Storage User Awareness and Training Voice over Internet Protocol Vulnerability Databases Websites and Applications Windows Wireless Networks Index EULA
Similar books
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF
The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians
1809 · PDF
Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix
2008 · PDF