ENGLISH

Gray Hat Hacking The Ethical Hacker's Handbook

Book information

Year
2015
ISBN
9780071838504, 0071838503, 9780071832380, 0071832386
Language
english
Format
PDF
Filesize
17 MB (18113342 bytes)
Edition
Fourth
Pages
\657
Time added
2020-06-20 15:38:56

Description

Cover Title Page Copyright Page Contents Preface Acknowledgments Introduction Part I Crash Course: Preparing for the War Chapter 1 Ethical Hacking and the Legal System Why You Need to Understand Your Enemy’s Tactics The Ethical Hacking Process The Rise of Cyberlaw Vulnerability Disclosure Summary References For Further Reading Chapter 2 Programming Survival Skills C Programming Language Computer Memory Intel Processors Assembly Language Basics Debugging with gdb Python Survival Skills Summary References For Further Reading Chapter 3 Static Analysis Ethical Reverse Engineering Why Bother with Reverse Engineering? Source Code Analysis Binary Analysis Summary For Further Reading Chapter 4 Advanced Analysis with IDA Pro Static Analysis Challenges Extending IDA Pro Summary For Further Reading Chapter 5 World of Fuzzing Introduction to Fuzzing Choosing a Target Types of Fuzzers Getting Started Peach Fuzzing Framework Generation Fuzzers Summary For Further Reading Chapter 6 Shellcode Strategies User Space Shellcode Other Shellcode Considerations Kernel Space Shellcode Summary References For Further Reading Chapter 7 Writing Linux Shellcode Basic Linux Shellcode Implementing Port-Binding Shellcode Implementing Reverse Connecting Shellcode Encoding Shellcode Automating Shellcode Generation with Metasploit Summary For Further Study Part II From Vulnerability to Exploit Chapter 8 Spoofing-Based Attacks What Is Spoofing? ARP Spoofing DNS Spoofing NetBIOS Name Spoofing and LLMNR Spoofing Summary For Further Reading Chapter 9 Exploiting Cisco Routers Attacking Community Strings and Passwords SNMP and TFTP Attacking Cisco Passwords Middling Traffic with Tunnels Exploits and Other Attacks Summary For Further Reading Chapter 10 Basic Linux Exploits Stack Operations Buffer Overflows Local Buffer Overflow Exploits Exploit Development Process Summary For Further Reading Chapter 11 Advanced Linux Exploits Format String Exploits Memory Protection Schemes Summary References For Further Reading Chapter 12 Windows Exploits Compiling and Debugging Windows Programs Writing Windows Exploits Understanding Structured Exception Handling (SEH) Summary References For Further Reading Chapter 13 Bypassing Windows Memory Protections Understanding Windows Memory Protections (XP SP3, Vista, 7, 8, Server 2008, and Server 2012) Bypassing Windows Memory Protections Summary References For Further Reading Chapter 14 Exploiting the Windows Access Control Model Why Access Control Is Interesting to a Hacker How Windows Access Control Works Tools for Analyzing Access Control Configurations Special SIDs, Special Access, and “Access Denied” Analyzing Access Control for Elevation of Privilege Attack Patterns for Each Interesting Object Type What Other Object Types Are Out There? Summary For Further Reading Chapter 15 Exploiting Web Applications Overview of the Top 10 Web Vulnerabilities MD5 Hash Injection Multibyte Encoding Injection Hunting Cross-site Scripting (XSS) Unicode Normalization Forms Attack Summary References For Further Reading Chapter 16 Exploiting IE: Smashing the Heap Setting Up the Environment Introduction to Heap Spray Spraying with HTML5 DOM Element Property Spray (DEPS) HeapLib2 Technique Flash Spray with Byte Arrays Flash Spray with Integer Vectors Leveraging Low Fragmentation Heap (LFH) Summary References For Further Reading Chapter 17 Exploiting IE: Use-After-Free Technique Use-After-Free Overview Dissecting Use-After-Free (UAF) Leveraging the UAF Vulnerability Summary References For Further Reading Chapter 18 Advanced Client-Side Exploitation with BeEF BeEF Basics Hooking Browsers Fingerprinting with BeEF Browser Exploitation Automating Attacks Summary For Further Reading Chapter 19 One-Day Exploitation with Patch Diffing Introduction to Binary Diffing Binary Diffing Tools Patch Management Process Summary References For Further Reading Part III Advanced Malware Analysis Chapter 20 Dissecting Android Malware The Android Platform Malware Analysis Summary For Further Reading Chapter 21 Dissecting Ransomware History of Ransomware Options for Paying the Ransom Dissecting Ransomlock CryptoLocker Summary For Further Reading Chapter 22 Analyzing 64-bit Malware Overview of the AMD64 Architecture Decrypting C&C Domains Summary For Further Reading Chapter 23 Next-Generation Reverse Engineering Notable IDA Plug-ins Honeypots and Sandboxes Using TrapX Summary References For Further Reading Appendix About the Download Index A B C D E F G H I J K L M N O P R S T U V W X Y Z

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

1809 · PDF

Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix

2008 · PDF