Showing posts with label Books I Read. Show all posts
Showing posts with label Books I Read. Show all posts

Tuesday, March 17, 2009

Book: Hacking Exposed, 6th Edition



Best hacking book by former Foundstone guys just released the sixth edition!

Updates:
  • New chapter on hacking hardware, including lock bumping, access card cloning, RFID hacks, USB U3 exploits, and Bluetooth device hijacking
  • Updated Windows attacks and countermeasures, including new Vista and Server 2008 vulnerabilities and Metasploit exploits
  • The latest UNIX Trojan and rootkit techniques and dangling pointer and input validation exploits
  • New wireless and RFID security tools, including multilayered encryption and gateways
  • All-new tracerouting and eavesdropping techniques used to target network hardware and Cisco devices
  • Updated DoS, man-in-the-middle, DNS poisoning, and buffer overflow coverage
  • VPN and VoIP exploits, including Google and TFTP tricks, SIP flooding, and IPsec hacking
  • Fully updated chapters on hacking the Internet user, web hacking, and securing code
Amazon Link

Tuesday, December 30, 2008

Book: The Best Damn IT Security Management Book Period


This is a huge book with 958 pages! I only finished reading Part1: From Vulnerability to Patch, which includes 11 chapters and 200 pages. The rest parts are only for reference when needed.

The following is six stages of a Vulnerability Management plan cut from the book. This is what the Part 1 tells, and introduces some free and commerical tools for implementation.

Tuesday, November 11, 2008

Book: Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research



This book is a detailed user manual for Metaploit Framework except case studies on vulnerability research, but to me the most interesting part is appendix B: Building a Test Lab for Penetration Testing. The author has shared much experience about this, which deserves a read.