Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

The Executive MBA in Information Security Review

The Executive MBA in Information Security
Average Reviews:

(More customer reviews)
Are you looking to buy The Executive MBA in Information Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Executive MBA in Information Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Executive MBA in Information Security ReviewIn The Executive MBA in Information Security, author John Trinckes notes that according to Washington, D.C., think tank the Brookings Institution, an organization's information and other intangible data assets account for more than 80 percent of its market value. Such a statistic unequivocally demonstrates the imperative of a strong enterprise information security program.

With that in mind, Trinckes first points out that data security is a management decision, and as such, requires executive leadership to create an effective foundation.

Leadership alone will not get the organization to a state of effective security, however, and that is where the book comes in. The reader will find within this work an overview of all of the core areas in information security. The format and content generally mirror the (ISC)2 Common Body of Knowledge, a basis for (ISC)2's Certified Information Systems Security Professional (CISSP) certification.

While nothing in the book is ground-breaking, its value lies in the integration of this information into a single volume for the person who does not have a strong background in information security and risk management.

While not the definitive text on the subject, The Executive MBA in Information Security provides a good start for any executive or professional looking to get a thorough understanding of the fundamentals of information security.
The Executive MBA in Information Security OverviewAccording to the Brookings Institute, an organization's information and other intangible assets account for over 80 percent of its market value. As the primary sponsors and implementers of information security programs, it is essential for those in key leadership positions to possess a solid understanding of the constantly evolving fundamental concepts of information security management. Developing this knowledge and keeping it current however, requires the time and energy that busy executives like you simply don't have. Supplying a complete overview of key concepts, The Executive MBA in Information Security provides the tools needed to ensure your organization has an effective and up-to-date information security management program in place. This one-stop resource provides a ready-to use security framework you can use to develop workable programs and includes proven tips for avoiding common pitfalls-so you can get it right the first time. Allowing for quick and easy reference, this time-saving manual provides those in key leadership positions with a lucid understanding of:The difference between information security and IT securityCorporate governance and how it relates to information securitySteps and processes involved in hiring the right information security staffThe different functional areas related to information securityRoles and responsibilities of the chief information security officer (CISO)Presenting difficult concepts in a straightforward manner, this concise guide allows you to get up to speed, quickly and easily, on what it takes to develop a rock-solid information security management program that is as flexible as it is secure.

Want to learn more information about The Executive MBA in Information Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Stealing the Network: How to Own a Shadow Review

Stealing the Network: How to Own a Shadow
Average Reviews:

(More customer reviews)
Are you looking to buy Stealing the Network: How to Own a Shadow? Here is the right place to find the great deals. we can offer discounts of up to 90% on Stealing the Network: How to Own a Shadow. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Stealing the Network: How to Own a Shadow ReviewDid you enjoy the previous three Stealing the Network books? Are you looking for more? Then move along now, nothing to see here.
The prior books were interesting because they introduced the reader to new ideas or new angles on old ideas, then moved on without belaboring them. If you wanted more details, there were often URLs provided. The last two tied the stories together with the intriguing Knuth character. But the folks running the project chose to switch to a new format, with fewer characters and stories, not to mention fewer authors, and fewer ways to split the profits.
After three books with the same (proven) formula, it's understandable the authors would want to try something new. Alas, it's a disaster.
Welcome to "How to Own a Shadow," aka "The SQL Injection Adventures of Pawn." Pawn is one of the new characters in this volume, and is the first StN character I hoped would get shot to death by the cops in a mini-mall parking lot. Yes, he's that irritating. Particularly after reading 40 pages about his childhood as a high-functioning autistic (or something like that), and around 100 pages of him performing SQL injection attacks. Most of which is totally unrelated to Knuth. Note to the authors: SQL injection is interesting, but if you want to write a book about it, just write a book about it. I even gave you a title, what more do you want? You can even recycle much of this book, like you recycled part of the last one here.
Oh, you noticed the real subtitle of the book, "The Chase for Knuth." First, one chases _after_ fugitives, and hunts or searches _for_ them. Not that it matters, because there's not much chasing or hunting going on in this book. There isn't much Knuth, either. We see him in the first hundred pages, which is mostly about his son analyzing poker software. That's the last we see of either of them. Because, really, this is "The Biography of Pawn." We do get 50 pages of Knuth at the end of the book, but don't get excited: it's all from the last book, added as obvious filler.
Speaking of filler, there's a 17 page advertorial thrown in for BiDiBLAH, which is commercial software by SensePost. Oddly enough, they're listed as technical advisors for the book. I'm sure it's a fine app, but the authors have forgotten about Knuth again, since it has nothing to do with the story. If it had been relevant, it might have been a less obnoxious addition.
Not everything is bad. There's a brief bit about RFID, which of course turns into how to use RFID for SQL attacks. We get to meet Knuth's supposedly dead wife, and a charming shrew she is. All in all, though, this book isn't worth reading unless you're a truly devoted fan of the series, or SQL. I'm still a fan of the previous books, and I hope the authors can recapture what made them so intriguing for their next book. I won't be buying that one until I'm sure it's not Book Two of the Pawn Saga, however.Stealing the Network: How to Own a Shadow OverviewThe best-selling Stealing the Network series reaches its climactic conclusion as law enforcement and organized crime form a high-tech web in an attempt to bring down the shadowy hacker-villain known as Knuth in the most technically sophisticated Stealing book yet.Stealing the Network: How to Own a Shadow is the final book in Syngress' ground breaking, best-selling, Stealing the Network series. As with previous title, How to Own a Shadow is a fictional story that demonstrates accurate, highly detailed scenarios of computer intrusions and counter-strikes. In How to Own a Thief, Knuth, the master-mind, shadowy figure from previous books, is tracked across the world and the Web by cyber adversaries with skill to match his own. Readers will be amazed at how Knuth, Law Enforcement, and Organized crime twist and torque everything from game stations, printers and fax machines to service provider class switches and routers steal, deceive, and obfuscate. From physical security to open source information gathering, Stealing the Network: How to Own a Shadow will entertain and educate the reader on every page. The book's companion Web site will also provide special, behind-the-scenes details and hacks for the reader to join in the chase for Knuth. The final book in the Stealing the Network series will be a must read for the 50,000 readers worldwide of the first three titles The companion Web site to the book will provide challenging scenarios from the book to allow the reader to track down Knuth Law enforcement and security professionals will gain practical, technical knowledge for apprehending the most supplicated cyber-adversaries

Want to learn more information about Stealing the Network: How to Own a Shadow?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security 2020: Reduce Security Risks This Decade Review

Security 2020: Reduce Security Risks This Decade
Average Reviews:

(More customer reviews)
Are you looking to buy Security 2020: Reduce Security Risks This Decade? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security 2020: Reduce Security Risks This Decade. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security 2020: Reduce Security Risks This Decade ReviewDisclaimer: I worked for Doug for a few years, and I know a number of the other contributing authors.
I liked this book, and I think it is a useful review of where InfoSec is coming from and a useful guide to how things are likely to go in the next years.
It strikes a good balance between technical details and executive management readability, which is good for a couple of reasons.
First, it will be useful to a wider audience, and broader awareness of these issues is a good thing.
Second, given that broad appeal, it can provide some common ground for the tactical folks in the trenches (like me), and the strategic folks in management. Making sure everyone is aware of the risks and getting everyone on the same page isn't always easy, and Security 2020 can help bridge the gap.
This is not "InfoSec 101" nor is it intended to be, though the writing is approachable enough that anyone will get something out of it. But for anyone in InfoSec directly, in a related role such as systems or network administration, or considering such a role, there's a lot of good stuff here. (Some might argue that systems or network administration are InfoSec roles, and I agree but depending on how your organization is structured you can end up with separate "silos"... Regardless--being on the same page is a Good Thing.)
If you've been around a while, the early chapters will be a good review, otherwise they'll help explain how we got where we are. Then it jumps to a blend of current threats and issues, where we're likely to go, and how we'll get there. My favorite section was the various scenarios in chapter 9, though the conclusions in chapter 10 are very interesting too.
Bottom line: if you have any role or interest in Information Security at all, this is good food for thought.Security 2020: Reduce Security Risks This Decade OverviewIdentify real security risks and skip the hype
After years of focusing on IT security, we find that hackers are as active and effective as ever. This book gives application developers, networking and security professionals, those that create standards, and CIOs a straightforward look at the reality of today's IT security and a sobering forecast of what to expect in the next decade. It debunks the media hype and unnecessary concerns while focusing on the knowledge you need to combat and prioritize the actual risks of today and beyond.
IT security needs are constantly evolving; this guide examines what history has taught us and predicts future concerns
Points out the differences between artificial concerns and solutions and the very real threats to new technology, with startling real-world scenarios
Provides knowledge needed to cope with emerging dangers and offers opinions and input from more than 20 noteworthy CIOs and business executives
Gives you insight to not only what these industry experts believe, but also what over 20 of their peers believe and predict as well

With a foreword by security expert Bruce Schneier, Security 2020: Reduce Security Risks This Decade supplies a roadmap to real IT security for the coming decade and beyond.

Want to learn more information about Security 2020: Reduce Security Risks This Decade?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Steal This Computer Book 4.0: What They Won't Tell You about the Internet Review

Steal This Computer Book 4.0: What They Won't Tell You about the Internet
Average Reviews:

(More customer reviews)
Are you looking to buy Steal This Computer Book 4.0: What They Won't Tell You about the Internet? Here is the right place to find the great deals. we can offer discounts of up to 90% on Steal This Computer Book 4.0: What They Won't Tell You about the Internet. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Steal This Computer Book 4.0: What They Won't Tell You about the Internet ReviewOverall this is a good book. The first part is sorta stupid, though. It talks mainly about how not to only listen to one person but to get information from multiple sources. It could be summed up in about a page.
Chapter 4 talks about buying computers and software. It helped me out by giving me some tricks to do next time I buy a computer.
Chapter 5 tells you about keeping your files secure with encryption. It tells you about some different types of encryption algorithms and how to write your own encryption programs. It also shows you how to play some dirty tricks. It talked about using anonymous remailers to send anonymous email and talked about just how anonymous they were. It even told you how to surf the web anonymously so that people couldn't receive information about your computer, browser, and more.
Chapter 6 told about phone phreaking history such as captian crunch. Wallace then goes on by telling you possibly things that could've happened but didn't. When telling these stories he tries to make himself sound like a phreaker but he didn't even do anything. Then, he tells your some really obvious stuff like "To start phone phreaking, you need access to a telephone." and "phreaking from your own phone will let the telephone company trace it to your house." I don't know if he couldn't think of anything else or he thinks you are really stupid. After that, he talks about phreaking color boxes and then goes on to voice mail hacking. Then, he talks about cellular phone fraud and tv satellite descrambling.
Chapter 7 talks about defeating windoz 3.1/95/98 screen saver passwords which if you ever tried you should've done it on the first or second try. It also talks about cracking program passwords and then it goes on to defeating parental control software. If you can't access certain web pages, Wallace tells you how by having the html code emailed to you. He also shows you how to read banned books in secret.
Chapter 8 talks about harassing online services, how pedophiles stalk innocent children and what you can do to stop them. He tells you about generating fake credit card numbers and making your own online harassment program.
Chapter 9 talks about stopping spam. It shows you multiply ways to take revenge on spammers. If the spammer used a forged email address, Wallace shows you how to track down the spammer like two magnets attracting each other.
Chapter 10 shows some pictures of acctual hacked web sites and how to hack them.
Chapter 11 shows you how to track people down by using specific things about them. For example if you only had their SSC# how you could still find them no matter where they were. At the end of the chapter, he shows you how to hide yourself if you don't want to be tracked down or how to let someone easily find you if, for example, you gave your child up for adoption years ago and you don't want to contact him/her but you do want to let them find you if they ever wanted you.
Chapter 12 shows you about ConGames on the Internet. It shows you how to do them and how to protect yourself from them.
Chapter 13 Viruses Part I. ( I heard that the plural form of virus is exposed to be virii, just like the plural form or fungus is fungi but in the book it is written viruses so that's how I will spell it.)
This chapter expains what viruses are, the parts of them, how to tell if you have a virus on your computer, the different infection methods, if all viruses are bad and how to learn more about them.
Chapter 14 Viruses Part II.
This chapter shows the different methods of how an antivirus program works and what to do if you find a virus ( If you say any idiot knows that if you find one you should delete it, but you could also send it in to an antivirus program if you think it is a uncommon virus, keep a copy of it, modify the virus and make a new one and many other things.)
Chapter 15 tells you about writing your own computer virus. Wallace also tells you to watch out because viruses sometimes attack their own creators. He tells you some true things about antivirus companies like how they hire virus writers to help them detect viruses (makes sense, doesn't it) and how that their isn't any evidence of this, but that they may hire the virus writers to write a virus that only they have the antidote for so people will buy their program to detect it.
Chapter 16 is about Java applets. I haven't read all of it but so far so good.
Appendice A is the glossary with a decent amount of terms covered in the book. I really haven't used it too much because I never needed to.
Appendice B is Visual Basic 3.0 ( a very easy programming language that I suggest you learn ) source code for altering Mega$hack. A program he discusses in 12. ( it is used by cons but he alters it so they get a taste of their own medicine.) The source code is written on the page so you will have to type it into your Visual Basic Compiler.
Appendice C is about additional resources. It is compiled of online magazines, webpages, hacker conventions and more.
Summary: This book is for you if you are interested in the above things. The websites and newsgroups in the book lead to nothing except for a few like metacrawler that he obviously was paid to advertise for. If you are still unsure after unreading all the reviews, go to a local bookstore and see if they have this book there. If they do then look at it, see if you like it and if so, compare the prices of Amazon plus the shipping and time to the prices of the bookstore. I hope that this review helped you because I know what it is like to have one person rate it 5 stars and another person rate it 1 star. Sinse this is a pain, I figured that instead of giving my opinion, I would tell you what the book had in it.Steal This Computer Book 4.0: What They Won't Tell You about the Internet Overview

Want to learn more information about Steal This Computer Book 4.0: What They Won't Tell You about the Internet?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Build Your Own Security Lab: A Field Guide for Network Testing Review

Build Your Own Security Lab: A Field Guide for Network Testing
Average Reviews:

(More customer reviews)
Are you looking to buy Build Your Own Security Lab: A Field Guide for Network Testing? Here is the right place to find the great deals. we can offer discounts of up to 90% on Build Your Own Security Lab: A Field Guide for Network Testing. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Build Your Own Security Lab: A Field Guide for Network Testing ReviewI'll be completely honest. I went through this in about two hours, and I plan on returning it. It simply didn't have anything new for me. I was expecting it to be more along the lines of setting up a virtual network, attempting to hack the VMs, and then checking the procedures to see if you did it right.
Instead, this book covers things like how to install OSes into VMs, gives basic overviews of tools, etc. However, this is a great book if you're at the appropriate level for it. I think this makes a good follow-up to CompTIA's Security+ certification. It'll help novices get their feet wet with actual hands-on activities. I've done nearly everything in this book on my own, and that's really the only problem with it. While I didn't pay a great deal of attention to every bit of text, it seemed to be technically accurate and free from errors.
I wish I could give a more detailed review, but I thought I'd at least post this since no one has reviewed it yet. Just take your skill level into account when considering this title. If you want more advanced books, check out the Hacking Exposed series, Grey Hat Hacking, and the Penetration Tester's Open Source Toolkit.Build Your Own Security Lab: A Field Guide for Network Testing OverviewIf your job is to design or implement IT security solutions or if you're studying for any security certification, this is the how-to guide you've been looking for. Here's how to assess your needs, gather the tools, and create a controlled environment in which you can experiment, test, and develop the solutions that work. With liberal examples from real-world scenarios, it tells you exactly how to implement a strategy to secure your systems now and in the future.
Note: CD-ROM/DVD and other supplementary materials are not included as part of eBook file.

Want to learn more information about Build Your Own Security Lab: A Field Guide for Network Testing?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Penetration Tester's Open Source Toolkit, Third Edition Review

Penetration Tester's Open Source Toolkit, Third Edition
Average Reviews:

(More customer reviews)
Are you looking to buy Penetration Tester's Open Source Toolkit, Third Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on Penetration Tester's Open Source Toolkit, Third Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Penetration Tester's Open Source Toolkit, Third Edition ReviewDo you have an interest in penetration testing or perform penetration testing as a professional? If you do, then this book is for you! Author Jeremy Faircloth, has done an outstanding job of writing a third edition of a book that explores a plethora of open source tools that are available to you as a penetration tester.
Faircloth, begins by looking at some of the major bundles of tools available in the open source world of penetration testing. In addition, the author focuses on reconnaissance and learning as much about your target as possible before you actually interact with it. He then leverages the data gathered through reconnaissance and expands on it. The author then, discusses social engineering and other attacks which can be used against individuals and their client workstations. He continues by focusing into a specific type of service, relational database management systems. In addition, the author covers topics associated with the web server software itself; as well as, the web applications running on top of that foundation. He then discusses network devices from the perspective of penetration testing. The author then ties everything that was discussed together, and uses that knowledge to demonstrate how to test an enterprise application. Then, the author discusses wireless networks, how they work, and how they are used in corporate environments. Finally, he discusses penetration test labs, what they are comprised of, and how to build them.
The goal of this most excellent book, is to provide you with a great introduction to penetration testing tools. Perhaps more importantly, this book gives you the opportunity to expand your knowledge in the area of penetration testing, by using open source tools.Penetration Tester's Open Source Toolkit, Third Edition Overview
Great commercial penetration testing tools can be very expensive and sometimes hard to use or of questionable accuracy. This book helps solve both of these problems. The open source, no-cost penetration testing tools presented do a great job and can be modified by the user for each situation. Many tools, even ones that cost thousands of dollars, do not come with any type of instruction on how and in which situations the penetration tester can best use them. Penetration Tester's Open Source Toolkit, Third Edition, expands upon existing instructions so that a professional can get the most accurate and in-depth test results possible. Real-life scenarios are a major focus so that the reader knows which tool to use and how to use it for a variety of situations.

Details current open source penetration testing tools
Presents core technologies for each type of testing and the best tools for the job
New to this edition: Enterprise application testing, client-side attacks and updates on Metasploit and Backtrack


Want to learn more information about Penetration Tester's Open Source Toolkit, Third Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Official Certified Ethical Hacker Review Guide Review

Official Certified Ethical Hacker Review Guide
Average Reviews:

(More customer reviews)
Are you looking to buy Official Certified Ethical Hacker Review Guide? Here is the right place to find the great deals. we can offer discounts of up to 90% on Official Certified Ethical Hacker Review Guide. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Official Certified Ethical Hacker Review Guide Reviewby far one of the better titles from Cengage (official curriculum vendor) a nice light read more like an exam cram style book. I recommend reading this through to understand the topics, the Read the Sybex CEH book by Kimberly Graves, and hit this one more time and review bluetooth and voip attacks using some simple google searches and you should be pretty well prepared to tackle this exam.Official Certified Ethical Hacker Review Guide OverviewGet ready for the latest Certified Ethical Hacker exam with the only book authorized by the creators of the certification, EC-Council!This book covers all of the various areas of the very challenging Certified Ethical Hacker exam, and includes hundreds of review questions in addition to refresher coverage of the information needed to successfully become a Certified Ethical Hacker.Including helpful at-a-glance quick reference boxes and tables, Exam Essentials summaries, review questions and answers, tutorial information and more, this resource is at once succinct and comprehensive.Not just an exam preparation tool, this book helps prepare future Certified Ethical Hackers to proactively protect their organization's systems from malicious hackers. It strengthens readers' knowledge that will help them successfully assess and analyze computer system weaknesses and vulnerabilities - so they can most effectively safeguard the organization's information and assets.This is the ideal resource for anyone looking to refresh their skills in this area, learn more about ethical hacking, or successfully pass the certification exam and become a Certified Ethical Hacker.

Want to learn more information about Official Certified Ethical Hacker Review Guide?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Penetration Tester's Open Source Toolkit Review

Penetration Tester's Open Source Toolkit
Average Reviews:

(More customer reviews)
Are you looking to buy Penetration Tester's Open Source Toolkit? Here is the right place to find the great deals. we can offer discounts of up to 90% on Penetration Tester's Open Source Toolkit. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Penetration Tester's Open Source Toolkit ReviewI am not sure why Penetration Tester's Open Source Toolkit (PTOST) was published. If you have no other security assessment books, you may find PTOST helpful. Otherwise, I don't believe this book offers enough value to justify purchasing it. Other books -- some published by Syngress -- cover some of the same ideas, and 5 of PTOST's chapters are published in other books anyway.
I was somewhat confused by PTOST's approach. The book features the logo of the Auditor live CD, along with a foreword by Auditor developer Max Moser. A version of Auditor is included with the book. However, PTOST isn't exactly a guide to Auditor. In fact, only on the back cover do we see a listing of the "CD contents." This list is odd since it does not distinguish between categories of tools (e.g., "Forensics") and the tools themselves (e.g., "Autopsy"). At the very least the book should have included an appendix listing the Auditor tools and a summary of their purpose.
PTOST does not feature enough original content to warrant buying the book. I think Osborne's Hacking Exposed, 5th Ed (HE5E) (or even the 4th Ed) addresses the phases of compromise in a more coherent and valuable manner. This is especially true for Ch 1 (Reconnaissance) and Ch 2 (Enumeration and Scanning); is there really anything original left to say on those subjects? I admit that coverage of certain SensePost tools was helpful, and SpiderFoot was cool.
Those looking to learn about database assessment (Ch 3) or Web hacking (Ch 4) would be better served by Syngress' own Special Ops: Host and Network Security for Microsoft, Unix, and Oracle. HE5E has a good chapter on Web hacking, and there's even a Hacking Exposed: Web Applications (HEWA) book. (A second edition of HEWA arrives this year, as does Syngress' new Web Application Security: A Guide for Developers and Penetration Testers.) However, I did like hearing about OScanner, SQLAT, and OAT in Ch 3.
Ch 5 (Wireless Penetration Testing Using Auditor), was one of my favorite chapters. It covered the material well enough, and it covered tools included with Auditor. The case studies were also helpful. Ch 6 (Network Devices) resembled Chs 1 and 2; it didn't contain anything really new. I could not understand why Ch 7 (Writing Open Source Security Tools) appeared in a book more or less about using a penetration testing live CD. The audiences for those using live CDs and those writing their own tools seem very different.
I also liked Ch 8 (Running Nessus from Auditor). Like Ch 5, it looked at the unique problems one encounters using a live CD for security work. For example, author Johnny Long offers multiple ways to update the Nessus plugins to a USB drive. This is exactly the sort of knowledge not found in other Nessus books. He also takes a look behind the scenes of the Nessus startup script on Auditor. Bravo.
I stopped reading PTOST after Ch 8. Why? Chs 9, 12, and 13 are published in Syngress' Writing Security Tools and Exploits (as Chs 9, 10, and 11). Chs 10 and 11 from PTOST are the same as Chs 3 and 4 from Syngress' Nessus, Snort, and Ethereal Power Tools. This tendency to reprint chapters from other books is worrisome.
I believe a second edition of PTOST would be more helpful if it focused strictly on tools found on a future assessment live CD, namely BackTrack. (BackTrack is a new live CD uniting the Auditor and Whax projects.) In fact, the authors might consider taking a case-based approach for the whole book. I thought the case studies in PTOST were some of the best material. For those looking for a comprehensive guide to security assessment, I recommend waiting for a second edition of Special Ops. Those who want a wide-ranging guide to security tools will like the recently published third edition of Osborne's Anti-Hacker Toolkit.Penetration Tester's Open Source Toolkit OverviewPenetration testing a network requires a delicate balance of art and science. A penetration tester must be creative enough to think outside of the box to determine the best attack vector into his own network, and also be expert in using the literally hundreds of tools required to execute the plan. This book provides both the art and the science. The authors of the book are expert penetration testers who have developed many of the leading pen testing tools; such as the Metasploit framework. The authors allow the reader "inside their heads" to unravel the mysteries of thins like identifying targets, enumerating hosts, application fingerprinting, cracking passwords, and attacking exposed vulnerabilities. Along the way, the authors provide an invaluable reference to the hundreds of tools included on the bootable-Linux CD for penetration testing.* Covers both the methodology of penetration testing and all of the tools used by malicious hackers and penetration testers * The book is authored by many of the tool developers themselves * This is the only book that comes packaged with the "Auditor Security Collection"; a bootable Linux CD with over 300 of the most popular open source penetration testing tools

Want to learn more information about Penetration Tester's Open Source Toolkit?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

CEH Certified Ethical Hacker All-in-One Exam Guide Review

CEH Certified Ethical Hacker All-in-One Exam Guide
Average Reviews:

(More customer reviews)
Are you looking to buy CEH Certified Ethical Hacker All-in-One Exam Guide? Here is the right place to find the great deals. we can offer discounts of up to 90% on CEH Certified Ethical Hacker All-in-One Exam Guide. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

CEH Certified Ethical Hacker All-in-One Exam Guide ReviewThis is, hands down, the most well written IT-related book I've come across. While other books have served as an immediate substitute for Ambien, Matt Walker and company have managed to pull off the tremendous feat of making their subject -- dare I say it? -- FUN. The writing is clear, the examples relevant, and there's a touch of humor to enliven the mundane. I've not taken the exam yet, so I can't speak to the alignment with the content, but I feel confident that no other book could have prepared me as well. I highly recommend this book and will keep an eye out for future works by this author.CEH Certified Ethical Hacker All-in-One Exam Guide Overview
Get complete coverage of all the objectives included on the EC-Council's Certified Ethical Hacker exam inside this comprehensive resource. Written by an IT security expert, this authoritative guide covers the vendor-neutral CEH exam in full detail. You'll find learning objectives at the beginning of each chapter, exam tips, practice exam questions, and in-depth explanations. Designed to help you pass the exam with ease, this definitive volume also serves as an essential on-the-job reference.

COVERS ALL EXAM TOPICS, INCLUDING:
Introduction to ethical hacking
Cryptography
Reconnaissance and footprinting
Network scanning
Enumeration
System hacking
Evasion techniques
Social engineering and physical security
Hacking web servers and applications
SQL injection
Viruses, trojans, and other attacks
Wireless hacking
Penetration testing


CD-ROM FEATURES:
Two practice exams
PDF copy of the book
Bonus appendix with author's recommended tools, sites, and references


Matt Walker, CEHv7, CPTS, CNDA, CCNA, MCSE, has held a wide variety of IT security teaching, writing, and leadership roles, including director of the Network Training Center on Ramstein AB, Germany, and IT security manager for Lockheed Martin at Kennedy Space Center. He is currently a security engineer for Hewlett-Packard.


Want to learn more information about CEH Certified Ethical Hacker All-in-One Exam Guide?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Android Forensics: Investigation, Analysis and Mobile Security for Google Android Review

Android Forensics: Investigation, Analysis and Mobile Security for Google Android
Average Reviews:

(More customer reviews)
Are you looking to buy Android Forensics: Investigation, Analysis and Mobile Security for Google Android? Here is the right place to find the great deals. we can offer discounts of up to 90% on Android Forensics: Investigation, Analysis and Mobile Security for Google Android. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Android Forensics: Investigation, Analysis and Mobile Security for Google Android ReviewAs Brian Carrier is to file system forensics and Harlan Carvey is to Windows registry analysis, Andrew Hoog is to the Android operating system. The level of detail in this book demonstrates a deep understanding of this complex and unique operating system. Chapter 1 begins with an overview of both Android and Linux in general. Instructions are provided for creating a virtual machine environment so the reader can follow along with the examples in the book. Throughout, the reader is encouraged to follow along, and ample opportunities are provided. This is highly appreciated as most technical books overwhelm the reader with information rather than guide them along the way. Chapter 2 presents an overview of the hardware that is supported by the Android OS. Chapter 3 begins the discussion of the Android OS proper. Included in this chapter are instructions on augmenting the previously created VM with the Android SDK providing additional tools for use in analysis. Chapter 4 is devoted to discussing the file systems likely to be encountered in the Android environment. Special attention is paid to YAFFS and YAFFS2. Chapter 5 discusses securing the data within the device. Also presented are recommendations for securely using Android devices in an enterprise environment. Additional advice is given for both users and developers to limit the exposure of sensitive data. Chapter 6 covers the most significant portion of the book with instructions on acquiring the data from device. Logical and physical acquisitions from the handset as well as the removable storage are discussed. The issue of passcode circumvention is discussed along with potential solutions. Chapter 7 finishes with timeline analysis techniques for the YAFFS file system and the FAT file system. Additional locations of interest to both security researchers and forensic analysts are also presented. Overall the book is enjoyable to read and will be a valuable asset for both forensic analysts and researchers.Android Forensics: Investigation, Analysis and Mobile Security for Google Android Overview
The open source nature of the platform has not only established a new direction for the industry, but enables a developer or forensic analyst to understand the device at the most fundamental level. Android Forensics covers an open source mobile device platform based on the Linux 2.6 kernel and managed by the Open Handset Alliance. The Android platform is a major source of digital forensic investigation and analysis. This book provides a thorough review of the Android platform including supported hardware devices, the structure of the Android development project and implementation of core services (wireless communication, data storage and other low-level functions). Finally, it will focus on teaching readers how to apply actual forensic techniques to recover data.

Ability to forensically acquire Android devices using the techniques outlined in the book
Detailed information about Android applications needed for forensics investigations
Important information about SQLite, a file based structured data storage relevant for both Android and many other platforms.


Want to learn more information about Android Forensics: Investigation, Analysis and Mobile Security for Google Android?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Google Hacking for Penetration Testers Review

Google Hacking for Penetration Testers
Average Reviews:

(More customer reviews)
Are you looking to buy Google Hacking for Penetration Testers? Here is the right place to find the great deals. we can offer discounts of up to 90% on Google Hacking for Penetration Testers. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Google Hacking for Penetration Testers ReviewThis review mainly focuses on evaluating how valuable is to get a copy of "Google Hacking for Penetration Testers - VOLUME 2" if you already own a copy of the first edition, and the scores rates exactly that. If you don't have neither of them, I strongly encourage you to acquire Volume 2 (see details below), no matter what area of the information security field you work in (and specially if you are a penetration tester), as the contents affect to you in multiple ways. On my day-to-day security consulting practice, I'm still very surprised about how many IT people don't know about these techniques. The book is a masterpiece for information disclosure and mining from public sources, such as (but not only) Google. If I had to evaluate the book on itself, not comparing between editions, it would definitely get a score of 5/5.
The first edition was released in 2005 and opened the world of the Google Hacking techniques to the general public, together with the GHDB. The second edition title is (at least) confusing, as Volume 2 seems to denote it is a complementary book to the first edition. It is not, so I do not recommend you to get the first edition today. Volume 2, or the second edition as it should have been called, has been thoroughly updated (including most of the screenshots) to cover the latest changes and Google applications. I did a major update to the SANS "Power Search with Google" course on the first half of 2006, when some of the new Google functionality (not in the first edition) was already available. The second edition reflects those updates I identified and put back together then, even the tiny ones, such as the maximum search terms, that changed from 10 to 32. Additionally, all the statistical references, covering number of results returned by Google, and main contents have been reviewed and updated to reflect the current state of the art.
Some chapters have been kept from the previous edition (chapters 1 to 3, and chapters 6 to 9, and chapter 12), although they have suffered updates. Others have been moved (such as the old chapter 10, now chapter 4) or redesigned (like the new chapter 5). Besides, there are brand new chapters, like 10 and 11.
I specially like the updates on chapter 5, with the new tools and scripts to query Google and, specially, to parse and process the results, including several Perl and User-Agent tricks. The book, obviously, covers the Google API changes and provides solutions to overcome them, such as Aura. Chapters 6 and 8 include relevant updates to the Google code search engine and new capabilities to locate malware and binaries, plus new techniques to track down login portals and network embedded devices and reports, respectively.
The new chapter 10 is a great reference covering the new Google services from a hacking and "malicious" perspective. It is a required update given the pace Google releases new functionality and information sources, such as the AJAX capabilities and API, the source code search engine, calendar, blogger, and alert services.
The new chapter 11, "Google Hacking Showcase", includes the real-world Google Hacking samples and cases Johnny Long has been presenting in several hacking conferences during the last years. A found having a printed copy of it within the book very valuable, as it is an eye-opener, and it is a fun read. Definitely, if you have not seen Johnny's presentations and talks, I encourage you to access the archives from BlackHat and DefCon and enjoy them.
Finally, chapter 12 (the old chapter 11), covers new techniques and tools from a defensive perspective. The new additions increase the defender arsenal in order to mitigate the old and new threats covered throughout the book.
The influence of multiple authors in this edition is evident, something good for the new contents and material, but not so good for the chapter layout, as some do not follow the original format with a final summary, solutions, links and FAQ. Chapter 10 is a good example of both.
The complementary appendixes from the first edition, not directly relevant to the book topic from my perspective, have been removed. Overall, I feel some of the waffle has been left out, a smart decision (but not always easy) in order to keep the book size reasonable, and make room for the new contents.
I would like to see some of the pages that simply provide long listings from the GHDB moved to an appendix and simply referenced from the associated chapter. It might be useful to have these lists full of query samples on the book, but not just in the middle of a chapter. Another improvement would be to have a book webpage consolidating all the code samples, such as the Blogger submission script, as I'm not sure they are all available on a single website.
To sum up, if you don't have a copy of this book, go and buy Volume 2! (not to mention Johnny's involvement with charities). If you are a professional penetration tester, the new material in this second edition is highly recommended, so update your shelves and start applying the new contents on your daily practice. If you are an infosec pro, not directly involved in Google Hacking tasks, and you already own a copy of the first edition, I think you do not need Volume 2, as you already understand the threat, risks, and what is all this about.
At some point I was almost involved in co-authoring this 2nd edition, but finally it didn't happened. A pity, as definitely, this is one of today's reference books that should be on any infosec shelves.Google Hacking for Penetration Testers OverviewA self-respecting Google hacker spends hours trolling the Internet for juicy stuff. Firing off search after search, they thrive on the thrill of finding clean, mean, streamlined queries and get a real rush from sharing those queries and trading screenshots of their findings. I know because I've seen it with my own eyes. As the founder of the Google Hacking Database (GHDB) and the Search engine hacking forums at http://johnny.ihackstuff.com, I am constantly amazed at what the Google hacking community comes up with. It turns out the rumors are true-creative Google searches can reveal medical, financial, proprietary and even classified information. Despite government edicts, regulation and protection acts like HIPPA and the constant barking of security watchdogs, this problem still persists. Stuff still makes it out onto the web, and Google hackers snatch it right up. Protect yourself from Google hackers with this new volume of information.-Johnny Long.Learn Google Searching BasicsExplore Google's Web-based Interface, build Google queries, and work with Google URLs..Use Advanced Operators to Perform Advanced QueriesCombine advanced operators and learn about colliding operators and bad search-fu..Learn the Ways of the Google HackerSee how to use caches for anonymity and review directory listings and traversal techniques..Review Document Grinding and Database DiggingSee the ways to use Google to locate documents and then search within the documents to locate information. .Understand Google's Part in an Information Collection FrameworkLearn the principles of automating searches and the applications of data mining..Locate Exploits and Finding TargetsLocate exploit code and then vulnerable targets..See Ten Simple Security SearchesLearn a few searches that give good results just about every time and are good for a security assessment..Track Down Web ServersLocate and profile web servers, login portals, network hardware and utilities..See How Bad Guys Troll for DataFind ways to search for usernames, passwords, credit card numbers, social security numbers, and other juicy information..Hack Google ServicesLearn more about the AJAX Search API, Calendar, Blogger, Blog Search, and more.

Want to learn more information about Google Hacking for Penetration Testers?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...