Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Information Security Management Handbook, Sixth Edition (Isc2 Press) Review

Information Security Management Handbook, Sixth Edition (Isc2 Press)
Average Reviews:

(More customer reviews)
Are you looking to buy Information Security Management Handbook, Sixth Edition (Isc2 Press)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Information Security Management Handbook, Sixth Edition (Isc2 Press). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Information Security Management Handbook, Sixth Edition (Isc2 Press) ReviewIf your goal is to pass the CISSP exam, this book may help, but there are better books out there. If your goal is to actually dig deep into the security domains, this book contains a vast collection of security related topics that may help you reach that goal.
I gave it a 2 star because I was disappointed at the number of errors and omissions I discovered in this book, for example chapter 4 has 4 dates for ITGI's begining which are all wrong, Chapter 8 has the correct date. as matter of fact if I was the editor of the book, I would remove the entire chapter 4. I was happy to see Kevin Henry bring up the "placement of security" but he does not take it far enough. So chapter 14 we are back to "IT" based information security. I think it is time for security experts to start writing outside the box, most companies have confidential information that is not "IT" related, take contracts as an example.
Chapter 76 "Intrusion in information system security simply means the attempts or actions of unauthorized entry into an IT system. " really!, this is 1990's way of thinking Gildas Deograt-Lumy Roy Naldo Please read The Art of Intrusion by Kevin D. Mitnick.
I would write a book describing all that is wrong with this book, only if I had the time and writing skills some of which was wasted reading this book, Oh by the way Mr.Ralph Spencer Poore, there are so many exciting new standards coming up with cryptographic key management you should have and could have written about, such as the 1619.3, but I guess I have to read yet another book to learn about it.
Information Security Management Handbook, Sixth Edition (Isc2 Press) OverviewConsidered the gold-standard reference on information security, the Information Security Management Handbookprovides an authoritative compilation of the fundamental knowledge, skills, techniques, and tools required of today's IT security professional. Now in its sixth edition, this 3200 pagestand-alone reference is organized under the CISSP Common Body of Knowledgedomains and has beenupdated yearly.Volumes 2,3, andthis year's Volume 4 reflect thechanges to the CBK in response to new laws and evolving technology.

Want to learn more information about Information Security Management Handbook, Sixth Edition (Isc2 Press)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts Review

Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts
Average Reviews:

(More customer reviews)
Are you looking to buy Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts ReviewThis is a rather short (Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts Overview
It's no longer just a buzz word: "Security" is an important part of your job as a Systems Administrator. Most security books are aimed at security professionals, but Security for System Administrators is written for System Administrators. This book covers the basics of securing your system environment as well as security concepts and how these concepts can be implemented practically using common tools and applications. Whether you are new to this profession or have been in the field a while, you'll find valuable information in each chapter. The book's examples will focus on Windows Server 2008 R2 and Windows 7, but many concepts are platform agnostic.

Take all the confusion out of security including: network attacks, system failures, social networking, and even audits
Learn how to apply and implement general security concepts
Identify and solve situations within your network and organization


Want to learn more information about Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

InfoSec Career Hacking: Sell Your Skillz, Not Your Soul Review

InfoSec Career Hacking: Sell Your Skillz, Not Your Soul
Average Reviews:

(More customer reviews)
Are you looking to buy InfoSec Career Hacking: Sell Your Skillz, Not Your Soul? Here is the right place to find the great deals. we can offer discounts of up to 90% on InfoSec Career Hacking: Sell Your Skillz, Not Your Soul. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

InfoSec Career Hacking: Sell Your Skillz, Not Your Soul ReviewI enjoyed reading this book and I kept thinking to myself, "I wished this book would have existed when I tried to break into Information Security/Information Assurance. So far I've had a pretty successful IA career and as I read each chapter of the book I realized that I basically followed almost all of the books suggestions, some by my own plans and some by accident.
This book is definitely authored by an all-star cast so I was excited to crack the seal. I liked the sections on employment opportunities and who's hiring. The brief IA overview was definitely necessary. I was also fond of the Laws of Security content. I've never thought about those laws and how true they really are.
When I get time my friend and I plan to use the Creating an Attack Lab content. It was a good collection of theory and tool descriptions.
Overall this book is a good read and even though I've been in the Information Assurance field for over 8 years now I plan to use it as a reference and to build me an attack lab ASAP.
All IA/Infosec newbies should read this....it could have saved me some stress when I was just a noob!
Mark Cavey, CISSP-ISSAP, IAM, IEM, CHS
Senior Computer Network Defense Engineer
InfoSec Career Hacking: Sell Your Skillz, Not Your Soul Overview"InfoSec Career Hacking" starts out by describing the many, different InfoSec careers available including Security Engineer, Security Analyst, Penetration Tester, Auditor, Security Administrator, Programmer, and Security Program Manager. The particular skills required by each of these jobs will be described in detail, allowing the reader to identify the most appropriate career choice for them. Next, the book describes how the reader can build his own test laboratory to further enhance his existing skills and begin to learn new skills and techniques. The authors also provide keen insight on how to develop the requisite soft skills to migrate form the hacker to corporate world.* The InfoSec job market will experience explosive growth over the next five years, and many candidates for these positions will come from thriving, hacker communities * Teaches these hackers how to build their own test networks to develop their skills to appeal to corporations and government agencies * Provides specific instructions for developing time, management, and personal skills to build a successful InfoSec career

Want to learn more information about InfoSec Career Hacking: Sell Your Skillz, Not Your Soul?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

CISO Leadership: Essential Principles for Success ((ISC)2 Press) Review

CISO Leadership: Essential Principles for Success ((ISC)2 Press)
Average Reviews:

(More customer reviews)
Are you looking to buy CISO Leadership: Essential Principles for Success ((ISC)2 Press)? Here is the right place to find the great deals. we can offer discounts of up to 90% on CISO Leadership: Essential Principles for Success ((ISC)2 Press). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

CISO Leadership: Essential Principles for Success ((ISC)2 Press) ReviewThis reference contains good insight and very practical information for a new security professionals or security professionals with less than 8 years in the field. The authors have and had leading positions in the information security field. I liked the way it was written with the different authors giving their perspective and advice. Very good reference.CISO Leadership: Essential Principles for Success ((ISC)2 Press) OverviewCaught in the crosshairs of 'Leadership" and 'Information Technology", Information Security professionals are increasingly tapped to operate as business executives. This often puts them on a career path they did not expect, in a field not yet clearly defined. IT training does not usually includemanagerial skills such as leadership, team-building, communication, risk assessment, and corporate business savvy, needed by CISOs. Yet a lack in any of these areas can short circuit a career in information security.
CISO Leadership: Essential Principles for Success captures years of hard knocks, success stories, and yes, failures. This is not a how-to book or a collection of technical data. It does not cover products or technology or provide a recapitulation of the common body of knowledge. The book delineates information needed by security leaders and includes from-the-trenches advice on how to have a successful career in the field.
With a stellar panel of contributors including William H. Murray, Harry Demaio, James Christiansen, Randy Sanovic, Mike Corby, Howard Schmidt, and other thought leaders, the book brings together the collective experience of trail blazers. The authors have learned through experience-been there, done that, have the t-shirt-and yes, the scars. A glance through the contents demonstrates the breadth and depth of coverage, not only in topics included but also in expertise provided by the chapter authors. They are the pioneers, who, while initially making it up as they went along, now provide the next generation of information security professionals with a guide to success.

Want to learn more information about CISO Leadership: Essential Principles for Success ((ISC)2 Press)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Ethical Hacking and Countermeasures: Attack Phases (EC-Council Certified Ethical Hacker (Ceh)) Review

Ethical Hacking and Countermeasures: Attack Phases (EC-Council Certified Ethical Hacker (Ceh))
Average Reviews:

(More customer reviews)
Are you looking to buy Ethical Hacking and Countermeasures: Attack Phases (EC-Council Certified Ethical Hacker (Ceh))? Here is the right place to find the great deals. we can offer discounts of up to 90% on Ethical Hacking and Countermeasures: Attack Phases (EC-Council Certified Ethical Hacker (Ceh)). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Ethical Hacking and Countermeasures: Attack Phases (EC-Council Certified Ethical Hacker (Ceh)) ReviewCovers many of the tools related to CEH certification, obviously not in a highly-detailed fashion.
There are typos, such as defining availability as "locking data that is in use....". Link to the student resource center leads to a "coming soon" page (to access the supplemental materials available online, use the registration number in the back of the book - access is given for 180 days).
Ethical Hacking and Countermeasures: Attack Phases (EC-Council Certified Ethical Hacker (Ceh)) OverviewThe EC-Council | Press Ethical Hacking and Countermeasures Series is comprised of five books covering a broad base of topics in offensive network security, ethical hacking, and network defense and countermeasures. The content of this series is designed to immerse the reader into an interactive environment where they will be shown how to scan, test, hack and secure information systems. With the full series of books, the reader will gain in-depth knowledge and practical experience with essential security systems, and become prepared to succeed on the Certified Ethical Hacker, or C|EH, certification from EC-Council.This certification covers a plethora of offensive security topics ranging from how perimeter defenses work, to scanning and attacking simulated networks. A wide variety of tools, viruses, and malware is presented in this and the other four books, providing a complete understanding of the tactics and tools used by hackers. By gaining a thorough understanding of how hackers operate, an Ethical Hacker will be able to set up strong countermeasures and defensive systems to protect an organization's critical infrastructure and information.

Want to learn more information about Ethical Hacking and Countermeasures: Attack Phases (EC-Council Certified Ethical Hacker (Ceh))?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Computer Forensics: Incident Response Essentials Review

Computer Forensics: Incident Response Essentials
Average Reviews:

(More customer reviews)
Are you looking to buy Computer Forensics: Incident Response Essentials? Here is the right place to find the great deals. we can offer discounts of up to 90% on Computer Forensics: Incident Response Essentials. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Computer Forensics: Incident Response Essentials ReviewI am a senior engineer for network security operations. I read "Computer Forensics: Incident Response Essentials" (CFIRE) because I am responsible for performing intrusion detection and incident response on a daily basis. Those with similar skills will probably consider CFIRE too basic. Those working outside the information technology world may find CFIRE enlightening.

I'm a graduate of the SANS System Forensics, Investigation, and Response course and have read "Incident Response: Investigating Computer Crime" (IRICC) by Mandia, Prosise, and Pepe. In my opinion, CFIRE does not offer any new or truly significant material. For example, chapter 2 ("Tracking an Offender") offers several pages on how to find the headers in Outlook messages. Elsewhere, one discovers very elementary information on UNIX commands, searching Windows hard drives, and understanding UNIX file systems. All of this appears in other books or is common knowledge for IT staff.

I was disappointed that the impressive reviewer list did not detect several errors. As a fairly young network engineer, I still recognized this mistake on page 32: "When you dial to an ISP with a modem, you might use a layer 3 protocol called Point to Point Protocol (PPP). Referring back to Figure 2-1, layer 3 is the network layer, and in the case of a dial-up connection, PPP replaces IP." Untrue -- PPP is actually a layer 2 protocol; IP is used above PPP. Furthermore, figure 2-1 on page 24 presents numerous problems: NetBEUI spans layers 3 to 5 (not 3 to 4), web browsers and email clients do not belong at layer 7 (they are applications which call layer 7 protocols), and so on. Also, page 121 claims "you cannot delete an alternate stream from the command line." However, page 193 of "Hacking Exposed: Windows 2000" demonstrates how to remove streams.

On the positive side, CFIRE will probably not scare non-IT staff. They will probably find the numerous tables, screen shots, and references useful. This book could be viewed as a gentle introduction to the incident response and forensics field, especially for the Microsoft Windows crowd.

Two types of staff wear "computer forensics" hats. The first type investigate misuse of computers, typically by authorized personnel. This group is happy to know how to image a drive and search the copy for signs of illicit images or software. The second type investigates compromises, where unknown (usually remote) parties have penetrated a network and used machines for their own purposes. This group will be unsatisfied when CFIRE states on page 132 "we don't anticipate that most readers of this book will become this specialized." If you need that deep level of knowledge, read "Incident Response: Investigating Computer Crime."

(Disclaimer: The publisher provided a free review copy.)Computer Forensics: Incident Response Essentials OverviewEvery computer crime leaves tracks—you just have to know where to find them. This book shows you how to collect and analyze the digital evidence left behind in a digital crime scene.Computers have always been susceptible to unwanted intrusions, but as the sophistication of computer technology increases so does the need to anticipate, and safeguard against, a corresponding rise in computer-related criminal activity.Computer forensics, the newest branch of computer security, focuses on the aftermath of a computer security incident. The goal of computer forensics is to conduct a structured investigation to determine exactly what happened, who was responsible, and to perform the investigation in such a way that the results are useful in a criminal proceeding.Written by two experts in digital investigation, Computer Forensics provides extensive information on how to handle the computer as evidence. Kruse and Heiser walk the reader through the complete forensics process—from the initial collection of evidence through the final report. Topics include an overview of the forensic relevance of encryption, the examination of digital evidence for clues, and the most effective way to present your evidence and conclusions in court. Unique forensic issues associated with both the Unix and the Windows NT/2000 operating systems are thoroughly covered.This book provides a detailed methodology for collecting, preserving, and effectively using evidence by addressing the three A's of computer forensics: Acquire the evidence without altering or damaging the original data.Authenticate that your recorded evidence is the same as the original seized data.Analyze the data without modifying the recovered data.Computer Forensics is written for everyone who is responsible for investigating digital criminal incidents or who may be interested in the techniques that such investigators use. It is equally helpful to those investigating hacked web servers, and those who are investigating the source of illegal pornography.0201707195B09052001

Want to learn more information about Computer Forensics: Incident Response Essentials?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security Metrics: Replacing Fear, Uncertainty, and Doubt Review

Security Metrics: Replacing Fear, Uncertainty, and Doubt
Average Reviews:

(More customer reviews)
Are you looking to buy Security Metrics: Replacing Fear, Uncertainty, and Doubt? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security Metrics: Replacing Fear, Uncertainty, and Doubt. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security Metrics: Replacing Fear, Uncertainty, and Doubt ReviewI read Security Metrics right after finishing Managing Cybersecurity Resources, a book by economists arguing that security decisions should be made using cost-benefit analysis. On the face of it, cost-benefit analysis makes perfect sense, especially given the authors' analysis. However, Security Metrics author Andy Jaquith quickly demolishes that approach (confirming the problem I had with the MCR plan). While attacking the implementation (but not the idea) of Annual Loss Expectancy for security events, Jaquith writes on p 33 "[P]ractitioners of ALE suffer from a near-complete inability to reliably estimate probabilities [of occurrence] or losses." Bingo, game over for ALE and cost-benefit analysis. It turns out the reason security managers "herd" (as mentioned in MCR) is that they have no clue what else to do; they seek safety in numbers by emulating peers and then claim that as a defense when they are breached.
Fortunately, Security Metrics offers another solution. The book gives readers three sets of information: theory, metrics, and tools (concepts, not programs). The theory chapters (1 and 2) were so concise yet insightful I was tempted to underline every sentence. (I am not kidding.) Even the Preface made me glad to be reading the book when it associated "security ROI" with "the Macarena" and called it a "needless distraction." I laughed in agreement when I saw Andy call "security enablement" the "Abominable Snowman: it is rarely spotted, but legions of people swear it exists. After all, as my friend Dan geer puts it, 'You don't usually see airlines advertising how their planes fall out of the sky less often than their competitors.'" Why is that? My answer is simple: security is assumed and expected. Advertising anything else has no effect or makes people suspicious. I knew this book would be good.
The metrics chapters probably list hundreds of metrics you can extract verbatim and apply to your own environment. To the reviewer who wanted to reprint them in an appendix: they're called chapters 3 and 4. My main concern with the metrics was the focus on input-centric measurements instead of results. I would have liked to read more metrics on measuring whether security programs are working, rather than what techniques and tools are applied up front.
The tools chapters were helpful to anyone needing a statistics refresher. The visualization sections were especially helpful. (Feel free to dismiss yet another ignorant review from WB, who thinks a "review" means writing a few paragraphs after flipping through the pages of five books a day.) Andy's examples of turning lousy graphs and charts into information visualization vehicles should be followed by all managers.
Security Metrics is strengthened by the many stories from the author's consulting experience. I sensed that his techniques work and are not the product of the thought laboratory alone. I found his "Balanced Scorecard" approach to be interesting, especially to the degree it ties real metrics to business operations.
I had a few issues with terminology, such as using the term "threats" on p 231 when "attacks" is more accurate. (The football analogy is correct, however.) I semi-agreed with the author's suggestion to abandon "risk management" in favor of metrics-based approaches, but I didn't think two pages (4-5) were really enough to make the case. On p 264, threats are not risks, but they help instantiate risks. On pp 78-7, "risk of exploit" should be "ease of exploitation."
These are minor concerns, given the overwhelming concentration of practical and implementation-worthy pieces of information in Security Metrics. You must read this book if you care to measure security progress. Now we need Dan Geer to extend beyond writing wise forewords and articles into the world of his own book!Security Metrics: Replacing Fear, Uncertainty, and Doubt OverviewThe Definitive Guide to Quantifying, Classifying, and Measuring Enterprise IT Security Operations


Security Metrics is the first comprehensive best-practice guide to defining, creating, and utilizing security metrics in the enterprise.

Usingsample charts, graphics, case studies, and war stories, Yankee GroupSecurity Expert Andrew Jaquith demonstrates exactly how to establisheffective metrics based on your organization's unique requirements.You'll discover how to quantify hard-to-measure security activities,compile and analyze all relevant data, identify strengths andweaknesses, set cost-effective priorities for improvement, and craftcompelling messages for senior management.

Security Metrics successfullybridges management's quantitative viewpoint with the nuts-and-boltsapproach typically taken by security professionals. It brings togetherexpert solutions drawn from Jaquith's extensive consulting work in thesoftware, aerospace, and financial services industries, including newmetrics presented nowhere else. You'll learn how to:

• Replace nonstop crisis response with a systematic approach to security improvement
• Understand the differences between "good" and "bad" metrics
•Measure coverage and control, vulnerability management, passwordquality, patch latency, benchmark scoring, and business-adjusted risk
• Quantify the effectiveness of security acquisition, implementation, and other program activities
• Organize, aggregate, and analyze your data to bring out key insights
• Use visualization to understand and communicate security issues more clearly
• Capture valuable data from firewalls and antivirus logs, third-party auditor reports, and other resources
• Implement balanced scorecards that present compact, holistic views of organizational security effectiveness

Whetheryou're an engineer or consultant responsible for security and reportingto management–or an executive who needs better information fordecision-making–Security Metrics is the resource you have been searching for.

Andrew Jaquith, programmanager for Yankee Group's Security Solutions and Services DecisionService, advises enterprise clients on prioritizing and managingsecurity resources. He also helps security vendors develop product,service, and go-to-market strategies for reaching enterprise customers.He co-founded @stake, Inc., a security consulting pioneer acquired bySymantec Corporation in 2004. His application security and metricsresearch has been featured in CIO, CSO, InformationWeek, IEEE Security and Privacy, and The Economist.

Foreword
Preface
Acknowledgments
About the Author
Chapter1 Introduction:Escaping the Hamster Wheel ofPain
Chapter2 Defining SecurityMetrics
Chapter 3 Diagnosing Problems and Measuring Technical Security
Chapter4 Measuring ProgramEffectiveness
Chapter 5 Analysis Techniques
Chapter 6 Visualization
Chapter 7 Automating Metrics Calculations
Chapter 8 Designing Security Scorecards
Index




Want to learn more information about Security Metrics: Replacing Fear, Uncertainty, and Doubt?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Metasploit: The Penetration Tester's Guide Review

Metasploit: The Penetration Tester's Guide
Average Reviews:

(More customer reviews)
Are you looking to buy Metasploit: The Penetration Tester's Guide? Here is the right place to find the great deals. we can offer discounts of up to 90% on Metasploit: The Penetration Tester's Guide. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Metasploit: The Penetration Tester's Guide ReviewIt's nice when a book not only delivers on its stated objective, but it also opens my eyes to a better understanding of a related subject. Metasploit: The Penetration Tester's Guide by David Kennedy, Jim O'Gorman, Devon Kerns, and Mati Aharoni falls solidly into that class. In addition to learning how I can use Metasploit for network penetration testing, I also saw just how easy it is for someone to compromise a system with very little effort or knowledge. You can never rest when it comes to network and system security.
Contents:
Introduction; The Absolute Basics of Penetration Testing; Metasploit Basics; Intelligence Gathering; Vulnerability Scanning; The Joy of Exploitation; Meterpreter; Avoiding Detection; Exploitation Using Client-Side Attacks; Metasploit Auxiliary Modules; The Social-Engineer Toolkit; Fast-Track; Karmetasploit; Building Your Own Module; Creating Your Own Exploits; Porting Exploits to the Metasploit Framework; Meterpreter Scripting; Simulated Penetration Testing; Configuring Your Target Machines; Cheat Sheet; Index
The authors set an ambitious goal in trying to write a book that is useful for both beginners and experienced users of Metasploit. Usually that means that neither side ends up being happy. I can say as a member of the beginner group, I can say they were successful on that end of the scale. There's a fine balance between step-by-step hand holding and the assumption that the reader already knows everything. After an introduction to a structured approach to penetration testing, they start to cover the basics of how someone might use Metasploit to probe a network, gather information on potential attack vectors, and then exploit those potential weaknesses. The major features are covered as opposed to trying to write about every last setting, so the material doesn't bog down in minutia. It's also nice that they set up a fictional penetration test scenario, and follow it through the different chapters. It makes for good continuity. As the book progresses, the emphasis moves towards creating your own modules to run within the Metasploit framework. Not every tester will need or want to go that route, but it's a reminder of how flexible this tool can be.
The bonus of this book was realizing how easy it is to launch various attacks without much effort. I guess I really hadn't thought through what would be necessary to set up phishing attacks, either by sending infected documents or setting up a fake site to collect personal information. With Metasploit, it's nothing more than selecting some options and running the tool. You can argue whether Metasploit is a good or bad thing depending on who is using it, but it's a certainty that this type of behavior will exist and happen regardless. By writing this book, the authors have helped even the playing field between the black hats and the white hats.
Metasploit: The Penetration Tester's Guide is a book that should be on the shelf of any serious computer security professional. And if you're just starting to dabble in the world of network security, this is a great resource to start your journey.
Disclosure:
Obtained From: Publisher
Payment: FreeMetasploit: The Penetration Tester's Guide Overview"The best guide to the Metasploit Framework." -HD Moore, Founder of the Metasploit Project
The Metasploit Framework makes discovering, exploiting, and sharing vulnerabilities quick and relatively painless. But while Metasploit is used by security professionals everywhere, the tool can be hard to grasp for first-time users. Metasploit: The Penetration Tester's Guide fills this gap by teaching you how to harness the Framework and interact with the vibrant community of Metasploit contributors.

Once you've built your foundation for penetration testing, you'll learn the Framework's conventions, interfaces, and module system as you launch simulated attacks. You'll move on to advanced penetration testing techniques, including network reconnaissance and enumeration, client-side attacks, wireless attacks, and targeted social-engineering attacks.

Learn how to:

Find and exploit unmaintained, misconfigured, and unpatched systems
Perform reconnaissance and find valuable information about your target
Bypass anti-virus technologies and circumvent security controls
Integrate Nmap, NeXpose, and Nessus with Metasploit to automate discovery
Use the Meterpreter shell to launch further attacks from inside the network
Harness standalone Metasploit utilities, third-party tools, and plug-ins
Learn how to write your own Meterpreter post exploitation modules and scripts

You'll even touch on exploit discovery for zero-day research, write a fuzzer, port existing exploits into the Framework, and learn how to cover your tracks. Whether your goal is to secure your own networks or to put someone else's to the test, Metasploit: The Penetration Tester's Guide will take you there and beyond.


Want to learn more information about Metasploit: The Penetration Tester's Guide?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...