Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Administering Windows Vista Security: The Big Surprises Review

Administering Windows Vista Security: The Big Surprises
Average Reviews:

(More customer reviews)
Are you looking to buy Administering Windows Vista Security: The Big Surprises? Here is the right place to find the great deals. we can offer discounts of up to 90% on Administering Windows Vista Security: The Big Surprises. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Administering Windows Vista Security: The Big Surprises ReviewHaving spoken at various Microsoft events on Windows Vista security, I have been looking for a comprehensive and deep book to recommend to IT administrators. I recently went through all of the Vista books listed in the bookstore looking for anything that called out Address Space Layout Randomization (ASLR) and Mandatory Integrity Control (MIC) in the index. Mark's book was the only one that even mentioned these topics.
Upon reading the book, not only does the book call out all of these topics, but it also explains them in great detail. Additionally real world examples are provided to demonstrate the new security features that are included with Windows Vista. It is one thing to be able to discuss the features, much as the whitepapers do, it is another thing to be able to show people examples of how these features actually work within the product. Mark further goes on to probe the product for unintended uses of the security features providing insightful information as to how Windows Vista security can and cannot be used. As an example, Mark's investigation of providing ACE's based on integrity level.
Overall I found this book to be the most thorough review of what has changed in the Windows Vista (and in the future Longhorn) security model. It was a great read with great examples and I highly recommend it to anyone interested in the topic.Administering Windows Vista Security: The Big Surprises OverviewAn Inside Look at Windows Vista Security for Systems AdministratorsGet an early start on Windows Vista security and the technology shifts you'll need to know as a systems administrator. From leading Windows expert Mark Minasi comes this "just-in-time" book to get you there. This targeted, hands-on guide takes a rapid-fire approach to the biggest security changes and how they'll affect business as usual for those who must integrate and provide technical support for Windows Vista. You'll find practical instruction, tips, workarounds, and much more.* Work through a slew of Vista surprises, such as logging on as Administrator and how to re-enable Run* Discover how virtualization works--and where it doesn't* Find out why you can no longer delete files in System32, even though you are an Administrator* Get familiar with new post-boot security features such as PatchGuard* Protect laptops to the max with the innovative BitLocker feature* Meet the new Windows Integrity mechanism* Explore the revamped Event Viewer, event forwarding, and new troubleshooting toolsGo above and beyond what you've heard about VistaDiscover the changes to Share and Registry AccessCatch up on all the encryption news and servicesTry out Vista Remote Desktop with its enhanced securityAbout the SeriesThe Mark Minasi Windows Administrator Library equips system administrators with in-depth technical solutions to the many challenges associated with administering Windows in an enterprise setting. Series editor Mark Minasi, a leading Windows expert, not only selects the topics and authors, he also develops each book to meet the specific needs and goals of systems administrators, MIS professionals, help-desk personnel, and corporate programmers.

Want to learn more information about Administering Windows Vista Security: The Big Surprises?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Pro PHP XML and Web Services Review

Pro PHP XML and Web Services
Average Reviews:

(More customer reviews)
Are you looking to buy Pro PHP XML and Web Services? Here is the right place to find the great deals. we can offer discounts of up to 90% on Pro PHP XML and Web Services. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Pro PHP XML and Web Services ReviewThis is first and foremost an XML reference. The author takes the reader through over 100 pages XML background in the first three chapters, then an overview of a few utilities like XPath and XPointer before he touches on PHP. Having provided some grounding in the basics, he then proceeds to develop the use of XML in PHP from the basic topics of DOM (Document Object Model) and XSLT (Extensible Stylesheet Language Transformations) to the more advanced topics of SOAP (Simple Object Access Protocol) and web services.
Along the way Richards introduces the reader to utility classes like SimpleXML, SAX (Simple API for XML), XMLReader. He also touches on PEAR (PHP Extension and Application Repository) utility classes and topics like security, RSS (Really Simple Syndication) and UDDI (Universal Description, Discovery and Integration). The author's examples are reasonably concise and readable; making the necessary points without getting carried away.
The bottom line is that this is a highly effective reference (that means fairly comprehensive, but dry reading; I read cover to cover, but it was relatively tedious) on XML and its varied uses in association with PHP. This is not a book for the newcomer to programming, nor is it a cookbook for examples for the casual programmer/web developer, although the author does provide PEAR examples for connecting with major web services like Amazon, Google and Yahoo (among others). My suggestion for readers is to review what you need of the first 11-12 chapters to ensure a firm grounding in XML, and then hop to the chapters specific to the problem being faced.
P-)Pro PHP XML and Web Services Overview
Pro PHP XML and Web Services is the authoritative guide to using the XML features of PHP 5 and PHP 6. No other book covers XML and Web Services in PHP as deeply as this title. The first four chapters introduce the core concepts of XML required for proficiency, and will bring you up to speed on the terminology and key concepts you need to proceed with the rest of the book. Next, the book explores utilizing XML and Web Services with PHP5. Topics include DOM, SimpleXML, SAX, xmlReader, XSLT, RDF, RSS, WDDX, XML-RPC, REST, SOAP, and UDDI.

Author Robert Richards, a major contributor to the PHP XML codebase, is a leading expert in the PHP community. In this book, Richards covers all topics in depth, blending theory with practical examples. You'll find case studies for the most popular web services like Amazon, Google, eBay, and Yahoo. The book also covers XML capabilities, demonstrated through informative examples, in the PEAR libraries.

Table of Contents
Introduction to XML and Web Services
XML Structure
Validation
XPath, XPointer, XInclude, and the Future
PHP and XML
Document Object Model (DOM)
SimpleXML
Simple API for XML (SAX)
XMLReader
Extensible Stylesheet Language Transformations (XSLT)
Effective and Efficient Processing
XML Security
PEAR and XML
Content Syndication: RSS and Atom
Web Distributed Data Exchange (WDDX)
XML-RPC
Representational State Transfer (REST)
SOAP
Universal Description, Discovery, and Integration (UDDI)
PEAR and Web Services
Other XML Technologies and Extensions


Want to learn more information about Pro PHP XML and Web Services?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Dissecting the Hack: The F0rb1dd3n Network Review

Dissecting the Hack: The F0rb1dd3n Network
Average Reviews:

(More customer reviews)
Are you looking to buy Dissecting the Hack: The F0rb1dd3n Network? Here is the right place to find the great deals. we can offer discounts of up to 90% on Dissecting the Hack: The F0rb1dd3n Network. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Dissecting the Hack: The F0rb1dd3n Network ReviewLet me get this out of the way: If books could be reviewed as "first effort" this would be a five/five. For a really ambitious book out of the gate it does a decent job of hitting tons of domains from multiple angles to inform, excite, and influence the thought processes of the reader.
To be even more honest had I thumbed through this book before buying it I would not have bought it. A lot of alarms can go off when you see pictures of vendor equipment, tables of network services, and a touch of conspiracy theory in places. Not that those things are inherently bad but it's only a 400 page tome so that's a lot of real estate to be worried about misusing. The authors use those pages as well as can be expected and in a way that even the most jaded readers should be able to ~respect~ if not always appreciate.
I'm not being hard on this book, trust me. It's now the third book, along with Silence on the Wire, and Anderson's Security Engineering, I expect all newer ITSec professionals to read early and often. I don't judge a non-textbook by the accuracy or timeliness of every statement. Or the quality of the story telling or case studied. I judge these types of books by their ability to affect ~thought processes~, ~perspective~, and ~risk analysis~... and I think this book is a winner on all three counts. It is all about influencing thought, not hand-feeding PRECISE EXACTING and ultimately useless step-by-step hacks.
Solid 4/4.5 star on any scale and a 5/5 for a new set of authors. I hope the editors and publisher give them the opportunity to add about 120/150 pages and build a community. One last note, the books and resources noted within this book are good stand-up lists and should not be overlooked either. The single paragraph stories from the web or people profiles are not to be skipped over.Dissecting the Hack: The F0rb1dd3n Network Overview
Dissecting the Hackis one heck of a ride! Hackers, IT professionals, and Infosec aficionados will find a gripping story that takes the reader on a global trip through the world of computer security exploits. One half massive case study, one half technical manual, Dissecting the Hack has it all - learn all about hacking tools and techniques and how to defend your network against threats.

Yes, the security threats are real - read more about the tactics that you see executed throughout the story in the second half of the book where you will learn to recon, scan, explore, exploit and expunge with the tools and techniques shown in the story. Every hack is real and can be used by you once you have the knowledge within this book!

Utilizes actual hacking and security tools in its story- helps to familiarize a newbie with the many devices and their code
Introduces basic hacking techniques in real life context for ease of learning
Presented in the words of the hacker/security pro, effortlessly envelops the beginner in the language of the hack


Want to learn more information about Dissecting the Hack: The F0rb1dd3n Network?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Defense and Detection Strategies against Internet Worms Review

Defense and Detection Strategies against Internet Worms
Average Reviews:

(More customer reviews)
Are you looking to buy Defense and Detection Strategies against Internet Worms? Here is the right place to find the great deals. we can offer discounts of up to 90% on Defense and Detection Strategies against Internet Worms. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Defense and Detection Strategies against Internet Worms Review(...)
It is not very common to see an unusual security book nowadays as many authors cover every subject. However, such sexy subject as worms, did not, in my opinion, receive adequate coverage. This book does fill this important niche effectively!
It starts from motivation sections that, if not exciting, provide a good intro and immerses the reader into the subject and how to approach it (worm analysis principles).
It then goes into: five worm components: reconnaissance, attack, communication, command, intelligence. Lots of nice details on all worm activities are in there. One of the book's advantages is author's clear writing style, easy and enjoyable to read, even if you know the subject already.
Worm traffic is the highlight of the book as well as trends and infection patterns. Traffic analysis (linked to worm traffic patterns) is described from the basics and lab setup to advanced worm hunting. The techniques include volume monitoring, new scans/sweeps, change in traffic for some systems, etc.
Worm history and taxonomy are also discussed. Also, worm internals and worm construction are covered in great detail. Worm detection goes beyond traffic analysis to honeypots and black hole monitor as well as signatures detection.

Of course, the worm book can't be complete without defenses. The defenses go beyond worms to all malware and are classified into network and host defenses, as well as counterattacking the worm population and networks.
Future worms - as usual - is the most exciting part. Overall, the book is fun and useful (in my opinion) for both researchers and practitioners. Among its negative sides I can only list its relatively high price.
(...)Defense and Detection Strategies against Internet Worms OverviewFocusing exclusively on Internet worms, this book offers you solid worm detection and mitigation strategies for your work in the field. This ground-breaking volume enables you to put rising worm trends into perspective with practical information in detection and defence techniques utilizing data from live networks, real IP addresses and commercial tools. It helps you understand the classifications and groupings of worms, and offers a deeper understanding of how they threaten network and system security. After examining how a worm is constructed and how its major life cycle steps are implemented, the book scrutinizes targets that worms have attacked over the years and the likely targets of the immediate future. Moreover, this reference explains how to detect worms using a variety of mechanisms and evaluates the strengths and weaknesses of three approaches - traffic analysis, honeypots and dark network monitors, and signature analysis. The book concludes with a discussion of four effective defences against network worms, including host-based defences, network firewalls and filters, application layer proxies, and a direct attack on the worm network itself.

Want to learn more information about Defense and Detection Strategies against Internet Worms?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Configuring IPCop Firewalls: Closing Borders with Open Source: How to setup, configure and manage your Linux firewall, web proxy, DHCP, DNS, time ... VPN with this powerful Open Source solution Review

Configuring IPCop Firewalls: Closing Borders with Open Source: How to setup, configure and manage your Linux firewall, web proxy, DHCP, DNS, time ... VPN with this powerful Open Source solution
Average Reviews:

(More customer reviews)
Are you looking to buy Configuring IPCop Firewalls: Closing Borders with Open Source: How to setup, configure and manage your Linux firewall, web proxy, DHCP, DNS, time ... VPN with this powerful Open Source solution? Here is the right place to find the great deals. we can offer discounts of up to 90% on Configuring IPCop Firewalls: Closing Borders with Open Source: How to setup, configure and manage your Linux firewall, web proxy, DHCP, DNS, time ... VPN with this powerful Open Source solution. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Configuring IPCop Firewalls: Closing Borders with Open Source: How to setup, configure and manage your Linux firewall, web proxy, DHCP, DNS, time ... VPN with this powerful Open Source solution ReviewI use IPCop at a 30 users network. We also route specific applications through different T1 connections, and have plenty of custom iptables rules.
IPCop per se is a great product.
I can't say the book is bad but it does not add any substantial information to the documentation you can find at IPCop site and download for free.
Buy it only if you want to pay for freely available documentation or if you are a book bluff.Configuring IPCop Firewalls: Closing Borders with Open Source: How to setup, configure and manage your Linux firewall, web proxy, DHCP, DNS, time ... VPN with this powerful Open Source solution OverviewThis book is an easy-to-read guide to using IPCop in a variety of different roles within the network. The book is written in a very friendly style that makes this complex topic easy and a joy to read. It first covers basic IPCop concepts, then moves to introduce basic IPCop configurations, before covering advanced uses of IPCop. This book is for both experienced and new IPCop users. Anyone interested in securing their networks with IPCop - from those new to networking and firewalls, to networking and IT Professionals with previous experience of IPCop. No knowledge of Linux or IPCop is required.

Want to learn more information about Configuring IPCop Firewalls: Closing Borders with Open Source: How to setup, configure and manage your Linux firewall, web proxy, DHCP, DNS, time ... VPN with this powerful Open Source solution?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Information Security Management Handbook, Sixth Edition (Isc2 Press) Review

Information Security Management Handbook, Sixth Edition (Isc2 Press)
Average Reviews:

(More customer reviews)
Are you looking to buy Information Security Management Handbook, Sixth Edition (Isc2 Press)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Information Security Management Handbook, Sixth Edition (Isc2 Press). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Information Security Management Handbook, Sixth Edition (Isc2 Press) ReviewIf your goal is to pass the CISSP exam, this book may help, but there are better books out there. If your goal is to actually dig deep into the security domains, this book contains a vast collection of security related topics that may help you reach that goal.
I gave it a 2 star because I was disappointed at the number of errors and omissions I discovered in this book, for example chapter 4 has 4 dates for ITGI's begining which are all wrong, Chapter 8 has the correct date. as matter of fact if I was the editor of the book, I would remove the entire chapter 4. I was happy to see Kevin Henry bring up the "placement of security" but he does not take it far enough. So chapter 14 we are back to "IT" based information security. I think it is time for security experts to start writing outside the box, most companies have confidential information that is not "IT" related, take contracts as an example.
Chapter 76 "Intrusion in information system security simply means the attempts or actions of unauthorized entry into an IT system. " really!, this is 1990's way of thinking Gildas Deograt-Lumy Roy Naldo Please read The Art of Intrusion by Kevin D. Mitnick.
I would write a book describing all that is wrong with this book, only if I had the time and writing skills some of which was wasted reading this book, Oh by the way Mr.Ralph Spencer Poore, there are so many exciting new standards coming up with cryptographic key management you should have and could have written about, such as the 1619.3, but I guess I have to read yet another book to learn about it.
Information Security Management Handbook, Sixth Edition (Isc2 Press) OverviewConsidered the gold-standard reference on information security, the Information Security Management Handbookprovides an authoritative compilation of the fundamental knowledge, skills, techniques, and tools required of today's IT security professional. Now in its sixth edition, this 3200 pagestand-alone reference is organized under the CISSP Common Body of Knowledgedomains and has beenupdated yearly.Volumes 2,3, andthis year's Volume 4 reflect thechanges to the CBK in response to new laws and evolving technology.

Want to learn more information about Information Security Management Handbook, Sixth Edition (Isc2 Press)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts Review

Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts
Average Reviews:

(More customer reviews)
Are you looking to buy Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts ReviewThis is a rather short (Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts Overview
It's no longer just a buzz word: "Security" is an important part of your job as a Systems Administrator. Most security books are aimed at security professionals, but Security for System Administrators is written for System Administrators. This book covers the basics of securing your system environment as well as security concepts and how these concepts can be implemented practically using common tools and applications. Whether you are new to this profession or have been in the field a while, you'll find valuable information in each chapter. The book's examples will focus on Windows Server 2008 R2 and Windows 7, but many concepts are platform agnostic.

Take all the confusion out of security including: network attacks, system failures, social networking, and even audits
Learn how to apply and implement general security concepts
Identify and solve situations within your network and organization


Want to learn more information about Security for Microsoft Windows System Administrators: Introduction to Key Information Security Concepts?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security Architecture: Design, Deployment and Operations Review

Security Architecture: Design, Deployment and Operations
Average Reviews:

(More customer reviews)
Are you looking to buy Security Architecture: Design, Deployment and Operations? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security Architecture: Design, Deployment and Operations. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security Architecture: Design, Deployment and Operations ReviewBoeing Aircraft is currently working on its next big airplane, the Sonic Cruiser. But even before a prototype of the Sonic Cruiser takes to the skies, tens of thousands of hours will have been spent on design, planning, testing, legal, administrative, and other tasks.
The product development scenario for information technology and information security is radically different. Corporate networks are being rolled out with planning and design that is not on par with that of our counterparts in the aviation and construction industries. In fact, already complex corporate networks are continuously becoming more byzantine. Take an average MIS department and add up all their hardware vendors, network topologies and protocols, operating systems, software add-ons, and custom-written applications. Now try to securely integrate them. If security was not designed into the original system architecture, how can these security products be expected to work? Despite the fact that companies are spending more and more money on information systems security, the systems are growing more and more complex -- and complex systems are much harder to protect.
Security Architecture: Design, Deployment and Operations, is intended to help readers design and deploy better security technologies. The authors believe that security architecture must be comprehensive, because a network that is 98% secure is actually 100% insecure. This is especially true, given that -- contrary to popular belief -- information security is not a pure science, but a mixture of art and science.
Effective information security must encompass every aspect of the enterprise. Security Architecture shows how to design a secure infrastructure. It addresses all of the major security products and provides details on how to deploy them.
The authors incisively write that it is not enough for security professionals to understand the theory behind information security; unless they are able to insert security controls in the proper places within an application (data flows, storage and processing), the security solution will not be effective. A security product that is implemented incorrectly is like medicine that is taken improperly: great in potential, but futile in reality.
In addition, if the inserted security solution is not managed with the proper processes in place (e.g., change management, separation of duties, notification, and escalation), the level of security provided will degrade with time until the control becomes ineffective.
The book covers all of the fundamentals of information security. Particularly noteworthy is Chapter 3, "Information Classification and Access Control Plan." As companies place more of their corporate data jewels on often-untrusted public networks, the lack of an information classification scheme can have significant negative security consequences. Also, access control is critical in that many organizations -- and even the media -- are busy obsessing about remote hackers from foreign countries and have become oblivious to the real threats to information security: insiders. While it is much more romantic to think about foreigners hacking into your system in the middle of the night, the reality is that most breaches occur via insiders during normal business hours.
The authors of Security Architecture discuss the elements needed to design and deploy effective information security architecture. Critical security products such as PKI, firewalls, VPN, IDS, and others are discussed, but cryptographic accelerators are not mentioned.
This book highlights best practices and security standards and guidelines for effectively securing an enterprise. The book is well organized and easy to read. Many chapters have additional references and URL's for further research.
The inclusion of numerous case studies, combined with the authors' real-world experience, makes Security Architecture a valuable reference. No one would ever want to get on a plane that had not been properly designed and tested. Neither should we want to use networks that have not been adequately designed and tested from a security standpoint. Security Architecture is intended to make sure that doesn't happen.Security Architecture: Design, Deployment and Operations OverviewWill more than 1.3 trillion dollars expected to be spent via e-business on the Internet by 2003, security has never been more important. This title offers a practical, step-by-step approach, and shows how to design and deploy security sucessfully across the enterprise.

Want to learn more information about Security Architecture: Design, Deployment and Operations?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

InfoSec Career Hacking: Sell Your Skillz, Not Your Soul Review

InfoSec Career Hacking: Sell Your Skillz, Not Your Soul
Average Reviews:

(More customer reviews)
Are you looking to buy InfoSec Career Hacking: Sell Your Skillz, Not Your Soul? Here is the right place to find the great deals. we can offer discounts of up to 90% on InfoSec Career Hacking: Sell Your Skillz, Not Your Soul. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

InfoSec Career Hacking: Sell Your Skillz, Not Your Soul ReviewI enjoyed reading this book and I kept thinking to myself, "I wished this book would have existed when I tried to break into Information Security/Information Assurance. So far I've had a pretty successful IA career and as I read each chapter of the book I realized that I basically followed almost all of the books suggestions, some by my own plans and some by accident.
This book is definitely authored by an all-star cast so I was excited to crack the seal. I liked the sections on employment opportunities and who's hiring. The brief IA overview was definitely necessary. I was also fond of the Laws of Security content. I've never thought about those laws and how true they really are.
When I get time my friend and I plan to use the Creating an Attack Lab content. It was a good collection of theory and tool descriptions.
Overall this book is a good read and even though I've been in the Information Assurance field for over 8 years now I plan to use it as a reference and to build me an attack lab ASAP.
All IA/Infosec newbies should read this....it could have saved me some stress when I was just a noob!
Mark Cavey, CISSP-ISSAP, IAM, IEM, CHS
Senior Computer Network Defense Engineer
InfoSec Career Hacking: Sell Your Skillz, Not Your Soul Overview"InfoSec Career Hacking" starts out by describing the many, different InfoSec careers available including Security Engineer, Security Analyst, Penetration Tester, Auditor, Security Administrator, Programmer, and Security Program Manager. The particular skills required by each of these jobs will be described in detail, allowing the reader to identify the most appropriate career choice for them. Next, the book describes how the reader can build his own test laboratory to further enhance his existing skills and begin to learn new skills and techniques. The authors also provide keen insight on how to develop the requisite soft skills to migrate form the hacker to corporate world.* The InfoSec job market will experience explosive growth over the next five years, and many candidates for these positions will come from thriving, hacker communities * Teaches these hackers how to build their own test networks to develop their skills to appeal to corporations and government agencies * Provides specific instructions for developing time, management, and personal skills to build a successful InfoSec career

Want to learn more information about InfoSec Career Hacking: Sell Your Skillz, Not Your Soul?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Implementing NAP and NAC Security Technologies: The Complete Guide to Network Access Control Review

Implementing NAP and NAC Security Technologies: The Complete Guide to Network Access Control
Average Reviews:

(More customer reviews)
Are you looking to buy Implementing NAP and NAC Security Technologies: The Complete Guide to Network Access Control? Here is the right place to find the great deals. we can offer discounts of up to 90% on Implementing NAP and NAC Security Technologies: The Complete Guide to Network Access Control. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Implementing NAP and NAC Security Technologies: The Complete Guide to Network Access Control ReviewDisclaimer:
I was asked to read a pre-release copy of the book, my quote made it onto the book, and I was given a review copy.
I found myself in a position to learn about the different types of NAC appliances as well as Mobile NAC. The problem is that I don't work for a NAC vendor or install NACs for a living. Googling left me with tons of vendor hype on NAC but not a lot of good information to help me understand the different type of NACs, how they work, and why I would would choose one type over the other. Dan Hoffman's book is the only NAC book I know of that is (mostly) vendor neutral. The only other NAC/NAP books I know of are Cisco Press book which obviously tout Cisco products as the best way to go. Dan Hoffman breaks down the functionality of NAC and they different types of NAC solutions into simple easy to understand language, just like he did for Blackjacking on mobile threats. He has a great knack for explaining technical systems and topics in an easy to understand way.
Here is a list of what he covers in the book:
CH1 Understanding Terms and Technologies
CH2 The Technical Components of NAC Solutions
CH3 What Are You Trying to Protect?
CH4 Understanding the Need for LAN-Based NAC/NAP
CH5 Understanding the Need for Mobile NAC
CH6 Understanding Cisco Clean Access
CH7 Understanding Cisco Network Admission Control Framework
CH8 Understanding Fiberlink Mobile NAC
CH9 Understanding Microsoft NAP Solutions
CH10 Understanding NAC and NAP in Other Products
My favorite chapters are CH3 "What Are You Trying to Protect?", CH4 "Understanding the Need for LAN-Based NAC/NAP", and CH5 "Understanding the Need for Mobile NAC."
By far the most important chapter is chapter three where Dan walks through the questions an organization needs to ask itself before it purchases a NAC solution. The company needs to know if they are trying to protect LAN based or Mobile assets and they need to know exactly what they are trying to protect the answer from the first question against. Dan discusses the various scenarios that come about from those two questions and the two follow on chapters provide even more detail on how the two types of solutions (LAN based and Mobile NAC) work and how they differ from one another. Chapter two covers the details of the different parts of NAC and Chapters 6-10 give some of the specifics about different NAC vendor's solutions (not a complete list).
The only thing I didn't like about the book was that it really didn't cover bypassing NAC. It would have been nice to see some content on how NAC is currently being bypassed or what NAC doesn't protect against and how to mitigate against it.Implementing NAP and NAC Security Technologies: The Complete Guide to Network Access Control OverviewThis guide presents real-world hacking scenarios along with complete implementation guidance for the right NAP/NAC solution, so you can understand which solution makes the most sense based upon the most prevalent risks in your environment. Follow the actual steps hackers take to perform specific exploits, determine which security solutions will stop the exploits from happening, and learn all about the standard components of any NAP/NAC solution. By learning to analyze a security posture, set policies for device analysis, and communicate with the device, you?ll be able to take action.

Want to learn more information about Implementing NAP and NAC Security Technologies: The Complete Guide to Network Access Control?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Information Security Management Handbook, Sixth Edition, Volume 2 Review

Information Security Management Handbook, Sixth Edition, Volume 2
Average Reviews:

(More customer reviews)
Are you looking to buy Information Security Management Handbook, Sixth Edition, Volume 2? Here is the right place to find the great deals. we can offer discounts of up to 90% on Information Security Management Handbook, Sixth Edition, Volume 2. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Information Security Management Handbook, Sixth Edition, Volume 2 ReviewThe book has a particularly good summary of phishing. Explaining the main attack methods used by phishers to trick users into divulging sensitive financial data about themselves.
It also goes into how phishers use compromised computers to inject their messages into the net. The reader should note that in most cases, these computers are not the targets of the bad phishing links inside the messages. So one lesson is that we must expect that phishers will always be able to disseminate messages.
The countermeasures are given. For a far more extensive discussion, check out Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft. However, neither book has made the conceptual leap to using Partner Lists and custom tags inside real messages from banks.Information Security Management Handbook, Sixth Edition, Volume 2 OverviewA compilation of the fundamental knowledge, skills, techniques, and tools require by all security professionals, Information Security Handbook, Sixth Edition sets the standard on which all IT security programs and certifications are based. Considered the gold-standard reference of Information Security, Volume 2 includes coverage of each domain of the Common Body of Knowledge, the standard of knowledge required by IT security professionals worldwide. In step with the lightening-quick, increasingly fast pace of change in the technology field, this book is updated annually, keeping IT professionals updated and current in their field and on the job.

Want to learn more information about Information Security Management Handbook, Sixth Edition, Volume 2?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Applied Oracle Security: Developing Secure Database and Middleware Environments Review

Applied Oracle Security: Developing Secure Database and Middleware Environments
Average Reviews:

(More customer reviews)
Are you looking to buy Applied Oracle Security: Developing Secure Database and Middleware Environments? Here is the right place to find the great deals. we can offer discounts of up to 90% on Applied Oracle Security: Developing Secure Database and Middleware Environments. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Applied Oracle Security: Developing Secure Database and Middleware Environments ReviewThis is an excellent part 2 book for anyone looking to understand the overall Oracle security architecture. The book is easy to read and understand. Has plenty of examples that improved my understanding of the concept being discussed. I was happy that it didn't repeat the content of Knox's first book (Effective Security by Design) and was intentionally written to take the reader onto the next level of learning Oracle security. Would recommend this to any DBA and application server administrator.Applied Oracle Security: Developing Secure Database and Middleware Environments Overview
Cutting-edge techniques from leading Oracle security experts

This Oracle Press guide demonstrates practical applications of the most compelling methods for developing secure Oracle database and middleware environments. You will find full coverage of the latest and most popular Oracle products, including Oracle Database and Audit Vaults, Oracle Application Express, and secure Business Intelligence applications.
Applied Oracle Security demonstrateshow to build and assemble the various Oracle technologies required to create the sophisticated applications demanded in today's IT world. Most technical references only discuss a single product or product suite. As such, there is no roadmap to explain how to get one product, product-family, or suite to work with another. This book fills that void with respect to Oracle Middleware and Database products and the area of security.

Want to learn more information about Applied Oracle Security: Developing Secure Database and Middleware Environments?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

MCSE Self-Paced Training Kit (Exam 70-298): Designing Security for a Microsoft® Windows Server(TM) 2003 Network Review

MCSE Self-Paced Training Kit (Exam 70-298): Designing Security for a Microsoft® Windows Server(TM) 2003 Network
Average Reviews:

(More customer reviews)
Are you looking to buy MCSE Self-Paced Training Kit (Exam 70-298): Designing Security for a Microsoft® Windows Server(TM) 2003 Network? Here is the right place to find the great deals. we can offer discounts of up to 90% on MCSE Self-Paced Training Kit (Exam 70-298): Designing Security for a Microsoft® Windows Server(TM) 2003 Network. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

MCSE Self-Paced Training Kit (Exam 70-298): Designing Security for a Microsoft® Windows Server(TM) 2003 Network ReviewThe purpose of this book is not to teach you the technical aspects of security in Active Directory, rather to teach you best security practices in use and deployment of this technology. The 70-298 exam should be one of the last you on the MCSE track. Microsoft assumes that you have already taken your workstation and core 4 exams by the time you get to this one.
That said, the book is helpful but not comprehensive, in helping you prepare for this exam from a CONCEPTUAL, not technical perspective.MCSE Self-Paced Training Kit (Exam 70-298): Designing Security for a Microsoft® Windows Server(TM) 2003 Network Overview
Ace your preparation for the skills measured by MCP Exam 70-298-and on the job-with this official Microsoft study guide. Work at your own pace through a system of lessons, practice exercises, and design activities.

The Readiness Review Suite on CD, featuring advanced technology from MeasureUp, provides 300 challenging questions for in-depth self-assessment and practice. You can choose timed or untimed testing mode, generate random tests, or focus on specific objectives. You get detailed explanations for right and wrong answers-including a customized learning path that describes how and where to focus your studies.

Maximize your performance on the exam by learning how to:

Document the impact of business and technical constraints on the security design process

Create a security design for:

Logical infrastructure
Network infrastructure for physical security
Network management and maintenance
Basic network functions
Wireless networks and Web servers

Readiness Review Suite on CD Powered by MeasureUp

Your kit includes:

NEW-Fully reengineered self-paced study guide with expert exam tips.
NEW-Readiness Review Suite featuring 300 questions and multiple testing options.
NEW-Practice exercises and design activities for real-world expertise.
NEW-180-day evaluation version of Windows Server 2003, Enterprise Edition.
NEW-eBook in PDF format.
NEW-Microsoft Encyclopedia of Security eBook.
Microsoft Encyclopedia of Networking, Second Edition eBook.

A Note Regarding the CD or DVD

The print version of this book ships with a CD or DVD. For those customers purchasing one of the digital formats in which this book is available, we are pleased to offer the CD/DVD content as a free download via O'Reilly Media's Digital Distribution services. To download this content, please visit O'Reilly's web site, search for the title of this book to find its catalog page, and click on the link below the cover image (Examples, Companion Content, or Practice Files). Note that while we provide as much of the media content as we are able via free download, we are sometimes limited by licensing restrictions. Please direct any questions or concerns to booktech@oreilly.com.


Want to learn more information about MCSE Self-Paced Training Kit (Exam 70-298): Designing Security for a Microsoft® Windows Server(TM) 2003 Network?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

CompTIA Security+ 2008 In Depth Review

CompTIA Security+ 2008 In Depth
Average Reviews:

(More customer reviews)
Are you looking to buy CompTIA Security+ 2008 In Depth? Here is the right place to find the great deals. we can offer discounts of up to 90% on CompTIA Security+ 2008 In Depth. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

CompTIA Security+ 2008 In Depth ReviewI used this as a third resource for the exam, after the Sybex Security+ Study Guide and the Security+ All-In-One book Passed 855/900).
This volume is slightly more current than the other two and provides useful supplemental material. I do not believe that it can be used as the only resource to pass the exam, your mileage may vary.
Good visual layout, easy reading. Very brief review section at the end of each chapter. No supplemental CDROM.CompTIA Security+ 2008 In Depth Overview"CompTIA Security+ 2008 In Depth" gives you the coverage you need to pass CompTIA's latest Security+ exam and to fully understand the current risks and threats to an organization's data. If you are just entering the IT field, you will appreciate the comprehensive coverage of the tools and techniques necessary to safeguard electronic data. You'll also learn everything you need to pass the Security+ exam and attain this increasingly valuable certification. All the domain objectives itemized by CompTIA in their Security+ exam are covered: systems security, network infrastructure, access control, assessments and audits, cryptography, and organizational security.

Want to learn more information about CompTIA Security+ 2008 In Depth?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

CISO Leadership: Essential Principles for Success ((ISC)2 Press) Review

CISO Leadership: Essential Principles for Success ((ISC)2 Press)
Average Reviews:

(More customer reviews)
Are you looking to buy CISO Leadership: Essential Principles for Success ((ISC)2 Press)? Here is the right place to find the great deals. we can offer discounts of up to 90% on CISO Leadership: Essential Principles for Success ((ISC)2 Press). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

CISO Leadership: Essential Principles for Success ((ISC)2 Press) ReviewThis reference contains good insight and very practical information for a new security professionals or security professionals with less than 8 years in the field. The authors have and had leading positions in the information security field. I liked the way it was written with the different authors giving their perspective and advice. Very good reference.CISO Leadership: Essential Principles for Success ((ISC)2 Press) OverviewCaught in the crosshairs of 'Leadership" and 'Information Technology", Information Security professionals are increasingly tapped to operate as business executives. This often puts them on a career path they did not expect, in a field not yet clearly defined. IT training does not usually includemanagerial skills such as leadership, team-building, communication, risk assessment, and corporate business savvy, needed by CISOs. Yet a lack in any of these areas can short circuit a career in information security.
CISO Leadership: Essential Principles for Success captures years of hard knocks, success stories, and yes, failures. This is not a how-to book or a collection of technical data. It does not cover products or technology or provide a recapitulation of the common body of knowledge. The book delineates information needed by security leaders and includes from-the-trenches advice on how to have a successful career in the field.
With a stellar panel of contributors including William H. Murray, Harry Demaio, James Christiansen, Randy Sanovic, Mike Corby, Howard Schmidt, and other thought leaders, the book brings together the collective experience of trail blazers. The authors have learned through experience-been there, done that, have the t-shirt-and yes, the scars. A glance through the contents demonstrates the breadth and depth of coverage, not only in topics included but also in expertise provided by the chapter authors. They are the pioneers, who, while initially making it up as they went along, now provide the next generation of information security professionals with a guide to success.

Want to learn more information about CISO Leadership: Essential Principles for Success ((ISC)2 Press)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning Review

Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning
Average Reviews:

(More customer reviews)
Are you looking to buy Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning? Here is the right place to find the great deals. we can offer discounts of up to 90% on Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning ReviewEarlier this year Fyodor sent me a pre-publication review copy of his new self-published book, Nmap Network Scanning (NNS). I had heard of Fyodor's book when I wrote my 3 star review of Nmap in the Enterprise in June, but I wasn't consciously considering what could be in Fyodor's version compared to the Syngress title. Although the copy I read was labelled "Pre-Release Beta Version," I was very impressed by this book. Now that I have the final copy (available from Amazon) in my hands, I am really pleased with the product. In short, if you are looking for *the* book on Nmap, the search is over: NNS is a winner.
I've reviewed dedicated "tool" books before, including titles about Snort, Nessus, and Nagios. NNS dives into the internals of Nmap unlike any other title I've read. Without Nmap author Fyodor as the author, I think any competitor would need to have thoroughly read the source code of the application to have a chance at duplicating the level of detail Fyodor includes in NNS.
Instead of just describing how to use Nmap, Fyodor explains how Nmap works. Going even further, he describes the algorithms used to implement various tests, and why he chose those approaches. The "Idle Scan Implementation Algorithsm" section in Ch 5 is a great example of this sort of material. I will probably just refer students of my TCP/IP Weapons School class to this part of NNS when we discuss the technique!
One of the best parts of NNS, mentioned but explained in no other text, is the Nmap Scripting Engine (NSE). Ch 9 is all about NSE, with a brief intro to Lua and excellent documentation of using and building upon NSE. Beyond this groundbreaking material readers will find many examples of Nmap case studies from users. This and other sections help make NNS a practical book, showing how people use Nmap in their environments for a variety of purposes.
If you use Nmap, for any reason, you should buy this book. Everyone (except author Fyodor) will learn something about network reconnaissance from this text.Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning OverviewNmap Network Scanning is the official guide to the Nmap Security Scanner, a free and open source utility used by millions of people for network discovery, administration, and security auditing. From explaining port scanning basics for novices to detailing low-level packet crafting methods used by advanced hackers, this book suits all levels of security and networking professionals. A 42-page reference guide documents every Nmap feature and option, while the rest of the book demonstrates how to apply those features to quickly solve real-world tasks. Examples and diagrams show actual communication on the wire.
Topics include subverting firewalls and intrusion detection systems, optimizing Nmap performance, and automating common networking tasks with the Nmap Scripting Engine. Hints and instructions are provided for common uses such as taking network inventory, penetration testing, detecting rogue wireless access points, and quashing network worm outbreaks. Nmap runs on Windows, Linux, and Mac OS X.
Nmap's original author, Gordon "Fyodor" Lyon, wrote this book to share everything he has learned about network scanning during more than 11 years of Nmap development. Visit http://nmap.org/book for more information and sample chapters.

Want to learn more information about Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment Review

VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment
Average Reviews:

(More customer reviews)
Are you looking to buy VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment? Here is the right place to find the great deals. we can offer discounts of up to 90% on VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment ReviewIn the first half of this year (2009), I was involved on extending my previous research on virtualization security, and specifically, I focused on securing and hardening VMware ESX environments. This stirred up my interest on this book. To sum up what this book is all about: "I would have loved to have this book handy back by that time, as it would have saved me tons of time" Instead, I had to read and compare multiple VMware security guides from VMware, CIS, NIST, etc, and perform an extensive hands-on research on my own.
The book offers a very solid and broad analysis of multiple security issues on virtual environments, covering not only the technical aspects associated to the virtualization hosts, virtual machines, and virtual data and storage networks, but also management and operational issues, availability concerns, and other common related tasks on newly deployed, or already established, virtualization setups.
The first two chapters focus on security threats and attacks, a basic foundation required for the cross-references available throughout the book,that can be skipped by the on-the-field security readers.
The next three chapters focus on offering best practices and security recommendations for different key components of any virtualization platform, such as the hypervisor, the storage network, and virtual clusters. The next couple of chapters cover most of the security aspects that must be considered on the design, deployment and operation of a virtual environment.
Although all these chapters provide a very good quality security advice, it is not complemented with hands-on examples. I think this could be improved by adding more detailed sections describing step-by-step how to complete the security recommendations exposed, not just what need to be done. However, I understand it is required to cut the size of the book at some point. A good example of how to extend this idea can be observed on chapter 6, where the integration between VMWare ESX and a directory service is covered in depth.
However, both the technical and operational aspects are integrated smoothly, offering a great in-depth overview. Apart from that, the whole recommended list of things to consider in order to get a more secure virtualization infrastructure is summarized in a useful set of boxes called "Security Notes" and spread all throughout the book. These boxes can be easily used as a checklist when deploying or assessing the security of virtual solutions.
My favourite chapters are chapter 8, and specially 9, where virtual machine and virtual networking security is analyzed, respectively. Chapter 9 offers a whole set of networking scenarios and discusses pros and cons to the number of (physical and virtual) network cards and its configuration. A very practical and thorough work!
The book ends up with three special chapters. Chapter 10 covers the new VMware virtual desktop infrastructure (VDI) and the security issues around it. Due to all the client-based attacks nowadays, most probably it is going to be a de-facto standard pretty soon, so getting involved on the virtualization of client systems is a must. Chapter 11 provides a detailed guide to harden VMware ESX and ESXi hosts, a mandatory initial process for every new virtual deployment. Finally, chapter 12 provides a quick and interesting introduction to digital forensics (and data recovery) on virtual enviroments, mainly focused on how to deal with virtual file systems, such as VMFS, VMDKs, and raw disks. A quick recommended read for forensic analysts interested on expanding their skills to virtual victims.
There are a few things I feel will improve the book contents. Unfortunately, due to the publication deadline, its coverage of the latest VMware vSphere virtual architecture is pretty limited, as the author clarifies. Besides that, considering the frequent security updates and patches released by virtualization vendors, I would have liked to find a better coverage of best practices to update the virtual infrastructure itself. Finally, as mentioned previously, about half of the book includes detailed how-to sections describing how to apply the recommended settings, but the other half misses that how-to portion. I understand this may be a limitation to make the book size manageable (it's over 500 pages now).
This book is highly recommended for IT and security architects, involved in the design of new virtual solutions, as well as virtualization administrators and anyone in charge of the maintenance of a virtual infrastructure. From a security perspective, people evaluating, assessing, and suggesting improvements for virtual solutions should read the book in order to have a full overview of all the security threats and possible countermeasures. Overall, the book is a must read for anyone already involved, or planning to get involved, in virtualization. It really helps to acquire a very broad and extensive knowledge of the security considerations that apply to such a complex and modern IT architectures.
VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment OverviewComplete Hands-On Help for Securing VMware vSphere and Virtual Infrastructure by Edward Haletky, Author of the Best Selling Book on VMware, VMware ESX Server in the EnterpriseAs VMware has become increasingly ubiquitous in the enterprise, IT professionals have become increasingly concerned about securing it. Now, for the first time, leading VMware expert Edward Haletky brings together comprehensive guidance for identifying and mitigating virtualization-related security threats on all VMware platforms, including the new cloud computing platform, vSphere.This book reflects the same hands-on approach that made Haletky's VMware ESX Server in the Enterprise so popular with working professionals. Haletky doesn't just reveal where you might be vulnerable; he tells you exactly what to do and how to reconfigure your infrastructure to address the problem. VMware vSphere and Virtual Infrastructure Security begins by reviewing basic server vulnerabilities and explaining how security differs on VMware virtual servers and related products. Next, Haletky drills deep into the key components of a VMware installation, identifying both real and theoretical exploits, and introducing effective countermeasures. Coverage includes• Viewing virtualization from the attacker's perspective, and understanding the new security problems it can introduce• Discovering which security threats the vmkernel does (and doesn't) address• Learning how VMsafe enables third-party security tools to access the vmkernel API• Understanding the security implications of VMI, paravirtualization, and VMware Tools• Securing virtualized storage: authentication, disk encryption, virtual storage networks, isolation, and more• Protecting clustered virtual environments that use VMware High Availability, Dynamic Resource Scheduling, Fault Tolerance, vMotion, and Storage vMotion• Securing the deployment and management of virtual machines across the network• Mitigating risks associated with backup, performance management, and other day-to-day operations• Using multiple security zones and other advanced virtual network techniques• Securing Virtual Desktop Infrastructure (VDI)• Auditing virtual infrastructure, and conducting forensic investigations after a possible breachinformit.com/ph www.Astroarch.com

Want to learn more information about VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Pro C# with .NET 3.0, Special Edition (Expert's Voice in .NET) Review

Pro C# with .NET 3.0, Special Edition (Expert's Voice in .NET)
Average Reviews:

(More customer reviews)
Are you looking to buy Pro C# with .NET 3.0, Special Edition (Expert's Voice in .NET)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Pro C# with .NET 3.0, Special Edition (Expert's Voice in .NET). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Pro C# with .NET 3.0, Special Edition (Expert's Voice in .NET) ReviewThis book covers the details at all levels and is good for people with programming experience that are new to .NET, experienced developers who use .NET regularly but want to round out their knowledge of the inner workings and lesser used features of the framework, and to people moving up from 1.0 / 1.1 to 2.0 or 3.0. It does have sections on 3.0, but this is a general overview only in those areas. The rest of the book comprehensively covers .NET up to 2.0.
It's a huge book, but it's well worth the read.Pro C# with .NET 3.0, Special Edition (Expert's Voice in .NET) Overview
C# 2005 has enjoyed huge success in the year since its launch, firmly establishing itself as the premier language for development on Microsofts successful .NET 2.0 platform. With the launch of the .NET 3.0 extensions in early 2007, the horizons of this language are being extended, and it is becoming even more powerful as it is able to leverage the new .NET 3.0 Foundations.

In recognition of this, Apress presents Pro C# with .NET 3.0, Special Edition to provide you with a complete A-to-Z reference for using C# with the .NET 2.0 platform and the .NET 3.0 extensions. The book contains new chapters that explore the interactions between the existing framework and the new extensions, giving you an edge when you evaluate and implement .NET 3.0 for the first time. To provide even more support, a bonus PDF download will be available with each purchase, offering over 500 pages of carefully selected additional content to help broaden your understanding of both .NET 2.0 and .NET 3.0.


Want to learn more information about Pro C# with .NET 3.0, Special Edition (Expert's Voice in .NET)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase Review

Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase
Average Reviews:

(More customer reviews)
Are you looking to buy Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase? Here is the right place to find the great deals. we can offer discounts of up to 90% on Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase ReviewThe preface clearly states that this book is a guide on implementing security and auditing for database environments Lays out who should read the book, basically administrators, auditors, security professionals, or any one involved with operational ownership of databases.
After reading the book I actually felt that there are so many vulnerabilities that effect every part of an IT shop that this book is a must read for developers, architects, and management as well. Often it is the way systems are architected and coded that bring out the vulnerabilities and allow would-be hackers in.
Ron really has hit a great balance between readability and information.
The book isnt just a text or reference book but also entertained me.Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase Overview

Want to learn more information about Implementing Database Security and Auditing: Includes Examples for Oracle, SQL Server, DB2 UDB, Sybase?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Honeypots for Windows (Books for Professionals by Professionals) Review

Honeypots for Windows (Books for Professionals by Professionals)
Average Reviews:

(More customer reviews)
Are you looking to buy Honeypots for Windows (Books for Professionals by Professionals)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Honeypots for Windows (Books for Professionals by Professionals). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Honeypots for Windows (Books for Professionals by Professionals) ReviewReview by Lou Vega of the Greater Charleston .NET User Group
This book provides immediate and useful information whether you have previous experience with Honeypots or hadn't even heard of one until you picked up the book. I would recommend this book to anyone who has ever been interested in network and systems security as it pertains to a Microsoft Windows environment, especially in light of the fact that most previous books and articles with information about Honeypots were geared toward *nix systems.
Those who have no previous experience with Honeypots and would like a background lesson can jump right into Chapters 1 and 2 which should give them a fair basic understanding of what's involved. Those persons who want to get right to work...start browsing between chapters 3 and 8 for hands on information including screenshots and installation/configuration information. Later chapters cover more advanced information concerning the monitoring and analysis of the traffic captured using your Honeypot.
The author doesn't leave you stranded with just setting up a Honeypot either. The chapters on Network Analysis, Honeypot Monitoring and alerting, and Honeypot data analysis give you a chance to begin to make real use of the Honeypot and the data gathered while using it. The walkthroughs for setting these analysis and monitoring tools seem easy enough and the author makes good use of available open source tools out there for those who don't have the budget for some of the commercial applications available.
An added bonus for any networking security person is the wealth of information concerning how to harden a Windows Server, common ports used in malware and numerous configuration demonstrations make this a handy book to keep as a general security reference.
This book will make a fine addition to any IT professional's reference collection.Honeypots for Windows (Books for Professionals by Professionals) OverviewThe Book will cover installing, configuring, and maintaining security Honeypots on Windows platforms. The Book will specifically cover the popular open source Honeypot product called honeyd, and summarize other commercial Honeypot solutions. There are no computer security books covering Honeypots (or IDSs) as they run on Windows platforms. Developers who are tired of reading Unix and Linux documentation and newsgroups to get information on how to build and maintain a Windows-based Honeypot this book is for you. No longer will you have to rummage through Unix-only advice and utilities to pull out the information that related to your Windows deployment. No longer will you have to listen to some Unix head bash Microsoft and Bill Gates when all you wanted to know is why your Honeypot wasn't working. Learn special tricks and troubleshooting hints to run a Windows-based Honeypot.Target audience: Windows network and security administrators; intrusion detection software users; subscribers to Honeypot mailing list; readers of other author's Honeypot books - all are very Unix-centric

Want to learn more information about Honeypots for Windows (Books for Professionals by Professionals)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...