Penetration Testing: A Survival Guide

4.8
4則評論
電子書
1045
評分和評論未經驗證  瞭解詳情

關於本電子書

A complete pentesting guide facilitating smooth backtracking for working hackersAbout This BookConduct network testing, surveillance, pen testing and forensics on MS Windows using Kali LinuxGain a deep understanding of the flaws in web applications and exploit them in a practical mannerPentest Android apps and perform various attacks in the real world using real case studiesWho This Book Is For

This course is for anyone who wants to learn about security. Basic knowledge of Android programming would be a plus.

What You Will LearnExploit several common Windows network vulnerabilitiesRecover lost files, investigate successful hacks, and discover hidden data in innocent-looking filesExpose vulnerabilities present in web servers and their applications using server-side attacksUse SQL and cross-site scripting (XSS) attacksCheck for XSS flaws using the burp suite proxyAcquaint yourself with the fundamental building blocks of Android Apps in the right wayTake a look at how your personal data can be stolen by malicious attackersSee how developers make mistakes that allow attackers to steal data from phonesIn Detail

The need for penetration testers has grown well over what the IT industry ever anticipated. Running just a vulnerability scanner is no longer an effective method to determine whether a business is truly secure. This learning path will help you develop the most effective penetration testing skills to protect your Windows, web applications, and Android devices.

The first module focuses on the Windows platform, which is one of the most common OSes, and managing its security spawned the discipline of IT security. Kali Linux is the premier platform for testing and maintaining Windows security. Employs the most advanced tools and techniques to reproduce the methods used by sophisticated hackers. In this module first,you'll be introduced to Kali's top ten tools and other useful reporting tools. Then, you will find your way around your target network and determine known vulnerabilities so you can exploit a system remotely. You'll not only learn to penetrate in the machine, but will also learn to work with Windows privilege escalations.

The second module will help you get to grips with the tools used in Kali Linux 2.0 that relate to web application hacking. You will get to know about scripting and input validation flaws, AJAX, and security issues related to AJAX. You will also use an automated technique called fuzzing so you can identify flaws in a web application. Finally, you'll understand the web application vulnerabilities and the ways they can be exploited.

In the last module, you'll get started with Android security. Android, being the platform with the largest consumer base, is the obvious primary target for attackers. You'll begin this journey with the absolute basics and will then slowly gear up to the concepts of Android rooting, application security assessments, malware, infecting APK files, and fuzzing. You'll gain the skills necessary to perform Android application vulnerability assessments and to create an Android pentesting lab.

This Learning Path is a blend of content from the following Packt products:

Kali Linux 2: Windows Penetration Testing by Wolf Halton and Bo WeaverWeb Penetration Testing with Kali Linux, Second Edition by Juned Ahmed AnsariHacking Android by Srinivasa Rao Kotipalli and Mohammed A. ImranStyle and approach

This course uses easy-to-understand yet professional language for explaining concepts to test your network's security.

評分和評論

4.8
4則評論

關於作者

Wolf Halton is a widely recognized authority on computer and internet security, an Amazon bestselling author on computer security, and the CEO of Atlanta Cloud Technology. He specializes in business continuity, security engineering, open source consulting, marketing automation, virtualization and datacenter restructuring, and Linux evangelism.

Bo Weaver is an old-school ponytailed geek whose first involvement with networks was in 1972, while working on an R&D project called ARPANET in the US Navy. He is now the senior penetration tester for Compliancepoint, an Atlanta-based security consulting company, where he works remotely from under a tree in the North Georgia mountains.

Juned Ahmed Ansari (@junedlive) is a cyber-security researcher based out of Mumbai. He currently leads the penetration testing and offensive security team of a large MNC. His primary focus areas are penetration testing, threat intelligence, and application security research. He holds leading security certifications such as GXPN, CISSP, CCSK, and CISA.

Srinivasa Rao Kotipalli (@srini0x00) is a security researcher from India. Through responsible disclosure programs, he has reported vulnerabilities in many top-notch organizations. He has extensive hands-on experience in performing web application, infrastructure, and mobile security assessments.

Mohammed A. Imran (@secfigo) has more than 6 years of experience in product security and consulting, he spends most of his time on penetration testing, vulnerability assessments, and source code reviews of web and mobile applications. He has helped telecom, banking, and software development houses create and maintain secure SDLC programs.

為這本電子書評分

歡迎提供意見。

閱讀資訊

智慧型手機與平板電腦
只要安裝 Google Play 圖書應用程式 Android 版iPad/iPhone 版,不僅應用程式內容會自動與你的帳戶保持同步,還能讓你隨時隨地上網或離線閱讀。
筆記型電腦和電腦
你可以使用電腦的網路瀏覽器聆聽你在 Google Play 購買的有聲書。
電子書閱讀器與其他裝置
如要在 Kobo 電子閱讀器這類電子書裝置上閱覽書籍,必須將檔案下載並傳輸到該裝置上。請按照說明中心的詳細操作說明,將檔案傳輸到支援的電子閱讀器上。