𝔖 Scriptorium
✦   LIBER   ✦

📁

Penetration Testing

✍ Scribed by Georgia Weidman


Publisher
No Starch Press
Year
2014
Tongue
English
Leaves
531
Edition
1
Category
Library

⬇  Acquire This Volume

No coin nor oath required. For personal study only.

✦ Synopsis


Penetration testers simulate cyber attacks to find security weaknesses in networks, operating systems, and applications. Information security experts worldwide use penetration techniques to evaluate enterprise defenses.

In Penetration Testing, security expert, researcher, and trainer Georgia Weidman introduces you to the core skills and techniques that every pentester needs. Using a virtual machine–based lab that includes Kali Linux and vulnerable operating systems, you’ll run through a series of practical lessons with tools like Wireshark, Nmap, and Burp Suite. As you follow along with the labs and launch attacks, you’ll experience the key stages of an actual assessment—including information gathering, finding exploitable vulnerabilities, gaining access to systems, post exploitation, and more.

Learn how to:
• Crack passwords and wireless network keys with brute-forcing and wordlists
• Test web applications for vulnerabilities
• Use the Metasploit Framework to launch exploits and write your own Metasploit modulesv
• Automate social-engineering attack
• Bypass antivirus software
• Turn access to one machine into total control of the enterprise in the post exploitation phase

You’ll even explore writing your own exploits. Then it’s on to mobile hacking — Weidman’s particular area of research — with her tool, the Smartphone Pentest Framework.
With its collection of hands-on lessons that cover key tools and strategies, Penetration Testing is the introduction that every aspiring hacker needs.

✦ Table of Contents


Foreward by Peter Van Eeckhoutte

Acknowledgements

Introduction

Penetration Testing Primer

Part 1: The Basics

Chapter 1: Setting Up Your Virtual Lab
Chapter 2: Using Kali Linux
Chapter 3: Programming
Chapter 4: Using the Metasploit Framework

Part 2: Assessments

Chapter 5: Information Gathering
Chapter 6: Finding Vulnerabilities
Chapter 7: Capturing Traffic

Part 3: Attacks

Chapter 8: Exploitation
Chapter 9: Password Attacks
Chapter 10: Client-Side Exploitation
Chapter 11: Social Engineering
Chapter 12: Bypassing Antivirus Applications
Chapter 13: Post Exploitation
Chapter 14: Web Application Testing
Chapter 15: Wireless Attacks

Part 4: Exploit Development

Chapter 16: A Stack-Based Buffer Overflow in Linux
Chapter 17: A Stack-Based Buffer Overflow in Windows
Chapter 18: Structured Exception Handler Overwrites
Chapter 19: Fuzzing, Porting Exploits, and Metasploit Modules

Part 5: Mobile Hacking

Chapter 20: Using the Smartphone Pentest Framework

Resources

Index

✦ Subjects


Linux;Command Line;Password Cracking;Security;Python;Penetration Testing;Web Applications;Wireless Networks;Android;Wireshark;Microsoft Windows;Packet Filtering;Vulnerability Scanning;Social Engineering;Exploitation;Kali Linux;Vulnerability Analysis;Nessus;Metasploit;nmap;SQL Injection;Fuzzing;Phishing;XSS;Antivirus Evasion;Burp;VMware;Nikto;Threat Models;Packet Analysis;bash;Password Management;Mobile Applications;Information Gathering;Traffic Capturing;Post-Exploitation


📜 SIMILAR VOLUMES


Penetration Testing
✍ Wolf Halton 📂 Library 🏛 Packt Publishing 🌐 English

This second edition of Kali Linux 2: Windows Penetration Testing provides approaches and solutions to the issues of modern penetration testing for a Microsoft Windows environment. As a pen tester, you need to be able to understand and use the best available tools - this book addresses these needs wi

Penetration Testing
✍ Weidman, Georgia 📂 Library 📅 2014 🏛 No Starch Press 🌐 English

A complete guide to longevity finance<br /><br />As the Baby Boomer population continues to age and the need for the securitization of life insurance policies increases, more financial institutions are looking towards longevity trading as a solution. Consequently, there is now a need for innovative