Nmap: Network Exploration and Security Auditing Cookbook - Second Edition
暫譯: Nmap:網路探索與安全審計食譜(第二版)

Paulino Calderon

相關主題

商品描述

Over 100 practical recipes related to network and application security auditing using the powerful Nmap

About This Book

  • Learn through practical recipes how to use Nmap for a wide range of tasks for system administrators and penetration testers.
  • Learn the latest and most useful features of Nmap and the Nmap Scripting Engine.
  • Learn to audit the security of networks, web applications, databases, mail servers, Microsoft Windows servers/workstations and even ICS systems.
  • Learn to develop your own modules for the Nmap Scripting Engine.
  • Become familiar with Lua programming.
  • 100% practical tasks, relevant and explained step-by-step with exact commands and optional arguments description

Who This Book Is For

The book is for anyone who wants to master Nmap and its scripting engine to perform real life security auditing checks for system administrators and penetration testers. This book is also recommended to anyone looking to learn about network security auditing. Finally, novice Nmap users will also learn a lot from this book as it covers several advanced internal aspects of Nmap and related tools.

What You Will Learn

  • Learn about Nmap and related tools, such as Ncat, Ncrack, Ndiff, Zenmap and the Nmap Scripting Engine
  • Master basic and advanced techniques to perform port scanning and host discovery
  • Detect insecure configurations and vulnerabilities in web servers, databases, and mail servers
  • Learn how to detect insecure Microsoft Windows workstations and scan networks using the Active Directory technology
  • Learn how to safely identify and scan critical ICS/SCADA systems
  • Learn how to optimize the performance and behavior of your scans
  • Learn about advanced reporting
  • Learn the fundamentals of Lua programming
  • Become familiar with the development libraries shipped with the NSE
  • Write your own Nmap Scripting Engine scripts

In Detail

This is the second edition of 'Nmap 6: Network Exploration and Security Auditing Cookbook'. A book aimed for anyone who wants to master Nmap and its scripting engine through practical tasks for system administrators and penetration testers. Besides introducing the most powerful features of Nmap and related tools, common security auditing tasks for local and remote networks, web applications, databases, mail servers, Microsoft Windows machines and even ICS SCADA systems are explained step by step with exact commands and argument explanations.

The book starts with the basic usage of Nmap and related tools like Ncat, Ncrack, Ndiff and Zenmap. The Nmap Scripting Engine is thoroughly covered through security checks used commonly in real-life scenarios applied for different types of systems. New chapters for Microsoft Windows and ICS SCADA systems were added and every recipe was revised. This edition reflects the latest updates and hottest additions to the Nmap project to date. The book will also introduce you to Lua programming and NSE script development allowing you to extend further the power of Nmap.

Style and approach

This book consists of practical recipes on network exploration and security auditing techniques, enabling you to get hands-on experience through real life scenarios.

商品描述(中文翻譯)

超過 100 個與網路和應用程式安全審計相關的實用配方,使用強大的 Nmap

本書介紹



  • 透過實用配方學習如何使用 Nmap 進行系統管理員和滲透測試者的各種任務。

  • 學習 Nmap 和 Nmap 腳本引擎的最新和最有用的功能。

  • 學習如何審計網路、網頁應用程式、資料庫、郵件伺服器、Microsoft Windows 伺服器/工作站,甚至是 ICS 系統的安全性。

  • 學習如何為 Nmap 腳本引擎開發自己的模組。

  • 熟悉 Lua 程式設計。

  • 100% 實用任務,相關且逐步解釋,包含精確的命令和可選參數描述。

本書適合誰


本書適合任何想要掌握 Nmap 及其腳本引擎,以進行系統管理員和滲透測試者的實際安全審計檢查的人士。本書也推薦給任何希望學習網路安全審計的人。最後,初學者 Nmap 使用者也能從本書中學到很多,因為它涵蓋了 Nmap 和相關工具的幾個進階內部方面。

您將學到什麼



  • 了解 Nmap 和相關工具,如 Ncat、Ncrack、Ndiff、Zenmap 和 Nmap 腳本引擎。

  • 掌握基本和進階技術以執行端口掃描和主機發現。

  • 檢測網頁伺服器、資料庫和郵件伺服器中的不安全配置和漏洞。

  • 學習如何檢測不安全的 Microsoft Windows 工作站,並使用 Active Directory 技術掃描網路。

  • 學習如何安全地識別和掃描關鍵的 ICS/SCADA 系統。

  • 學習如何優化掃描的性能和行為。

  • 了解進階報告。

  • 學習 Lua 程式設計的基本知識。

  • 熟悉隨 NSE 附帶的開發庫。

  • 撰寫自己的 Nmap 腳本引擎腳本。

詳細內容


這是《Nmap 6:網路探索與安全審計食譜》的第二版。這本書旨在幫助任何希望通過實用任務掌握 Nmap 及其腳本引擎的系統管理員和滲透測試者。除了介紹 Nmap 和相關工具的最強大功能外,還逐步解釋了本地和遠端網路、網頁應用程式、資料庫、郵件伺服器、Microsoft Windows 機器,甚至是 ICS SCADA 系統的常見安全審計任務,並提供精確的命令和參數解釋。


本書從 Nmap 和相關工具(如 Ncat、Ncrack、Ndiff 和 Zenmap)的基本用法開始。Nmap 腳本引擎通過在不同類型系統中常用的安全檢查進行徹底介紹。新增了針對 Microsoft Windows 和 ICS SCADA 系統的章節,並對每個配方進行了修訂。本版反映了迄今為止 Nmap 專案的最新更新和最熱門的新增功能。本書還將介紹 Lua 程式設計和 NSE 腳本開發,讓您進一步擴展 Nmap 的功能。

風格與方法


本書包含有關網路探索和安全審計技術的實用配方,使您能夠通過實際情境獲得實踐經驗。