Penetration Testing Bootcamp
暫譯: 滲透測試訓練營

Jason Beltrame

  • 出版商: Packt Publishing
  • 出版日期: 2017-06-27
  • 售價: $2,000
  • 貴賓價: 9.5$1,900
  • 語言: 英文
  • 頁數: 258
  • 裝訂: Paperback
  • ISBN: 1787288749
  • ISBN-13: 9781787288744
  • 相關分類: Penetration-test
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Key Features

  • Get practical demonstrations with in-depth explanations of complex security-related problems
  • Familiarize yourself with the most common web vulnerabilities
  • Get step-by-step guidance on managing testing results and reporting

Book Description

Penetration Testing Bootcamp delivers practical, learning modules in manageable chunks. Each chapter is delivered in a day, and each day builds your competency in Penetration Testing.

This book will begin by taking you through the basics and show you how to set up and maintain the C&C Server. You will also understand how to scan for vulnerabilities and Metasploit, learn how to setup connectivity to a C&C server and maintain that connectivity for your intelligence gathering as well as offsite processing. Using TCPDump filters, you will gain understanding of the sniffing and spoofing traffic. This book will also teach you the importance of clearing up the tracks you leave behind after the penetration test and will show you how to build a report from all the data obtained from the penetration test.

In totality, this book will equip you with instructions through rigorous tasks, practical callouts, and assignments to reinforce your understanding of penetration testing.

What you will learn

  • Perform different attacks such as MiTM, and bypassing SSL encryption
  • Crack passwords and wireless network keys with brute-forcing and wordlists
  • Test web applications for vulnerabilities
  • Use the Metasploit Framework to launch exploits and write your own Metasploit modules
  • Recover lost files, investigate successful hacks, and discover hidden data
  • Write organized and effective penetration testing reports

About the Author

Jason Beltrame is a Systems Engineer for Cisco, living in the Eastern Pennsylvania Area. He has worked in the Network and Security field for 18 years, with the last 2 years as a Systems Engineer, and the prior 16 years on the operational side as a Network Engineer. During that time, Jason has achieved the following certifications: CISSP, CCNP, CCNP Security, CCDP, CCSP, CISA, ITILv2, and VCP5. He is a graduate from DeSales University with a BS in Computer Science. He has a passion for security and loves learning.

In his current role at Cisco, Jason focuses on Security and Enterprise Networks, but as a generalist SE, he covers all aspects of technology. Jason works with commercial territory customers, helping them achieve their technology goals based on their individual business requirements. His 16 years of real-world experience allows him to relate with his customers and understand both their challenges and desired outcomes.

Table of Contents

  1. Planning and Preparation
  2. Information Gathering
  3. Setting up and maintaining the C&C Server
  4. Vulnerability Scanning and Metasploit
  5. Traffic sniffing and spoofing
  6. Password based Attacks
  7. Attacks on the Network Infrastructure
  8. Web application Attacks
  9. Cleaning up and Getting out
  10. Writing up the penetration testing Report

商品描述(中文翻譯)

#### 主要特點
- 獲得實用的示範,深入解釋複雜的安全相關問題
- 熟悉最常見的網路漏洞
- 獲得逐步指導,管理測試結果和報告

#### 書籍描述
《滲透測試訓練營》提供可管理的實用學習模組。每一章節都在一天內完成,每一天都能提升你在滲透測試方面的能力。

本書將從基礎開始,教你如何設置和維護 C&C 伺服器。你還將了解如何掃描漏洞和使用 Metasploit,學習如何設置與 C&C 伺服器的連接並維持該連接以進行情報收集和外部處理。使用 TCPDump 過濾器,你將理解嗅探和偽造流量的概念。本書還將教你在滲透測試後清理留下的痕跡的重要性,並展示如何從滲透測試中獲得的所有數據中撰寫報告。

總體而言,本書將通過嚴謹的任務、實用的提示和作業來增強你對滲透測試的理解。

#### 你將學到的內容
- 執行不同的攻擊,例如中間人攻擊 (MiTM) 和繞過 SSL 加密
- 使用暴力破解和字典攻擊破解密碼和無線網路金鑰
- 測試網路應用程式的漏洞
- 使用 Metasploit 框架發動攻擊並撰寫自己的 Metasploit 模組
- 恢復丟失的檔案,調查成功的駭客攻擊,並發現隱藏的數據
- 撰寫組織良好且有效的滲透測試報告

#### 關於作者
**Jason Beltrame** 是思科的系統工程師,居住在賓夕法尼亞州東部地區。他在網路和安全領域工作了 18 年,最近 2 年擔任系統工程師,之前的 16 年則在運營方面擔任網路工程師。在此期間,Jason 獲得了以下認證:CISSP、CCNP、CCNP Security、CCDP、CCSP、CISA、ITILv2 和 VCP5。他畢業於德塞爾斯大學,獲得計算機科學學士學位。他對安全充滿熱情,喜歡學習。

在思科的目前角色中,Jason 專注於安全和企業網路,但作為一名通才系統工程師,他涵蓋了技術的各個方面。Jason 與商業領域的客戶合作,幫助他們根據各自的業務需求實現技術目標。他 16 年的實際經驗使他能夠與客戶建立聯繫,理解他們的挑戰和期望的結果。

#### 目錄
1. 計劃與準備
2. 資訊收集
3. 設置和維護 C&C 伺服器
4. 漏洞掃描和 Metasploit
5. 流量嗅探和偽造
6. 基於密碼的攻擊
7. 對網路基礎設施的攻擊
8. 網路應用程式攻擊
9. 清理和撤離
10. 撰寫滲透測試報告