The Vulnerability Researcher's Handbook: A comprehensive guide to discovering, reporting, and publishing security vulnerabilities
暫譯: 漏洞研究者手冊:發現、報告及發佈安全漏洞的全面指南

Strout, Benjamin

  • 出版商: Packt Publishing
  • 出版日期: 2023-02-17
  • 售價: $1,590
  • 貴賓價: 9.5$1,511
  • 語言: 英文
  • 頁數: 260
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1803238879
  • ISBN-13: 9781803238876
  • 相關分類: 資訊安全
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

Learn the right way to discover, report, and publish security vulnerabilities to prevent exploitation of user systems and reap the rewards of receiving credit for your work

Key Features

- Build successful strategies for planning and executing zero-day vulnerability research
- Find the best ways to disclose vulnerabilities while avoiding vendor conflict
- Learn to navigate the complicated CVE publishing process to receive credit for your research

Book Description

Vulnerability researchers are in increasingly high demand as the number of security incidents related to crime continues to rise with the adoption and use of technology. To begin your journey of becoming a security researcher, you need more than just the technical skills to find vulnerabilities; you'll need to learn how to adopt research strategies and navigate the complex and frustrating process of sharing your findings. This book provides an easy-to-follow approach that will help you understand the process of discovering, disclosing, and publishing your first zero-day vulnerability through a collection of examples and an in-depth review of the process.

You'll begin by learning the fundamentals of vulnerabilities, exploits, and what makes something a zero-day vulnerability. Then, you'll take a deep dive into the details of planning winning research strategies, navigating the complexities of vulnerability disclosure, and publishing your research with sometimes-less-than-receptive vendors.

By the end of the book, you'll be well versed in how researchers discover, disclose, and publish vulnerabilities, navigate complex vendor relationships, receive credit for their work, and ultimately protect users from exploitation. With this knowledge, you'll be prepared to conduct your own research and publish vulnerabilities.

What you will learn

- Find out what zero-day vulnerabilities are and why it's so important to disclose and publish them
- Learn how vulnerabilities get discovered and published to vulnerability scanning tools
- Explore successful strategies for starting and executing vulnerability research
- Discover ways to disclose zero-day vulnerabilities responsibly
- Populate zero-day security findings into the CVE databases
- Navigate and resolve conflicts with hostile vendors
- Publish findings and receive professional credit for your work

Who this book is for

This book is for security analysts, researchers, penetration testers, software developers, IT engineers, and anyone who wants to learn how vulnerabilities are found and then disclosed to the public. You'll need intermediate knowledge of operating systems, software, and interconnected systems before you get started. No prior experience with zero-day vulnerabilities is needed, but some exposure to vulnerability scanners and penetration testing tools will help accelerate your journey to publishing your first vulnerability.

商品描述(中文翻譯)

學習正確的方法來發現、報告和發布安全漏洞,以防止用戶系統被利用,並獲得對您工作的認可。

主要特點

- 建立成功的策略以規劃和執行零日漏洞研究
- 找到最佳的漏洞披露方式,同時避免與供應商的衝突
- 學習如何駕馭複雜的CVE發布過程,以獲得您研究的認可

書籍描述

隨著科技的採用和使用,與犯罪相關的安全事件數量不斷上升,漏洞研究人員的需求也日益增加。要開始成為一名安全研究人員,您需要的不僅僅是發現漏洞的技術技能;您還需要學習如何採用研究策略,並駕馭分享您發現的複雜且令人沮喪的過程。本書提供了一種易於遵循的方法,幫助您通過一系列示例和對過程的深入回顧,理解發現、披露和發布您的第一個零日漏洞的過程。

您將首先學習漏洞、利用和什麼是零日漏洞的基本概念。然後,您將深入研究規劃成功研究策略的細節,駕馭漏洞披露的複雜性,並在有時不太接受的供應商那裡發布您的研究。

在書籍結束時,您將熟悉研究人員如何發現、披露和發布漏洞,如何駕馭複雜的供應商關係,獲得對其工作的認可,並最終保護用戶免受利用。擁有這些知識,您將準備好進行自己的研究並發布漏洞。

您將學到什麼

- 了解什麼是零日漏洞,以及為什麼披露和發布它們如此重要
- 學習漏洞是如何被發現並發布到漏洞掃描工具的
- 探索成功的策略以開始和執行漏洞研究
- 發現負責任地披露零日漏洞的方法
- 將零日安全發現填入CVE數據庫
- 駕馭並解決與敵對供應商的衝突
- 發布發現並獲得專業的工作認可

本書適合誰

本書適合安全分析師、研究人員、滲透測試員、軟體開發人員、IT工程師,以及任何想學習漏洞是如何被發現並披露給公眾的人。在開始之前,您需要具備中級的操作系統、軟體和互聯系統的知識。無需具備零日漏洞的先前經驗,但對漏洞掃描器和滲透測試工具的某些接觸將有助於加速您發布第一個漏洞的旅程。

目錄大綱

1. An Introduction to Vulnerabilities
2. Exploring Real-World Impacts of Zero-Days
3. Vulnerability Research – Getting Started with Successful Strategies
4. Vulnerability Disclosure – Communicating Security Findings
5. Vulnerability Publishing – Getting Your Work Published in Databases
6. Vulnerability Mediation – When Things Go Wrong and Who Can Help
7. Independent Vulnerability Publishing
8. Real-World Case Studies – Digging into Successful (and Unsuccessful) Research Reporting
9. Working with Security Researchers – A Vendor's Guide
10. Templates, Resources, and Final Guidance

目錄大綱(中文翻譯)

1. An Introduction to Vulnerabilities

2. Exploring Real-World Impacts of Zero-Days

3. Vulnerability Research – Getting Started with Successful Strategies

4. Vulnerability Disclosure – Communicating Security Findings

5. Vulnerability Publishing – Getting Your Work Published in Databases

6. Vulnerability Mediation – When Things Go Wrong and Who Can Help

7. Independent Vulnerability Publishing

8. Real-World Case Studies – Digging into Successful (and Unsuccessful) Research Reporting

9. Working with Security Researchers – A Vendor's Guide

10. Templates, Resources, and Final Guidance