Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 41 guests and 3 members online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
cc08f_midwestbus_banner_130x488.gif
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Columnsarrow Gatesarrow Hacking Exposed Wireless: Book Review
Ethical Hacker Community Forums
October 15, 2008, 02:26:24 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Hacking Exposed Wireless: Book Review  (Read 4291 times)
0 Members and 1 Guest are viewing this topic.
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1009


View Profile WWW
« on: September 26, 2007, 05:07:07 PM »



Hacking Exposed Wireless Book Review


3 stars


Doesn't live up to the Hacking Exposed reputation


I have a ton of those red covered books on the book shelf. The Hacking Exposed series has been good to me and good to every person trying to learn security. So, I was excited to have my new green covered Hacking Exposed Wireless book show up at the house so I could learn some wireless hacking. The first 60 pages or so of background technical content is interesting but not totally necessary to get going with the topic. I do realize to be a good "hacker" you need to understand the technology, but the other HE's have been able to balance giving us the background and still able to use the tools for some hacking action.


I felt that once we finally got into the technical content (starts with 802.11 discovery) that they talked around topics but really didn't cover how to actually "do" anything. There isn't much to running kismet after configuring the one or two lines of the conf file. Then its a simple #kismet or $sudo kismet and it runs. Netstumbler is even easier since you have GUI to help you out and its on Windows and same same with KisMAC on OS X.


The cracking WEP section starts out with saying use an old kernel and the madwifi-old drivers. That may have been great advice when the book was published but it is certainly not useful for the average user today especially since it appears the bugs have been worked out of the new madwifi driver and aircrack-ng. (We do have to take into account that I read the book in Sep 07 and it was published in March 07). The section on using aircrack to break WEP on linux on pages 180-182 was decent but certainly not anything you cant get on the aircrack-ng homepage. A little more content on how we do fake authentication attempts and then why and how we have aireplay send our ARP packets would have been nice. The current version of aireplay when you run that capture makes you pick which capture we want to use, since they don't cover what packet to use it may be difficult for the person following along. The shell of the instructions are there, but the details are missing.

The opportunity to shine by talking about the Fragmentation and ChopChop attacks is devoid of actually using aircrack-ng or other tools to launch the attacks, so it falls short.


The Hacking Hotspots section (CH 9) looked to be the redeeming section at first glance but much like the WEP cracking section is lacking any useful screenshots or how to use any of the tools they mention. The most frustrating part was the author telling us how they have a slick SSH set up to use public hotspots but provides no information on how to set up one of our own. The tunneling using ozymanDNS attack gives no useful information on how to use the tool, the billing attacks section gives no useful information either. While I understand its illegal to steal wifi, if you aren't going to actually cover it, don't bother talking all around it. The client attack section consisted of installing nmap and nessus and running it against clients on the LAN. That section was the perfect set up to really cover KARMA in-depth, sadly a missed opportunity.


The bluetooth section (CH 10) that looks to be written by Kevin Finisterre was excellent and met the high standards previous HE books set. He walks us through a fictional scenario with real code and explains how we can use the code to exploit bluetooth vulnerabilities on OSX and gives us the link to the code :-)


Overall I was disappointed in the book which is unfortunate because the authors are known to be very knowledgeable and skilled people in the security industry. It can be a good reference on wifi background and hardware if you need one but it falls a bit short IMO of being as useful as some of the other HE titles.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Kev
Sr. Member
****
Offline Offline

Posts: 345


View Profile
« Reply #1 on: September 29, 2007, 06:29:47 PM »

Good review and I agree totally.  I had a chance to preview the book and ended up putting it back on the shelf of the store. The general feeling the book gives is if the authors were rushing to put something together. That might be unfair and I do know it takes a lot of effort to write a book, but if you are going to go 80% why not push it a little harder and go 100%?
Logged
kyrow
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #2 on: November 14, 2007, 10:23:26 AM »

I know this might sound pretty dumb after what you guys had just put so much critisim on the book, but should i still pick it up?

Im really a complete newb still when it comes to ethical hacking (or any hacking for that matter), however will the book still provide educational use to people like me or should i try else where.

Please provide Suggestions.
Thanks!
Peace. Cheesy
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1009


View Profile WWW
« Reply #3 on: November 14, 2007, 11:37:12 AM »

they new Wi-Foo is coming out soon.  you may want to wait on that.  but it really depends on how much you have to spend and your background.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.036 seconds with 23 queries.
 
Special Event
Pen Testing Perfect Storm Webcast Series: Part I

Join the Convo HERE!
Q&A in EH-Net Community Forums

Polls
Why a Career in Ethical Hacking:
 

cc08f_midwestbus_banner_130x488.gif
ChicagoCon 2008f

Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.