Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 27 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Featuresarrow Book Reviewsarrow Recomended book for Pen Tester
EH-Net
May 25, 2013, 11:34:37 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 2 [3] 4   Go Down
  Print  
Author Topic: Recomended book for Pen Tester  (Read 46343 times)
0 Members and 1 Guest are viewing this topic.
Capotao
Newbie
*
Offline Offline

Posts: 2



View Profile
« Reply #30 on: August 08, 2012, 06:12:54 PM »

I'd recommend this book: The Basics of Hacking and Penetration Testing, by Syngress.

It's start from the basics, explaning the process of a pentest, goes through linux usage and the most used tools to scan and exploit systems.

http://www.amazon.com/The-Basics-Hacking-Penetration-Testing/dp/1597496553/ref=pd_sim_b_1

Its a very good book to begginers, but if you are already familiar with the basics concepts, I'd recommend: Advanced Penetration Testing for Highly-Secured Environments, Packt Publishing.

http://www.amazon.com/Advanced-Penetration-Testing-Highly-Secured-Environments/dp/1849517746/ref=sr_1_1?s=books&ie=UTF8&qid=1344467380&sr=1-1&keywords=advanced+penetration

What is great in this book are the  advanced techniques and the labs setups. It teachs you to build up labs with layers of firewalls and systems to make your exploitation harder.
Logged

Push me, and then just touch me, 'till I can get my SATISFACTION!
fred
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #31 on: August 09, 2012, 01:20:57 AM »

wooohooo!! I already bought those books but the first one is awsome
Logged

ICS Academy Network Security Certified
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #32 on: August 09, 2012, 03:52:54 AM »

Not read the second one has anyone read it ? is it any good ?
Logged

OSWP | Hackingdojo Nidan | eCPPT
fred
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #33 on: August 09, 2012, 12:53:16 PM »

Not read the second one has anyone read it ? is it any good ?
i havent read the second one but i think the first one is better
Logged

ICS Academy Network Security Certified
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #34 on: August 09, 2012, 03:13:05 PM »

I read the first one and felt was ok a great read for a beginner.
Logged

OSWP | Hackingdojo Nidan | eCPPT
SecurityMonkey
Jr. Member
**
Offline Offline

Posts: 89



View Profile WWW
« Reply #35 on: August 09, 2012, 06:22:53 PM »

Advanced Penetration Testing for Highly-Secured Environments is a great read... +1
Logged

fred
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #36 on: August 09, 2012, 07:21:55 PM »

im not saying that the second one is bad ofcourse is great too but the first one is awsome
Logged

ICS Academy Network Security Certified
shadowzero
Full Member
***
Offline Offline

Posts: 120


It's a UNIX system, I know this!


View Profile
« Reply #37 on: August 09, 2012, 08:18:51 PM »

I've flipped through Advanced Penetration Testing for Highly-Secured Environments. I have some mixed feelings about it. Some things in the book aren't what I'd consider "advanced" (starting an ftp server, basic nmap scans, snmp scans, selecting a text editor (Huh)). Yet there are some gems in there, like setting up your own virtual lab, and bypassing IDSs and firewalls. Other things it barely touches upon (buffer overflow refresher - but never really goes into detail). There's a section on fuzzing, but only covers basic fuzzing.

Maybe it's just me, but when I see "Advanced" I expect something like this: http://www.inguardians.com/research/docs/Skoudis_pentestsecrets.pdf
Logged
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #38 on: August 10, 2012, 04:55:25 AM »

hmm I find most books follow the same sort of thing and cover the same topics.
Logged

OSWP | Hackingdojo Nidan | eCPPT
Catalyst256
Newbie
*
Offline Offline

Posts: 23



View Profile WWW
« Reply #39 on: August 10, 2012, 08:45:38 AM »

I've only been focusing on learning more about security since the beginning of the year and I have a bit of a different view on books.

I own a few different security books, grey hat hacking, hacking exposed and they are pretty much similar in content (which you would expect), but it depends on your skill level and the way you learn.

In all honestly I only use books as a reference point rather than reading through the whole thing, and forgetting most of it. The book depends on what you want/need to learn, for the myself I wrote a training plan over a year covering different tools and methods and then find the books (and don't forget Google) to learn those particular areas. I throw in a healthy dose of lab work (built various VM's) to push home what I've read and learnt.

Pen Testing usually follows a set pattern in terms of what you need to do:

scan, enumerated, exploit etc etc

From that you can work out the areas you need to learn about and then find books/pdf's/google material to progress. Otherwise you might end up reading books about subjects you don't need or only just cover a subject that is really important.

But then that's the just the way I learn best, like I said everyone is different and there are a lot of good books available.

I've just created a new wish list of Security books. Check it out here.

http://www.amazon.co.uk/registry/wishlist/1INPZOXT8TJY3

Adam
Logged

@catalyst256

Security+ OSCP VCP CCA
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #40 on: August 10, 2012, 02:57:16 PM »

Cool there are some good books on that list anyone else have good recommendation
Logged

OSWP | Hackingdojo Nidan | eCPPT
LT72884
Jr. Member
**
Offline Offline

Posts: 95


View Profile
« Reply #41 on: August 10, 2012, 03:41:25 PM »

http://www.amazon.com/Advanced-Penetration-Testing-Highly-Secured-Environments/dp/1849517746/ref=sr_1_1?s=books&ie=UTF8&qid=1344467380&sr=1-1&keywords=advanced+penetration

What is great in this book are the  advanced techniques and the labs setups. It teachs you to build up labs with layers of firewalls and systems to make your exploitation harder.

Question about VB and VMplayer. Chapter 8 of the advanced pen test book is avialable for free to the public. They use VB and the auther mentions that backtrack is on vlan1 and ubuntu is on vlan2. Now is the terminology of vlan in virtual box the same as it is in cisco? or is that they way virtualbox lables virtual network adapters? If it is an actual vlan, then is there a way to do that in vmplayer?

thanks guys
Logged
Capotao
Newbie
*
Offline Offline

Posts: 2



View Profile
« Reply #42 on: August 10, 2012, 06:26:23 PM »

http://www.amazon.com/Advanced-Penetration-Testing-Highly-Secured-Environments/dp/1849517746/ref=sr_1_1?s=books&ie=UTF8&qid=1344467380&sr=1-1&keywords=advanced+penetration

What is great in this book are the  advanced techniques and the labs setups. It teachs you to build up labs with layers of firewalls and systems to make your exploitation harder.

Question about VB and VMplayer. Chapter 8 of the advanced pen test book is avialable for free to the public. They use VB and the auther mentions that backtrack is on vlan1 and ubuntu is on vlan2. Now is the terminology of vlan in virtual box the same as it is in cisco? or is that they way virtualbox lables virtual network adapters? If it is an actual vlan, then is there a way to do that in vmplayer?

thanks guys


Actually, VLAN is a terminology used not only by Cisco. I reckon that is used by the networking area in general. The idea would be exactly what you have in mind when thinking about Cisco’s configurations to setup VLANs (one switch divided into 2 LANs).

I’m not sure about it if you can do it in VMPlayer, since I use Workstation.
Logged

Push me, and then just touch me, 'till I can get my SATISFACTION!
LT72884
Jr. Member
**
Offline Offline

Posts: 95


View Profile
« Reply #43 on: August 11, 2012, 02:42:13 AM »

o cool. yeah vlan is used in hp switches, juniper and basically any managed switch. haha. i did a little bit more digging and in the book, he just calls it vlan1 and vlan2 as the name of the network in VB because pfsense firewall apparently uses vlans as the way to seperate networks. sorta like how other firewalls had color coded names. red(public)green(private lan)orange(dmz)blue(wifi) pfsense just uses vlans. pretty much same thing.

so in vb the name is just vlan1 and vlan2 in the settings. its not actually creating vlans. haha. in vmplayer, its different. im actually learning tons right now. my lab is lookin awesome. i have a firewall between bt5 and de-ice lvl 1. this way i cn see how a fw is working. gonna install snort on it next.

took me like 4 hours to figure out what the book was trying to do. haha. since i dont use vb i had to make sure it was not actual vlans, but rather just names of the network cards. he later changes them to wlan1 and wlan2 or wan1 and wan2. haha.

thanks guys.

here is the link to the free chapter in case you want to read i.its 40$ from the same site if you want to buy it

http://packtlib.packtpub.com/library/9781849517744

http://www.packtpub.com/sites/default/files/9781849517744-Chapter-8.pdf?utm_source=packtpub&utm_medium=free&utm_campaign=pdf
« Last Edit: August 11, 2012, 02:48:42 AM by LT72884 » Logged
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #44 on: August 11, 2012, 02:33:27 PM »

Thanks will find it useful need to have a  read of it
Logged

OSWP | Hackingdojo Nidan | eCPPT
Pages: 1 2 [3] 4   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.072 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.