Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 90 guests and 3 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Featuresarrow Book Reviewsarrow Professional Penetration Testing
EH-Net
May 26, 2012, 07:42:54 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Professional Penetration Testing  (Read 3333 times)
0 Members and 2 Guests are viewing this topic.
n3r
Jr. Member
**
Offline Offline

Posts: 95



View Profile
« on: October 17, 2011, 03:36:19 PM »

Hello !
Someone has read this book ?
http://syngress.com/hacking-and-penetration-testing/Professional-Penetration-Testing/

I'm looking for a book with a lot of exercises for testing the method. In this book there is a DVD with some lessons, and i saw in the summary that we work on our virtual lab.

So if someone can tell me if it's a must buy or not it'll be cool ! Because of the price i'm not sure if i can buy it or not.

thanks !

PART I - Setting Up
Chapter 1: Introduction
Chapter 2: Ethics and Hacking
Chapter 3: Hacking as a Career
Chapter 4: Setting up Your Lab
Chapter 5: Creating and Using PenTest Targets in Your Lab
Chapter 6: Methodologies
Chapter 7: PenTest Metrics
Chapter 8: Management of a PenTest

PART II - Running a PenTest
Chapter 9: Information Gathering
Chapter 10: Vulnerability Identification
Chapter 11: Vulnerability Verification
Chapter 12: Compromising a System and Privilege Escalation
Chapter 13: Maintaining Access
Chapter 14: Covering Your Tracks

PART III - Wrapping Everything Up
Chapter 15: Reporting Results
Chapter 16: Archiving Data
Chapter 17: Cleaning Up Your Lab
Chapter 18: Planning for Your Next PenTest

Appendix A - Acronyms
Appendix B - Definitions
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3917


Editor-In-Chief


View Profile WWW
« Reply #1 on: October 17, 2011, 03:38:18 PM »

Try the Features tab at the top, then choose book reviews:

http://www.ethicalhacker.net/content/view/277/2/

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
p0et
Full Member
***
Offline Offline

Posts: 197



View Profile
« Reply #2 on: October 17, 2011, 03:55:23 PM »

If you're looking for a book with step by step exercises, try this one as well: http://www.amazon.com/Practical-Hacking-Techniques-Countermeasures-Spivey/dp/0849370574/ref=sr_1_1?ie=UTF8&qid=1318884860&sr=8-1

He's coming out with a 2nd book soon too.
Logged

GCIH, Security+, Network+, A+, MCP, DCSE
rance
Full Member
***
Offline Offline

Posts: 163


<censored>


View Profile
« Reply #3 on: October 17, 2011, 05:01:13 PM »

If you're looking for something to practice against, check out WebGoat or DVWA.  Both are intentionally insecure apps.  WebGoat has built in "lessons", and DVWA will give you three difficulty levels.  These will give you a ton of exercises to work on...

(Keep in mind that any machine you run these on instantly becomes vulnerable, take care.)
Logged

Poking at security since 1986.  +++ATH
n3r
Jr. Member
**
Offline Offline

Posts: 95



View Profile
« Reply #4 on: October 18, 2011, 12:42:59 AM »

Thanks I didn't see the review.
Any comments from you about this book ?
Logged
TheXero
Full Member
***
Offline Offline

Posts: 112


Try Harder!


View Profile WWW
« Reply #5 on: October 18, 2011, 02:25:45 AM »

The book itself seems mostly about how to managed a pentest project, but the two courses focus on the methodologies and how to put them into practice.

I wouldn't say it's an overly technical book and it's mainly for managerial type people.
Logged

Jamie.R
Hero Member
*****
Offline Offline

Posts: 626



View Profile WWW
« Reply #6 on: October 18, 2011, 03:39:44 AM »

If you just want to practice maybe set up your own lab if you want step by step guide to hacking I don't think there is one but there are a few good books that can help you.

there is also this resource that explain how to setup two labs
http://www.securityaegis.com/network-pentest-lab/

The application hackers handbook is most likely the best for web apps.
http://www.amazon.co.uk/Web-Application-Hackers-Handbook-Discovering/dp/1118026470/ref=sr_1_1?ie=UTF8&qid=1318927013&sr=8-1

Gray hat hacking is another good one.
http://www.amazon.co.uk/Gray-Hacking-Ethical-Hackers-Handbook/dp/0071742557/ref=sr_1_1?s=books&ie=UTF8&qid=1318927037&sr=1-1

If you really new to security there a book called basic hacking
http://www.amazon.co.uk/Basics-Hacking-Penetration-Testing-Syngress/dp/1597496553/ref=sr_1_1?s=books&ie=UTF8&qid=1318927112&sr=1-1
Logged

OSWP | eCPPT | HackingDojo Nidan
www.jamierougive.co.uk
n3r
Jr. Member
**
Offline Offline

Posts: 95



View Profile
« Reply #7 on: October 18, 2011, 07:43:24 AM »

i already have Gray Hat hacking but it's a lot of theory and not a lot of exercises.
I think in this book we find a little bit of everything but nothing is really explained step by step.
Logged
Agoonie
Full Member
***
Online Online

Posts: 144



View Profile
« Reply #8 on: October 18, 2011, 07:54:30 AM »

So this is not worth a 1-click from Amazon.  Thanks fellas.  Grin
Logged

OSCE, OSCP, OSWP, CISSP, MEH...
n3r
Jr. Member
**
Offline Offline

Posts: 95



View Profile
« Reply #9 on: October 18, 2011, 08:05:59 AM »

Well this book is very good but for example the chapter on C and Python is very basic
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.375 seconds with 20 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.