Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 41 guests and 1 member online
You are here:
Home
Features
Book Reviews
Book Review: The Basics of Hacking and Penetration Testing
EH-Net
May 24, 2013, 12:09:26 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Features
>
Book Reviews
(Moderator:
don
) >
Book Review: The Basics of Hacking and Penetration Testing
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Book Review: The Basics of Hacking and Penetration Testing (Read 12248 times)
0 Members and 1 Guest are viewing this topic.
l33t5h@rk
Jr. Member
Offline
Posts: 79
Book Review: The Basics of Hacking and Penetration Testing
«
on:
December 16, 2011, 01:19:27 PM »
I have been looking for a book to offer a general framework and pathway for identifying the basic fundamentals of pen testing. Admittedly, the length of the book (180 pages) made me question whether it would be possible to condense the material in a concise enough way to provide optimal value, or if it would prove to be skimming material that was a waste of money and time. I am overly satisfied with the book as it thoroughly explains the foundations of pen testing in a very enjoyable format. The author spent adequate time on all of the chapters, and reminds the reader to be sure to spend time on each of the topics in order to gain a true understanding of the topic. The tools mentioned in the book are vendor agnostic and should be a part of any pen testers arsenal. The SDLC of the pen test framework in this book is broken into four steps: Reconnaissance, Scanning Exploitation, & Maintaining Access. The author breaks down each phase with an explanation as to the importance of each phase, as well as specific tools and examples to use during each phase. He does a good job of emphasizing that penetration testing is more than just exploitation and using automated, script kiddie techniques. He accentuates that the recon & scanning phases provide great value to a pen tester breaking into the industry, explaining that good pen testers do more than push buttons in a pre-built tool. Though constantly overlooked, the final chapter focuses on the importance of customer service and reporting structures. A solid outline is given on how to identify customer needs and explain the remedy for their current findings. I am giving this title a 5-5 stars as it delivers exactly what is expected from the title.
Logged
hurtl0cker
Jr. Member
Offline
Posts: 73
Re: Book Review: The Basics of Hacking and Penetration Testing
«
Reply #1 on:
December 16, 2011, 04:54:29 PM »
I just have a doubt, I read some other Pen Testing beginners books like:
Hacking: The Art of Exploitation, 2nd Edition
Gray Hat Hacking The Ethical Hackers Handbook, 3rd Edition
Counter Hack Reloaded (2nd Edition)
I just want to know that what diffrence does this new book " The Basics of Hacking and Penetration Testing" make from the other books covering almost the same conecepts.
Logged
“Knowing is not enough; we must apply. Willing is not enough: we must do.”
- Bruce Lee
l33t5h@rk
Jr. Member
Offline
Posts: 79
Re: Book Review: The Basics of Hacking and Penetration Testing
«
Reply #2 on:
December 16, 2011, 09:23:02 PM »
I think the (short) length of it really made it accommodating as well as covering topics in just the right level of depth for a "back to basics" approach.
Logged
millwalll
Guest
Re: Book Review: The Basics of Hacking and Penetration Testing
«
Reply #3 on:
December 17, 2011, 10:01:40 AM »
I think this great book if you are total new to security but if you done a security course I dont think it will help that much
Logged
chrisj
Hero Member
Offline
Posts: 1163
Re: Book Review: The Basics of Hacking and Penetration Testing
«
Reply #4 on:
December 17, 2011, 04:18:10 PM »
I'm reading through it right now. Splitting my time between it and 2 others. I'm still in the information gathering section and keep thinking how useless this is for what I bought it for. Just that section. Not the book as a whole.
I bought it to get a better idea of what kinds of attacks to use in a CTF, and things to look for. As for the info gathering section, I like the one in Hacking the Next Generation more. But for what the book is supposed to be (to get your feet wet), the section is ok.
I'm also not above admitting that I pulled the book out the other day to help a buddy. we were looking for a contact number for the hosting provider (Dream Host). While the book itself wasn't useful in that, it did give me an idea to do something that helped some. I found a large list of email and contact numbers.
«
Last Edit: December 17, 2011, 04:19:44 PM by chrisj
»
Logged
OSWP, Sec+
l33t5h@rk
Jr. Member
Offline
Posts: 79
Re: Book Review: The Basics of Hacking and Penetration Testing
«
Reply #5 on:
December 17, 2011, 07:05:49 PM »
Quote from: Jamie.R on December 17, 2011, 10:01:40 AM
I think this great book if you are total new to security but if you done a security course I dont think it will help that much
That's exactly what I liked about it. If you want a back to basics, fundamentals book, I think it is perfect. Similar to how I rate movies, if something delivers exactly what I expect, I give it a perfect score. For example, is 300 the best movie of all time? No. But, is 300 exactly what you would want in a movie about Spartans fighting incredible battles and chopping limbs off in slow motion? Yes.
The purpose of the book is to outline the foundation of penetration testing, I think it accomplishes that quite succinctly.
Logged
monkeydust
Newbie
Offline
Posts: 4
Re: Book Review: The Basics of Hacking and Penetration Testing
«
Reply #6 on:
January 03, 2012, 02:38:47 PM »
I agree with the good reviews of this book. As a rookie to this security / pentesting game, it was a good book to point me in multiple new directions to expand my knowledge on my own. It was just enough to explain what it's all about without overloading on how. It's a good starting point.
Logged
Security+ce , C)PTE , OSWP
Working on SSCP , CWNA
vp75
Jr. Member
Offline
Posts: 78
Re: Book Review: The Basics of Hacking and Penetration Testing
«
Reply #7 on:
January 05, 2012, 11:27:45 AM »
I got this book very recently, I have been reading actively this week and really a good book, especially as jamie pointed, it is good for newbie who needs to understand about security/pen testing has its lifecycle and how informations are obtained.
V
Logged
eCPPT
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(28) by
don
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(6) by
azmatt
Greetings
: Hi from the UK
(4) by
MrTuxracer
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.