Полное описание
>
Pruteanu, Adrian. Becoming the hacker : the playbook for getting inside the mind of an attacker / Adrian Pruteanu. - Birmingham : Packt Publishing Ltd, 2019. - 11 p) : ill. - URL: https://cat.gpntb.ru/?id=FT/ShowFT&sid=7f1e0041f89b17f7a1f760d4b31e0ef9. - Includes bibliographical references and index. - ISBN 1788623754. - ISBN 9781788623759. - Текст : электронный.Description based upon print version of record.
Содержание: >
Cover; Copyright; Packt upsell; Contributors; Table of Contents; Preface; Chapter 1 -- Introduction to Attacking Web Applications; Rules of engagement; Communication; Privacy considerations; Cleaning up; The tester's toolkit; Kali Linux; Kali Linux alternatives; The attack proxy; Burp Suite; Zed Attack Proxy; Cloud infrastructure; Resources; Exercises; Summary; Chapter 2 -- Efficient Discovery; Types of assessments; Target mapping; Masscan; WhatWeb; Nikto; CMS scanners; Efficient brute-forcing; Content discovery; Burp Suite; OWASP ZAP; Gobuster; Persistent content discovery; Payload processing
Polyglot payloadsSame payload, different context; Code obfuscation; Resources; Exercises; Summary; Chapter 3 -- Low-Hanging Fruit; Network assessment; Looking for a way in; Credential guessing; A better way to shell; Cleaning up; Resources; Summary; Chapter 4 -- Advanced Brute-forcing; Password spraying; LinkedIn scraping; Metadata; The cluster bomb; Behind seven proxies; Torify; Proxy cannon; Summary; Chapter 5 -- File Inclusion Attacks; RFI; LFI; File inclusion to remote code execution; More file upload issues; Summary; Chapter 6 -- Out-of-Band Exploitation; A common scenario
Command and controlLet's Encrypt Communication; INet simulation; The confirmation; Async data exfiltration; Data inference; Summary; Chapter 7 -- Automated Testing; Extending Burp; Authentication and authorization abuse; The Autorize flow; The Swiss Army knife; sqlmap helper; Web shells; Obfuscating code; Burp Collaborator; Public Collaborator server; Service interaction; Burp Collaborator client; Private Collaborator server; Summary; Chapter 8 -- Bad Serialization; Abusing deserialization; Attacking custom protocols; Protocol analysis; Deserialization exploit; Summary
Chapter 9 -- Practical Client-Side AttacksSOP; Cross-origin resource sharing; XSS; Reflected XSS; Persistent XSS; DOM-based XSS; CSRF; BeEF; Hooking; Social engineering attacks; The keylogger; Persistence; Automatic exploitation; Tunneling traffic; Summary; Chapter 10 -- Practical Server-Side Attacks; Internal and external references; XXE attacks; A billion laughs; Request forgery; The port scanner; Information leak; Blind XXE; Remote code execution; Interactive shells; Summary; Chapter 11 -- Attacking APIs; API communication protocols; SOAP; REST; API authentication; Basic authentication
API keysBearer authentication; JWTs; JWT quirks; Burp JWT support; Postman; Installation; Upstream proxy; The environment; Collections; Collection Runner; Attack considerations; Summary; Chapter 12 -- Attacking CMS; Application assessment; WPScan; sqlmap; Droopescan; Arachni web scanner; Backdooring the code; Persistence; Credential exfiltration; Summary; Chapter 13 -- Breaking Containers; Vulnerable Docker scenario; Foothold; Situational awareness; Container breakout; Summary; Other Books You May Enjoy; Index
Рубрики:
Penetration testing (Computer security)
Computer security
Computers -- Access control
Computer networks -- Security measures
Hacking
COMPUTERS / Security / Networking
Аннотация: Adrian Pruteanu adopts the mindset of both a defender and an attacker in this practical guide to web application testing. By giving key insights into attack vectors and defenses, Becoming the Hacker builds your ability to analyze from both viewpoints and create robust defense strategies.
Держатели документа:
Полнотекстовая коллекция книг EBSCO eBooks (Шифр в БД-источнике (EBSKO): on1085235984)>
Шифр в сводном ЭК: 0707447f2499062ccf38eafdd7317a21
Clarke N. Transparent User Authentication : Biometrics, RFID and Behavioural Profiling / by Nathan Clarke., 2011 r=on-line (Введено оглавление). - Текст : электронный.Keromytis A.D. Voice over IP Security : A Comprehensive Survey of Vulnerabilities and Academic Research / by Angelos D. Keromytis., 2011 r=on-line (Введено оглавление). - Текст : электронный.Intelligence Management : Knowledge Driven Frameworks for Combating Terrorism and Organized Crime / edited by Babak Akhgar, Simeon Yates., 2011 r=on-line. - Текст : электронный.Moving Target Defense : Creating Asymmetric Uncertainty for Cyber Threats / edited by Sushil Jajodia, Anup K. Ghosh, Vipin Swarup [et al.], 2011 r=on-line (Введено оглавление). - Текст : электронный.Ou X. Quantitative Security Risk Assessment of Enterprise Networks : монография / by Xinming Ou, Anoop Singhal., 2011 r=on-line (Введено оглавление). - Текст : электронный.Khrais Hussam. Python for Offensive PenTest : a practical guide to ethical hacking and penetration testing using Python / Hussam. Khrais, 2018. - 7 с. (Введено оглавление). - Текст : электронный.Chauhan A.S. Practical network scanning : capture network vulnerabilities using standard tools such as Nmap and Nessus / Ajay Singh Chauhan., 2018. - 18 с. - Текст : электронный.Gupta, Rajneesh. Hands-on cybersecurity with Blockchain : implement DDoS protection, PKI-based identity, 2FA, and DNS security using Blockchain / Rajneesh Gupta., 2018. - 18 с. (Введено оглавление). - Текст : электронный.John, Tomcy. Hands-on Spring Security 5 for Reactive applications : learn effective ways to secure your applications with Spring and Spring WebFlux / Tomcy John., 2018. - 23 с. - Текст : электронный.Sabih, Zaid. Learn ethical hacking from scratch : your stepping stone to penetration testing / Zaid Sabih., 2018. - 60 с. - Текст : электронный.Advanced methodologies and technologies in system security, information privacy, and forensics / IGI Global,, [2019]. - 11 с. (Введено оглавление). - Текст : электронный.Exploring security in software architecture and design / Michael Felderer and Riccardo Scandariato, editor., 2019. - 17 с. - Текст : электронный.Countering cyber attacks and preserving the integrity and availability of critical systems / S. Geetha and Asnath Victy Phamila, editors., 2019. - 10 с. - Текст : электронный.Pruteanu, Adrian. Becoming the hacker : the playbook for getting inside the mind of an attacker / Adrian Pruteanu., 2019. - 11 p) (Введено оглавление). - Текст : электронный.Ozkaya Erdal. Hands-On Cybersecurity for Finance : Identify Vulnerabilities and Secure Your Financial Services from Security Breaches / Erdal. Ozkaya, 2019. - 26 p). - Текст : электронный.Hsu T.H. Practical Security Automation and Testing : Tools and Techniques for Automated Security Scanning and Testing in DevSecOps / T. H. Hsu, 2019. - 13 p) (Введено оглавление). - Текст : электронный.Medical data security for bioengineers / Butta Singh, Barjinder Singh Saini, Dilbag Singh, Anukul Pandey, [editors]., [2019]. - 16 с. (Введено оглавление). - Текст : электронный.Developments in information security and cybernetic wars / IGI Global,, [2019]. - 10 с. (Введено оглавление). - Текст : электронный.Sharma, Himanshu. Kali Linux, an ethical hacker's cookbook : practical recipes that combine strategies, attacks, and tools for advanced penetration testing / Himanshu Sharma., 2019. - 72 с. (Введено оглавление). - Текст : электронный.Spellman F.R. Information technology protection and homeland security / Frank R. Spellman., [2019]. - 4 с. (Введено оглавление). - Текст : электронный.
Показать все результатыПросмотр издания