Hacking For Dummies, 3rd Edition

411 Pages · 8.57 mb ·

Beaver Kevin

Internet Software

Table of contents

- Hacking For Dummies®, 3rd Edition (Page 3)
- Contents at a Glance (Page 9)
- Table of Contents (Page 11)
- Introduction (Page 25)
- Part I: Building the Foundation for Ethical Hacking (Page 31)
- Chapter 1: Introduction to Ethical Hacking (Page 33)
- Straightening Out the Terminology (Page 33)
- Recognizing How Malicious Attackers Beget Ethical Hackers (Page 35)
- Understanding the Need to Hack Your Own Systems (Page 37)
- Understanding the Dangers Your Systems Face (Page 38)
- Obeying the Ethical Hacking Commandments (Page 40)
- Using the Ethical Hacking Process (Page 41)
- Chapter 2: Cracking the Hacker Mindset (Page 49)
- What You’re Up Against (Page 49)
- Who Breaks into Computer Systems (Page 51)
- Why They Do It (Page 53)
- Planning and Performing Attacks (Page 56)
- Maintaining Anonymity (Page 58)
- Chapter 3: Developing Your Ethical Hacking Plan (Page 59)
- Establishing Your Goals (Page 60)
- Determining Which Systems to Hack (Page 61)
- Creating Testing Standards (Page 64)
- Selecting Security Assessment Tools (Page 68)
- Chapter 4: Hacking Methodology (Page 69)
- Setting the Stage for Testing (Page 69)
- Seeing What Others See (Page 71)
- Scanning Systems (Page 76)
- Determining What’s Running on Open Ports (Page 77)
- Assessing Vulnerabilities (Page 79)
- Penetrating the System (Page 81)
- Part II: Putting Ethical Hacking in Motion (Page 83)
- Chapter 5: Social Engineering (Page 85)
- Social Engineering 101 (Page 85)
- Before You Start (Page 86)
- Why Attackers Use Social Engineering (Page 88)
- Understanding the Implications (Page 89)
- Performing Social Engineering Attacks (Page 90)
- Social Engineering Countermeasures (Page 96)
- Chapter 6: Physical Security (Page 99)
- Physical Security Vulnerabilities (Page 100)
- What to Look For (Page 102)
- Chapter 7: Passwords (Page 109)
- Password Vulnerabilities (Page 110)
- Cracking Passwords (Page 113)
- General Password-Cracking Countermeasures (Page 133)
- Securing Operating Systems (Page 137)
- Part III: Hacking the Network (Page 139)
- Chapter 8: Network Infrastructure (Page 141)
- Network Infrastructure Vulnerabilities (Page 143)
- Choosing Tools (Page 144)
- Scanning, Poking, and Prodding (Page 145)
- Common Router, Switch, and Firewall Weaknesses (Page 171)
- General Network Defenses (Page 173)
- Chapter 9: Wireless LANs (Page 175)
- Understanding the Implications of Wireless Network Vulnerabilities (Page 176)
- Choosing Your Tools (Page 178)
- Wireless LAN Discovery (Page 180)
- Wireless Network Attacks and Countermeasures (Page 182)
- Part IV: Hacking Operating Systems (Page 203)
- Chapter 10: Windows (Page 205)
- Windows Vulnerabilities (Page 206)
- Choosing Tools (Page 207)
- Information Gathering (Page 209)
- Null Sessions (Page 214)
- Share Permissions (Page 220)
- Missing Patch Exploitation (Page 222)
- Authenticated Scans (Page 229)
- Chapter 11: Linux (Page 231)
- Linux Vulnerabilities (Page 232)
- Choosing Tools (Page 232)
- Information Gathering (Page 233)
- Unneeded and Unsecured Services (Page 237)
- .rhosts and hosts.equiv Files (Page 242)
- NFS (Page 244)
- File Permissions (Page 245)
- Buffer Overflows (Page 247)
- Physical Security (Page 248)
- General Security Tests (Page 249)
- Patching Linux (Page 250)
- Chapter 12: Novell NetWare (Page 253)
- NetWare Vulnerabilities (Page 253)
- Choosing Tools (Page 254)
- Getting Started (Page 254)
- Authentication (Page 257)
- Solid Practices for Minimizing NetWare Security Risks (Page 267)
- Part V: Hacking Applications (Page 271)
- Chapter 13:Communication and Messaging Systems (Page 273)
- Messaging System Vulnerabilities (Page 273)
- E-Mail Attacks (Page 276)
- Instant Messaging (Page 291)
- Voice over IP (Page 294)
- Chapter 14: Web Sites and Applications (Page 301)
- Choosing Your Web Application Tools (Page 302)
- Web Vulnerabilities (Page 304)
- Best Practices for Minimizing Web Security Risks (Page 322)
- Chapter 15: Databases and Storage Systems (Page 327)
- Databases (Page 327)
- Best Practices for Minimizing Database Security Risks (Page 332)
- Storage Systems (Page 333)
- Best Practices for Minimizing Storage Security Risks (Page 337)
- Part VI: Ethical Hacking Aftermath (Page 339)
- Chapter 16: Reporting Your Results (Page 341)
- Pulling the Results Together (Page 341)
- Prioritizing Vulnerabilities (Page 343)
- Reporting Methods (Page 344)
- Chapter 17: Plugging Security Holes (Page 347)
- Turning Your Reports into Action (Page 347)
- Patching for Perfection (Page 348)
- Hardening Your Systems (Page 350)
- Assessing Your Security Infrastructure (Page 351)
- Chapter 18: Managing Security Changes (Page 353)
- Automating the Ethical Hacking Process (Page 353)
- Monitoring Malicious Use (Page 354)
- Outsourcing Ethical Hacking (Page 356)
- Instilling a Security-Aware Mindset (Page 357)
- Keeping Up with Other Security Issues (Page 358)
- Part VII: The Part of Tens (Page 359)
- Chapter 19: Ten Tips for Getting Upper Management Buy-In (Page 361)
- Cultivate an Ally and Sponsor (Page 361)
- Don’t Be a FUDdy Duddy (Page 361)
- Demonstrate How the Organization Can’t Afford to Be Hacked (Page 362)
- Outline the General Benefits of Ethical Hacking (Page 363)
- Show How Ethical Hacking Specifically Helps the Organization (Page 363)
- Get Involved in the Business (Page 363)
- Establish Your Credibility (Page 364)
- Speak on Management’s Level (Page 364)
- Show Value in Your Efforts (Page 364)
- Be Flexible and Adaptable (Page 365)
- Chapter 20: Ten Reasons Hacking Is the Only Effective Way to Test (Page 367)
- The Bad Guys Are Thinking Bad Thoughts, Using Good Tools, and Developing New Attack Methods (Page 367)
- IT Governance and Compliance Is More Than High-Level Checklist Audits (Page 367)
- Ethical Hacking Complements Audits and Security Evaluations (Page 368)
- Someone’s Going to Ask How Secure Your Systems Are (Page 368)
- The Law of Averages Is Working Against Businesses (Page 368)
- Ethical Hacking Creates a Better Understanding of What the Business Is Up Against (Page 368)
- If a Breach Occurs, You Have Something to Fall Back On (Page 369)
- Ethical Hacking Brings Out the Worst in Your Systems (Page 369)
- Ethical Hacking Combines the Best ofP enetration Testing and VulnerabilityTesting (Page 369)
- Ethical Hacking Can Uncover Operational Weaknesses That Might Go Overlooked For Years (Page 369)
- Chapter 21: Ten Deadly Mistakes (Page 371)
- Not Getting Prior Approval in Writing (Page 371)
- Assuming That You Can Find All Vulnerabilities during Your Tests (Page 371)
- Assuming That You Can Eliminate All Security Vulnerabilities (Page 372)
- Performing Tests Only Once (Page 372)
- Thinking That You Know It All (Page 372)
- Running Your Tests without Looking at Things from a Hacker’s Viewpoint (Page 373)
- Not Testing the Right Systems (Page 373)
- Not Using the Right Tools (Page 373)
- Pounding Production Systems at the Wrong Time (Page 373)
- Outsourcing Testing and Not Staying Involved (Page 374)
- Appendix: Tools and Resources (Page 375)
- Bluetooth (Page 375)
- Certifications (Page 376)
- Databases (Page 376)
- Exploit Tools (Page 376)
- General Research Tools (Page 377)
- Hacker Stuff (Page 378)
- Keyloggers (Page 378)
- Laws and Regulations (Page 378)
- Linux (Page 379)
- Live Toolkits (Page 379)
- Log Analysis (Page 379)
- Messaging (Page 379)
- Miscellaneous Tools (Page 380)
- NetWare (Page 380)
- Networks (Page 380)
- Password Cracking (Page 382)
- Patch Management (Page 383)
- Security Education and Learning Resources (Page 384)
- Security Methods and Models (Page 384)
- Source Code Analysis (Page 385)
- Storage (Page 385)
- System Hardening (Page 385)
- User Awareness and Training (Page 386)
- Voice over IP (Page 386)
- Vulnerability Databases (Page 387)
- Web Applications (Page 387)
- Windows (Page 388)
- Wireless Networks (Page 389)
- Index (Page 391)