Create bookmark
Network Security Assessment
Know Your Network
Notes
Please login to add notes
- Table of Contents
- + Foreword
-
+
Preface
-
+
Network Security Assessment
-
+
The Tools Required
-
+
Internet Host and Network Enumeration
- + IP Network Scanning
- + Assessing Remote Information Services
-
+
Assessing Web Services
- Web Services
- + Identifying the Web Service
- + Identifying Subsystems and Components
-
+
Investigating Web Service Vulnerabilities
- + Accessing Poorly Protected Information
-
+
Assessing CGI Scripts and Custom ASP Pages
- Web Services Countermeasures
- + Assessing Remote Maintenance Services
- + Assessing FTP and Database Services
- + Assessing Windows Networking Services
- + Assessing Email Services
- + Assessing IP VPN Services
-
+
Assessing Unix RPC Services
- + Enumerating Unix RPC Services
-
+
RPC Service Vulnerabilities
- + Abusing rpc.mountd (100005)
- + Multiple Vendor rpc.statd (100024) Vulnerabilities
- + Solaris rpc.sadmind (100232) Vulnerabilities
- Solaris rpc.cachefsd (100235) Vulnerability
- Solaris rpc.snmpXdmid (100249) Vulnerability
- Multiple Vendor rpc.cmsd (100068) Vulnerabilities
- + Multiple Vendor rpc.ttdbserverd (100083) Vulnerability
- Unix RPC Services Countermeasures
-
+
Application-Level Risks
- The Fundamental Hacking Concept
- The Reasons Why Software Is Vulnerable
- + Network Service Vulnerabilities and Attacks
-
+
Classic Buffer-Overflow Vulnerabilities
- + Heap Overflows
- + Integer Overflows
- + Format String Bugs
- Memory Manipulation Attacks Recap
- + Mitigating Process Manipulation Risks
- Recommended Secure Development Reading
- + Example Assessment Methodology
- + TCP, UDP Ports, and ICMP Message Types
- + Sources of Vulnerability Information
- Index
There are hundreds--if not thousands--of techniques used to compromise both Windows and Unix-based systems. Malicious code and new exploit scripts are released on a daily basis, and each evolution becomes more and more sophisticated. Keeping up with the myriad of systems used by hackers in the wild is a formidable task, and scrambling to patch each potential vulnerability or address each new attack one-by-one is a bit like emptying the Atlantic with paper cup.
If you're a network administrator, the pressure is on you to defend your systems from attack. But short of devoting your life to becoming a security expert, what can you do to ensure the safety of your mission critical systems? Where do you start?
Using the steps laid out by professional security analysts and consultants to identify and assess risks, Network Security Assessment offers an efficient testing model that an administrator can adopt, refine, and reuse to create proactive defensive strategies to protect their systems from the threats that are out there, as well as those still being developed.
This thorough and insightful guide covers offensive technologies by grouping and analyzing them at a higher level--from both an offensive and defensive standpoint--helping administrators design and deploy networks that are immune to offensive exploits, tools, and scripts. Network administrators who need to develop and implement a security assessment program will find everything they're looking for--a proven, expert-tested methodology on which to base their own comprehensive program--in this time-saving new book.
Test the closed alpha on paperc.com

