Create bookmark
Assessing Network Security
Notes
Please login to add notes
- + Cover
- Dedication
- Contents at a Glance
- Table of Contents
- Acknowledgments
- Foreword
- Introduction
-
+
Part I Planning and Performing Security Assessments
-
+
Chapter 1 Introduction to Performing Security Assessments
-
+
Chapter 2 Key Principles of Security
-
+
Making Security Easy
- Keeping Services Running
- Allowing the Right Users Access to the Right Information
- Defending Every Layer as if It Were the Last Layer of Defense
- Keeping a Record of Attempts to Access Information
- Compartmentalizing and Isolating Resources
- Avoiding the Mistakes Everyone Else Makes
- Controlling the Cost of Meeting Security Objectives
- + Risk Management
- Immutable Laws
- Frequently Asked Questions
-
+
Making Security Easy
-
+
Chapter 3 Using Vulnerability Scanning to Assess Network Security
-
+
Chapter 4 Conducting a Penetration Test
-
+
Chapter 5 Performing IT Security Audits
-
+
Chapter 6 Reporting Your Findings
-
+
Chapter 7 Building and Maintaining Your Security Assessment Skills
-
+
Chapter 1 Introduction to Performing Security Assessments
- + Part II Penetration Testing for Nonintrusive Attacks
-
+
Part III Penetration Testing for Intrusive Attacks
-
+
Chapter 14 Automated Vulnerability Detection
-
+
Chapter 15 Password Attacks
-
+
Chapter 16 Denial of Service Attacks
- + Chapter 17 Application Attacks
-
+
Chapter 18 Database Attacks
-
+
Chapter 19 Network Sniffing
-
+
Chapter 20 Spoofing
-
+
Chapter 21 Session Hijacking
-
+
Chapter 22 How Attackers Avoid Detection
-
+
Chapter 23 Attackers Using Non-Network Methods to Gain Access
-
+
Chapter 14 Automated Vulnerability Detection
- + Part IV Security Assessment Case Studies
-
+
Part V Appendixes
-
+
Appendix A Checklists
-
+
Penetration Test Checklists
- Chapter 8: Information Reconnaissance
- Chapter 9: Host Discovery Using DNS and NetBIOS
- Chapter 10: Network and Host Discovery
- Chapter 11: Port Scanning
- Chapter 12: Obtaining Information from a Host
- Chapter 13: War Dialing, War Driving, and Bluetooth Attacks
- Chapter 14: Automated Vulnerability Detection
- Chapter 15: Password Attacks
- Chapter 16: Denial of Service Attacks
- Chapter 17: Application Attacks
- Chapter 18: Database Attacks
- Chapter 19: Network Sniffing
- Chapter 20: Spoofing
- Chapter 21: Session Hijacking
- Chapter 22: How Attackers Avoid Detection
- Chapter 23: Attackers Using Non-Network Methods to Gain Access
- Chapter 24: Web Threats
- Chapter 25: E-Mail Threats
- Chapter 26: Domain Controller Threats
- Chapter 27: Extranet and VPN Threats
-
+
Countermeasures Checklists
- Chapter 8: Information Reconnaissance
- Chapter 9: Host Discovery Using DNS and NetBIOS
- Chapter 10: Network and Host Discovery
- Chapter 11: Port Scanning
- Chapter 12: Obtaining Information from a Host
- Chapter 13: War Dialing, War Driving, and Bluetooth Attacks
- Chapter 15: Password Attacks
- Chapter 16: Denial of Service Attacks
- Chapter 17: Application Attacks
- Chapter 18: Database Attacks
- Chapter 19: Network Sniffing
- Chapter 20: Spoofing
- Chapter 21: Session Hijacking
- Chapter 22: How Attackers Avoid Detection
- Chapter 23: Attackers Using Non-Network Methods to Gain Access
- Chapter 24: Web Threats
- Chapter 25: E-Mail Threats
- Chapter 26: Domain Controller Threats
- Chapter 27: Extranet and VPN Threats
-
+
Penetration Test Checklists
-
+
Appendix B References
- Chapter 1: Introduction to Performing Security Assessments
- Chapter 2: Key Principles of Security
- Chapter 3: Using Vulnerability Scanning to Assess Network Security
- Chapter 4: Conducting a Penetration Test
- Chapter 5: Performing IT Security Audits
- Chapter 6: Reporting Your Findings
- Chapter 7: Building and Maintaining Your Security Assessment Skills
- Chapter 8: Information Reconnaisance
- Chapter 9: Host Discovery Using DNS and NetBIOS
- Chapter 10: Network and Host Discovery
- Chapter 11: Port Scanning
- Chapter 12: Obtaining Information from a Host
- Chapter 13: War Dialing, War Driving, and Bluetooth Attacks
- Chapter 14: Automated Vulnerability Detection
- Chapter 15: Password Attacks
- Chapter 16: Denial of Service Attacks
- Chapter 17: Application Attacks
- Chapter 18: Database Attacks
- Chapter 19: Network Sniffing
- Chapter 20: Spoofing
- Chapter 21: Session Hijacking
- Chapter 22: How Attackers Avoid Detection
- Chapter 23: Attackers Using Non-Network Methods to Gain Access
- Chapter 24: Web Threats
- Chapter 25: E-Mail Threats
- Chapter 26: Domain Controller Threats
- Chapter 27: Extranet and VPN Threats
-
+
Appendix A Checklists
- + About the Authors
- System Requirements
Don’t wait for an attacker to find and exploit your security vulnerabilities—take the lead by assessing the state of your network’s security. This book delivers advanced network testing strategies, including vulnerability scanning and penetration testing, from members of the Microsoft security teams. These real-world practitioners provide hands-on guidance on how to perform security assessments, uncover security vulnerabilities, and apply appropriate countermeasures. The companion CD features time-saving tools and scripts that you can use to reveal and help correct security vulnerabilities in your own network.
Sharpen and advance your security assessment skills, including how to:
Detect vulnerabilities and perform penetration tests
Conduct and properly report an IT security audit
Find hidden hosts by using DNS, WINS, and NetBIOS
Sweep your network to analyze network topology, existing hosts, and multi- homed systems
Determine the status of ICP and UDP ports by using port scanning
Recognize and help counter common network threats, including:
War dialing, war driving, and Bluetooth attacks
Packet and network sniffing
IP, e-mail, and DNS spoofing
Password cracking
Communication interceptions and modifications
IDS and IPS attacker detection avoidance
Spam and other e-mail abuses
CD features:
Tools for testing e-mail, databases, and Web servers
Scripts for finding common information leaks and other potential security issues
Complete eBook in PDF format
A Note Regarding the CD or DVD
The print version of this book ships with a CD or DVD. For those customers purchasing one of the digital formats in which this book is available, we are pleased to offer the CD/DVD content as a free download via O'Reilly Media's Digital Distribution services. To download this content, please visit O'Reilly's web site, search for the title of this book to find its catalog page, and click on the link below the cover image (Examples, Companion Content, or Practice Files). Note that while we provide as much of the media content as we are able via free download, we are sometimes limited by licensing restrictions. Please direct any questions or concerns to booktech@oreilly.com.
Test the closed alpha on paperc.com
Book Details
Authors
Kevin Lam, David LeBlanc, and Ben Smith
Categories
Computers > System Administration > Disaster & Recovery
Publishers
Publication year : 2009
License: All rights reserved ©
Times read: 209

