具体描述
Contents | Reviews | Updates
Order now and get early access to the ebook!
(What's that?)
Get 30% off with the coupon code EARLYBIRD
Download the supplementary files for the book
Download the Kali Linux virtual machine image used in the book from Offensive Security (Kali Linux 1.0.6 32bit VMWare)
Penetration testers simulate cyber attacks to find security weaknesses in networks, operating systems, and applications. Information security experts worldwide use penetration techniques to evaluate enterprise defenses.
In Penetration Testing, security expert, researcher, and trainer Georgia Weidman introduces you to the core skills and techniques that every pentester needs. Using a virtual machine–based lab that includes Kali Linux and vulnerable operating systems, you’ll run through a series of practical lessons with tools like Wireshark, Nmap, and Burp Suite. As you follow along with the labs and launch attacks, you’ll experience the key stages of an actual assessment—including information gathering, finding exploitable vulnerabilities, gaining access to systems, post exploitation, and more.
Learn how to:
Crack passwords and wireless network keys with brute-forcing and wordlists
Test web applications for vulnerabilities
Use the Metasploit Framework to launch exploits and write your own Metasploit modules
Automate social-engineering attacks
Bypass antivirus software
Turn access to one machine into total control of the enterprise in the post exploitation phase
You’ll even explore writing your own exploits. Then it’s on to mobile hacking—Weidman’s particular area of research—with her tool, the Smartphone Pentest Framework.
With its collection of hands-on lessons that cover key tools and strategies, Penetration Testing is the introduction that every aspiring hacker needs.
作者简介
Georgia Weidman is a penetration tester and researcher, as well as the founder of Bulb Security, a security consulting firm. She presents at conferences around the world, including Black Hat, ShmooCon, and DerbyCon, and teaches classes on topics such as penetration testing, mobile hacking, and exploit development. She was awarded a DARPA Cyber Fast Track grant to continue her work in mobile device security.
目录信息
读后感
用户评价
我对这本书的期望很高,因为它代表着我深入学习网络安全领域的一个重要步骤。我希望它能为我打开一扇通往更广阔网络安全世界的大门,让我能够更加自信地面对未来的挑战。我希望通过阅读这本书,我能够掌握一项有用的技能,为保护数字世界的安全贡献自己的力量。
我了解到,渗透测试不仅仅是技术层面的操作,更是一种思维方式。我希望这本书能够帮助我培养这种“攻击者”的思维模式,学会从潜在攻击者的角度去思考问题,从而更好地发现和防范安全风险。我期待书中能够提供一些关于安全策略、风险评估以及道德黑客的观点,让我能够更全面地理解渗透测试的意义。
在我看来,一本优秀的专业书籍,除了内容本身,其排版和语言风格也至关重要。我希望这本书的排版清晰、图文并茂,能够让读者在阅读过程中保持专注。同时,我期待作者能够用一种既专业又易于理解的语言来阐述复杂的概念,让非专业人士也能够轻松入门。
我一直对信息安全领域充满了好奇,而“渗透测试”这个词本身就带着一种探索未知、挑战极限的意味。这本书的标题直击了我内心深处的兴趣点,让我迫不及待地想了解更多。我之所以选择这本书,是因为它听起来像是为那些想要深入理解网络安全攻防机制的读者量身打造的。我期待它能为我揭示网络世界不为人知的另一面,让我从一个“被保护者”的角度,转变为一个能够理解甚至洞察潜在威胁的人。
这本书的包装设计非常吸引人,封面选用了一种深邃的蓝色,搭配着银白色的字体,给人一种专业、神秘且略带科技感的感觉。当我在书店第一次看到它时,就被这种低调却又充满力量的设计所吸引。我尤其喜欢封面上的那个抽象的、由交错线条构成的“漏洞”图案,它巧妙地暗示了本书的核心主题——渗透测试。翻开扉页,纸张的质感也相当不错,厚实且带有淡淡的油墨香,这让我在阅读过程中获得了一种愉悦的触觉和嗅觉体验。
我是一个非常注重实践的学习者,因此,我非常期待这本书中能够提供丰富的案例分析和实践指导。我希望它不仅仅是理论的堆砌,而是能够通过真实的场景模拟,让我理解渗透测试的实际操作流程,学习如何运用各种工具和技术来发现和利用系统中的弱点。如果书中包含一些动手实验的指导,那就更好了,这样我就可以边学边练,巩固所学知识。
对于任何一个希望在这个领域有所建树的人来说,“渗透测试”的知识都是必不可少的。我选择这本书,正是因为它直观地指出了这个关键领域。我希望它能为我提供一个坚实的基础,让我能够在此之上构建更复杂的安全知识体系。我期待这本书能成为我学习道路上的重要里程碑。
信息安全是一个不断发展的领域,新技术层出不穷。我希望这本书能够及时地反映当前渗透测试领域的最新发展和趋势。例如,我很好奇书中是否会涉及云计算环境下的渗透测试、物联网设备的漏洞挖掘,或者是对新兴攻击手段的探讨。一个与时俱进的书籍,能够帮助我保持学习的热情,并跟上行业的发展步伐。
作为一名对网络安全充满热情的初学者,我购买这本书的初衷是为了能够系统地学习渗透测试的相关知识。我希望这本书能够从基础讲起,循序渐进地引导我入门,让我能够理解渗透测试的原理、流程以及常用的方法论。如果书中能够提供清晰易懂的解释,并且避免使用过于晦涩的术语,那就再好不过了。
在浏览这本书的目录时,我注意到它涵盖了从基础概念到高级技术的广泛内容。序言部分就对渗透测试的定义、目的以及在现代网络安全体系中的重要性进行了清晰的阐述,这让我对本书的整体框架有了初步的认识。我尤其对其中提到的“信息收集”、“漏洞扫描”以及“漏洞利用”等章节感到兴奋,这些都是我一直想要深入学习的关键技术。
看了一部分,先放下了,有更重要的东西要读
看了一部分,先放下了,有更重要的东西要读
看了一部分,先放下了,有更重要的东西要读
看了一部分,先放下了,有更重要的东西要读
看了一部分,先放下了,有更重要的东西要读