Ethical Hacking and Penetration Testing GuideRequiring no prior hacking experience, Ethical Hacking and Penetration Testing Guide supplies a complete introduction to the steps required to complete a penetration test, or ethical hack, from beginning to end. You will learn how to properly utilize and interpret the results of modern-day hacking tools, which are required to complete a penetration test. The book covers a wide range of tools, including Backtrack Linux, Google reconnaissance, MetaGooFil, dig, Nmap, Nessus, Metasploit, Fast Track Autopwn, Netcat, and Hacker Defender rootkit. Supplying a simple and clean explanation of how to effectively utilize these tools, it details a four-step methodology for conducting an effective penetration test or hack.Providing an accessible introduction to penetration testing and hacking, the book supplies you with a fundamental understanding of offensive security. After completing the book you will be prepared to take on in-depth and advanced topics in hacking and penetration testing. The book walks you through each of the steps and tools in a structured, orderly manner allowing you to understand how the output from each tool can be fully utilized in the subsequent phases of the penetration test. This process will allow you to clearly see how the various tools and phases relate to each other. An ideal resource for those who want to learn about ethical hacking but don‘t know where to start, this book will help take your hacking skills to the next level. The topics described in this book comply with international standards and with what is being taught in international certifications. |
Contents
Introduction to Hacking | 1 |
Linux Basics | 19 |
Information Gathering Techniques | 53 |
Target Enumeration and Port Scanning Techniques | 97 |
Vulnerability Assessment | 121 |
Network Sniffing | 139 |
Remote Exploitation | 163 |
Client Side Exploitation | 197 |
Postexploitation | 231 |
Windows Exploit Development Basics | 271 |
Wireless Hacking | 291 |
Web Hacking | 313 |
Back Cover | 493 |
Other editions - View all
Common terms and phrases
access point application ARP spoofing attack vector authentication backdoor BackTrack browser brute force attacks Buffer Overflow burp bypass client side compromise cookies crack create credentials database default DOM-based XSS dvwa e-mail enumerate example execute exploit filter firewall following command FTP server function Google hacker hacking hashes host http://localhost/index.php?support=yes input inside install interface IP address JavaScript launch Linux MAC address machine malicious Metasploit meterpreter module MySQL Nessus nmap OpenVAS operating system options output packet parameter password payload penetration test pentest perform phishing protocol query rafay rainbow tables remote request running scanners scenario screenshot script session shell shellcode SNMP spoofing spoofing attack SQL injection SSRF Step symlink Syntax take a look target tokens tool traffic update upload username victim webserver Windows Wireshark XSS vulnerability


