Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Professional Penetration Testing: Creating and Operating a Formal Hacking Lab Review

Professional Penetration Testing: Creating and Operating a Formal Hacking Lab
Average Reviews:

(More customer reviews)
Are you looking to buy Professional Penetration Testing: Creating and Operating a Formal Hacking Lab? Here is the right place to find the great deals. we can offer discounts of up to 90% on Professional Penetration Testing: Creating and Operating a Formal Hacking Lab. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Professional Penetration Testing: Creating and Operating a Formal Hacking Lab ReviewI had fairly high hopes for Professional Penetration Testing (PPT). The book looks very well organized, and it is published in the new Syngress style that is a big improvement over previous years. Unfortunately, PPT should be called "Professional Pen Testing Project Management." The vast majority of this book is about non-technical aspects of pen testing, with the remainder being the briefest overview of a few tools and techniques. You might find this book useful if you either 1) know nothing about the field or 2) are a pen testing project manager who wants to better understand how to manage projects. Those looking for technical content would clearly enjoy a book like Professional Pen Testing for Web Applications by Andres Andreu, even though that book is 3 years older and focused on Web apps.
PPT offers 18 chapters, with 12 chapters on project management and non-technical issues, and 6 ostensibly covering technical issues. The technical material is limited to the basics of conducting reconnaissance, running Nmap, Nessus, CORE IMPACT, Ettercap, Aircrack-ng, Netcat for "maintaining access," SSH for an "encrypted tunnel," and trivial file and script changes to "cover tracks." Seriously. I'm sure some review readers are saying "sometimes it's just that easy." That's true, but we don't need a 528 page book with an outrageous price tag to read about these well-known methods. If your experience with pen testing is limited to this book, take a look at Andres Andreu's title to see the sort of material you should expect in a book on pen testing.
I didn't find the project management parts all that helpful, either. Some of it just repeats material published in various guides like the Open Source Security Testing Methodology Manual. Other sections repeat certification descriptions found on vendor Web sites. It is clear the author really cares about project management, so maybe he should have just written a book on project management for security managers?
I gave the book three stars because I didn't find the book to be technically or managerially incorrect. (If that had been the case, I would have rated it two stars.) If you want much better coverage on technical matters not found in Andreu's book, try the core Hacking Exposed titles. They address the same topics that PPT barely introduces.Professional Penetration Testing: Creating and Operating a Formal Hacking Lab Overview
Save yourself some money! This complete classroom-in-a-book on penetration testing provides material that can cost upwards of $1,000 for a fraction of the price!

Thomas Wilhelm has delivered pen testing training to countless security professionals and now through the pages of this book you can benefit from his years of experience as a professional penetration tester and educator. After reading this book you will be able to create a personal penetration test lab that can deal with real-world vulnerability scenarios.

Penetration testing is the act of testing a network to find security vulnerabilities before they are exploited by phishers, digital piracy groups, and countless other organized or individual malicious hackers. The material presented will be useful to beginners all the way through to advanced practitioners.


Find out how to turn hacking and pen testing skills into a professional career


Understand how to conduct controlled attacks on a network through real-world examples of vulnerable and exploitable servers


Master project management skills necessary for running a formal penetration test and setting up a professional ethical hacking business


Discover metrics and reporting methodologies that provide experience crucial to a professional penetration tester


Learn through video - the DVD includes instructional videos that replicate classroom instruction and live, real-world vulnerability simulations of complete servers with known and unknown vulnerabilities to practice hacking skills in a controlled lab environment



Want to learn more information about Professional Penetration Testing: Creating and Operating a Formal Hacking Lab?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Digital Forensics with Open Source Tools Review

Digital Forensics with Open Source Tools
Average Reviews:

(More customer reviews)
Are you looking to buy Digital Forensics with Open Source Tools? Here is the right place to find the great deals. we can offer discounts of up to 90% on Digital Forensics with Open Source Tools. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Digital Forensics with Open Source Tools ReviewNo dongle? No problem, says it all! Authors, Cory Altheide and Harlan Carvey, deliver a superb, field guide for digital forensic practitioners. This book is not a textbook on how to perform digital forensics, but a guide for the veteran or new forensic examiner to reference, to extend his/her analysis capabilities with open source tools. The authors bring their years of real world experience at practicing digital forensics, into a single publication.
Digital Forensics With Open Source Tools (DFWOST) begins by defining "free" vs. "open" and the digital forensic process, as well as the benefits of using open source tools. DFWOST quickly moves into setting up the examination workstation, that the examiner/analyst will use to perform the digital forensic examination; regardless, of the host operating system of your forensic machine.
While the book is not a textbook on how to perform a digital forensic examination, it does outline basic digital forensic concepts and terminology that the forensic examiner must comprehend to utilize the open source framework that the book mainly focuses upon, The Sleuth Kit.
From here, the book goes into depth with Windows, Linux, and Mac OS X operating systems and how to use open source tools to identify, parse, and "forensicate" the various system artifacts.
The book's final chapter focuses on automating forensic analysis and extending capabilities with open source tools Finally, the appendix is full of free, non-open source tools that you should become familiar with and integrate into your digital forensic toolkit. Remember, there are many ways to skin a cat! [Disclaimer: no kitteh's were harmed in compiling this book review :)]
Here's why I am giving this book a five star review:
1) Altheide and Carvey walk the reader through compiling a forensic examination workstation to utilize for a digital forensic investigation. It's full of tips, command line refreshers, and best practices delivered from experienced digital forensic professionals with perfect symmetry (i.e., "It is best to complete Y, to avoid Z").
2) In regards to symmetry, Altheide and Carvey do an awesome job of describing The Sleuth Kit Tools, breaking down the common TSK prefixes and each layer of TSK tools, which for new examiners can be task within itself. If you are new to TSK, DFWOST is the perfect companion.
3) Altheide and Carvey eliminate the barrier of just having OS specific forensic tools. Linux and Mac OS X users can now play in their own sandbox, using their own toys (Of course, Linux and Mac users knew this all along).
4) Chapter 8 on File Analysis is the longest chapter (41 pages in length), covering analysis of image files, audio and video files, archive files, and documents. This chapter breaks down a file's content and metadata. DFWOST puts file analysis into a practical and digestible format, that a new examiner should be able to apply immediately to a forensic investigation.
5) The book's length, based on the subject matter is spot on and not too cumbersome (255 pages including Appendix on Free, Non Open Tools). Just as Carvey done with Windows Registry Forensics (WRF), Digital Forensics With Open Source Tools (DFWOST) takes a sniper approach on the subject matter. Depending on what type of reader you are, you may knock it out in a single reading session; or, it may take several reading sessions, which will allow you to follow along, complete the examples, and exercises outlined in the book.
6) Lastly, the DFWOST print version that I purchased is signed by both authors. I was able to catch both authors at the Open Source Digital Forensics Conference last week in NoVa. Thank you gentlemen!
The book's content, length, and practical application make it a necessity for the digital forensic examiner's toolkit! Now, go forth and 'forensicate', DFWOST-style!
Digital Forensics with Open Source Tools Overview

Want to learn more information about Digital Forensics with Open Source Tools?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...