Attacking Network Protocols - A Hacker's Guide to Capture, Analysis, and Exploitation
Verlag | No Starch Press |
Auflage | 2017 |
Seiten | 336 |
Format | 17,7 x 23,4 x 2,1 cm |
Gewicht | 634 g |
Artikeltyp | Englisches Buch |
ISBN-10 | 1593277504 |
EAN | 9781593277505 |
Bestell-Nr | 59327750UA |
Attacking Network Protocols is a deep dive into network protocol security from James Forshaw, one of the world s leading bug hunters. This comprehensive guide looks at networking from an attacker s perspective to help you discover, exploit, and ultimately protect vulnerabilities.
You ll start with a rundown of networking basics and protocol traffic capture before moving on to static and dynamic protocol analysis, common protocol structures, cryptography, and protocol security. Then you ll turn your focus to finding and exploiting vulnerabilities, with an overview of common bug classes, fuzzing, debugging, and exhaustion attacks.
Learn how to:
- Capture, manipulate, and replay packets
- Develop tools to dissect traffic and reverse engineer code to understand the inner workings of a network protocol
- Discover and exploit vulnerabilities such as memory corruptions, authentication bypasses, and denials of service
- Use capture and analysis tools like Wi reshark and develop your own custom network proxies to manipulate network traffic
Attacking Network Protocols is a must-have for any penetration tester, bug hunter, or developer looking to understand and discover network vulnerabilities.
Inhaltsverzeichnis:
Introduction
Chapter 1: The Basics of Networking
Chapter 2: Capturing Application Traffic
Chapter 3: Network Protocol Structures
Chapter 4: Developing an Analysis Framework
Chapter 5: Advanced Traffic Capture
Chapter 6: Analysis from the Wire
Chapter 7: Application Reverse Engineering
Chapter 8: Network Protocol Security
Chapter 9: Implementing the Protocol
Chapter 10: Root Causes of Vulnerabilities
Chapter 11: Fuzzing, Debugging, and Exploit Development
Appendix: Binary Protocol Exploiter s Toolkit
Rezension:
"One of the best, if not the best, reference books on this material."
Andrew Swoboda, Tripwire
Very readable and accessible...worth reading even if your only interest in network security is as an applications developer.
I Programmer
"Whether you're a pen tester, fuzzer, or a serene developer seeking understanding of what not to do, this book is an excellent beginner's guide."
Sven Dietrich, IEEE Cipher, Cipher Book Review
"Concise and easy to follow."
Nicky Lim, Goodreads Reviewer