The Basics of Hacking and Penetration Testing: Ethical Ha... and over one million other books are available for Amazon Kindle. Learn more

Vous voulez voir cette page en français ? Cliquez ici.

Have one to sell? Sell yours here
Start reading The Basics of Hacking and Penetration Testing on your Kindle in under a minute.

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

The Basics of Hacking and Penetration Testing: Ethical Hacking and Penetration Testing Made Easy [Paperback]

Patrick Engebretson
5.0 out of 5 stars  See all reviews (1 customer review)

Available from these sellers.


Formats

Amazon Price New from Used from
Kindle Edition CDN $17.65  
Paperback --  
Save Up to 90% on Textbooks
Hit the books in Amazon.ca's Textbook Store and save up to 90% on used textbooks and 35% on new textbooks. Learn more.
There is a newer edition of this item:
The Basics of Hacking and Penetration Testing: Ethical Hacking and Penetration Testing Made Easy The Basics of Hacking and Penetration Testing: Ethical Hacking and Penetration Testing Made Easy 4.0 out of 5 stars (2)
CDN$ 29.95
In Stock.
Join Amazon Student in Canada


Book Description

July 21 2011 1597496553 978-1597496551 1

The Basics of Hacking and Penetration Testing serves as an introduction to the steps required to complete a penetration test or perform an ethical hack. You learn how to properly utilize and interpret the results of modern day hacking tools; which are required to complete a penetration test. Tool coverage will include, Backtrack Linux, Google, Whois, Nmap, Nessus, Metasploit, Netcat, Netbus, and more. A simple and clean explanation of how to utilize these tools will allow you  to gain a solid understanding of each of the four phases and prepare them to take on more in-depth texts and topics. This book includes the use of a single example (pen test target) all the way through the book which allows you to clearly see how the tools and phases relate.

  • Named a 2011 Best Hacking and Pen Testing Book by InfoSec Reviews
  • Each chapter contains hands-on examples and exercises that are designed to teach you how to interpret the results and utilize those results in later phases.
  • Writen by an author who works in the field as a Penetration Tester and who teaches Offensive Security, Penetration Testing, and Ethical Hacking, and Exploitation classes at Dakota State University.
  • Utilizes the Backtrack Linus distribution and focuses on the seminal tools required to complete a penetration test.

Customers Who Bought This Item Also Bought


Product Details


Product Description

Review

"Although this book is ideal for beginners, most security professionals will have been involved with penetration testing during some point in their career. This book is thus an excellent refresher for those of us who fondly recall Nmap, Nessus and Netcat as being the tools of choice for both whitehat and blackhat hackers, but have long-since forgotten the full command-line syntax and would benefit from a refresh. Patrick Engebretson gets the reader involved in the art of hacking from page one and makes this book a fascinating and productive read."--Best Hacking and Pen Testing Books in InfoSecReviews Book Awards

"Have you heard of penetration testing but have no idea what it entails? This is the perfect book to get you started, easy to read, does not assume prior knowledge, and is up-to-date. I strongly recommend Pat's latest work."--Jared DeMott, Principle Security Researcher, Crucial Security, Inc.

"If you are searching for a book to get you started with penetration testing, 'The Basics of Hacking and Penetration Testing' is the right one. It assumes little and gives a lot, and doesn't require huge amounts of technical knowledge in order to be read or understood. As complex the subject may sound to novices, the author does a great job explaining it. He eschews techno-babble and when he repeatedly returns to some issues, it's because he has more to say about them, not because he can't think about what to right next."--Help Net Security

"This book offers a broad overview of basic concepts of hacking and penetration testing for readers with no previous background. It outlines a four-phase model of conducting a penetration test, or an 'ethical hack,' and shows how to use such hacking tools as Backtrack Linux, Hacker Defender, and MetGooFil. A sequential example throughout the book demonstrates how the tools and phases work together. The book includes chapter introductions and summaries, b&w screenshots, examples and exercises, and recommended resources."--SciTech Book News

"If you are an information security beginner with some experience in computer technology, especially networking, I would recommend this book. If you are an intermediate level pen tester or an advanced tester, you might not find this book as useful. That being said, it never hurts to browse through the book and see if any new tools or technology are mentioned here that warrant a closer look. As mentioned earlier, penetration testing is an ever growing field and it is quite possible that as an expert, you might have missed something new. This book introduces you to just enough tools and technology to get your feet wet. If this kind of testing gives you a thrill, then you might want to look into more advanced topics and resources. If this is the only resource you used to escalate your interest in pen testing, then you have no one else but the author to thank for it."--PenTest Extra Magazine Vol. 2, No. 3, June

From the Back Cover

The Basics of Hacking and Penetration Testing serves as an introduction to the steps required to complete a penetration test or perform an ethical hack from beginning to end. No prior hacking experience is needed. You learn how to properly utilize and interpret the results of modern day hacking tools, which are required to complete a penetration test. Tool coverage includes Backtrack Linux, Google reconnaissance, MetaGooFil, dig, Nmap, Nessus, Metasploit, Fast Track Autopwn, Netcat, Hacker Defender rootkit, and more. A simple and clean explanation of how to effectively utilize these tools as well as the introduction to a four-step methodology for conducting a penetration test or hack, will provide you with know-how required to jump start your career or gain a better understanding of offensive security. The book serves as an introduction to penetration testing and hacking and will provide you with a solid foundation of knowledge. After completing the book readers will be prepared to take on in-depth and advanced topics in hacking and penetration testing. The book walks through each of the steps and tools in a structured, orderly manner allowing readers to understand how the output from each tool can be fully utilized in the subsequent phases of the penetration test. This process allows readers to clearly see how the tools and phases relate.

    • Each chapter contains hands-on examples and exercises that are designed to teach you how to interpret the results and utilize those results in later phases
    • Written by an author who works in the field as a Penetration Tester and who teaches Offensive Security, Penetration Testing, and Ethical Hacking, and Exploitation classes at Dakota State University
    • Utilizes the Backtrack Linux distribution and focuses on the seminal tools required to complete a penetration test

Inside This Book (Learn More)
Browse Sample Pages
Front Cover | Copyright | Table of Contents | Excerpt | Index
Search inside this book:


Customer Reviews

4 star
0
3 star
0
2 star
0
1 star
0
5.0 out of 5 stars
5.0 out of 5 stars
Most helpful customer reviews
1 of 1 people found the following review helpful
5.0 out of 5 stars Great place to start Feb. 11 2012
By user
Format:Paperback
I started by being curious about pen test or hacking my computers. I got this book and was very glad to see that they start from the ground. Remember that this is a starting point type of book. It goes through some of the tools you'll need and how to gather information. Also it explains how to practice these skills. Very good place to start.
Was this review helpful to you?
Most Helpful Customer Reviews on Amazon.com (beta)
Amazon.com: 4.4 out of 5 stars  74 reviews
51 of 55 people found the following review helpful
5.0 out of 5 stars Excellent book - Delivers on the Title Aug. 15 2011
By jlh - Published on Amazon.com
Format:Paperback|Verified Purchase
This is a really great book that delivers on the promise described in the title. It covers the basics of hacking and penetration test and makes no assumption of prior security or hacking knowledge. This is an excellent resource for anyone looking to jumpstart his or her knowledge in this area.

The book takes the reader on a quick step-by-step journey through a penetration test beginning with Information Gathering, moving into Scanning, then Exploitation, and concluding with Report Writing. While the book does not cover any particular methodology like OSSTM or PTES it does a nice job of laying out each step in an orderly and straightforward manner. The book covers all of the major tools, in an appropriate order so the reader gets a good sense of how to run the tools and how they relate to each other.

The book gets down to business in chapter 1 and wastes no time in bringing the reader up to speed on the latest tools and techniques. One of the greatest strengths of the book is its size. Most people will be able to read through the entire book in just a few days. Another benefit of covering only the basics is that the book should have a longer shelf life. As the author points out, a Nmap Syn scan has been the same for the past 10 years.

If you're looking for an in-depth coverage of any particular tool like Nmap, Metasploit, or the like, this is not the book for you. You're better off buying a book dedicated to the tool you're interested in.

On the flip side, if you're interested in seeing the whole picture and getting a feel for how to run and use the major tools used in a basic penetration test this is a good buy.

Finally, I enjoyed the laidback and casual writing style of the author. This made the chapters easier to digest and kept me interested while still delivering enough technical meat to satisfy my knowledge and process requirements.
22 of 24 people found the following review helpful
5.0 out of 5 stars A delicious sip of network security and PEN test Oct. 10 2011
By Jose - Published on Amazon.com
Format:Paperback|Verified Purchase
Very easy to read, very fun and interesting! I'm more into databases but the way everything integrates now in the current IT world, I realized that I need to get a better understanding of how to protect my database servers (or provide additional value to my Projects), network or at least, being able to discuss about security with my network team without feeling lost. This books is about how to protect yourself from the very "nasty" and "wild" Internet world we all are living in. It will change your false sense of security at work or home, trust me! Even though this is not an in-depth volume about PEN testing tools or techniques, this book delivers what is promised on the cover and much more!

All chapters are very coherent, meticously structured and nicely integrated between each other thanks to the PEN test process it follows. There are even suggestions about how to test all the examples in a secure and practical way. Of course, a virtual lab using any of the virtualization technologies is highly advised. The author suggests VMware, I used Parallels, but there are several free tools out there including Virtual PC or VirtualBox, both are free as well.

The book uses Metasploit framework/software for its examples but makes strong emphasize on concepts rather than tools, which it is very good in my opinion because whatever is being taught can be later extrapolated using other tools. PEN test is more a process than mere scripts and tools. I also like the fact that you don't need a very strong knowledge on networking, cryptography or C++ in order to understand this book. Instead It relies on easy vocabulary with lot of examples and screen-shoots that help almost anyone who is new into this field (a basic knowledge of Linux won't hurt though, that made it easy for me to understand some commands)

-- Additional bibliography --

Once you're done with this one I recommend these two books: Metasploit: The Penetration Tester's Guide, by David Kennedy and Nmap Cookbook: The Fat-free Guide to Network Scanning. The 1st one expands a bit more on the Metasploit software and its components, which are briefly explained on the Syngress book. The Nmap cookbook, talks about nmap scanning tool and different switches you can use when working on the scanning phase; nmap cookbook is not a theory book, but visual examples of how to use the tool depending of the target or desired goal
19 of 23 people found the following review helpful
5.0 out of 5 stars Really helped my understanding of Penetration Testing Aug. 19 2011
By Frederick Schmidt - Published on Amazon.com
Format:Paperback|Verified Purchase
I work for a small company with little resources for security when it comes to protection against people with malicious intent. We run our own web and data servers and have been hacked on at least on occasion. This book really helped me learn how to test my network for weaknesses. Gave me best practice tips for protecting our servers against unwanted penetration. Most of all it showed me how little I new about how easy it was to penetrate our network even with off the shelf applications. This book is a must for small businesses trying to run big business operations.
28 of 36 people found the following review helpful
3.0 out of 5 stars This book is confused on what it is and what it is doing March 23 2012
By GK - Published on Amazon.com
Format:Paperback|Verified Purchase
Pros:
Some good introductions to ideas and tools of penetration testing.

Cons:
Not coherent or consistent at times.

This book starts and finishes well, but the middle is insufficient in information and lacks consistency. More than once in the penetration/exploit sections I had to check to see if I was missing a page. The biggest problem with coherence in the book has to do with the fact that the author explains that most pen tests will be done from the outside, but then out of nowhere switches from penetration testing to hacking a machine while actually sitting at it! The author would talk about what could be done from the outside, but then go on to how it is done from the inside (physically at the machine) with no explanation for the jump. I more than once had to check to see if I was missing a page, because the jumps were that drastic. Also many of the screen shots are not placed well, to the point where you have to stop reading and find the reference screenshot.

While there is a decent amount of good introductive information for those looking to get into or just learn about penetration testing, this book falls horribly short of what it could and should be. Bottom line, if you have no or little knowledge of penetration testing there is enough in this book to introduce you to some concepts and tools used in penetration testing. However this book is seriously lacking for anyone that is more than a novice.
6 of 7 people found the following review helpful
5.0 out of 5 stars Interesting, Informative, and Brief - Excellent intro to Ethical Hacking Feb. 13 2012
By Jim Johnson - Published on Amazon.com
Format:Paperback|Verified Purchase
This book is a very interesting and informative read. I followed all of the steps almost verbatim and everything worked as written. The contents of the book have already been reviewed, and I don't find it necessary to regurgitate. I agree with the good reviews, this book rocks.

Here's a couple of tips:

1. Acquire a copy of Windows XP with no Service Pack (They are difficult to find, but keep looking. It is worth the wait). A pre Service Pack XP is an easy target using the steps outlined in the book. If you can't find a pre-SP XP, at least try to find one that doesn't yet have patch MS08-067. This patch makes for an easy win, which will motivate you to learn more. I think this is the patch used in the book for the example.

2. Get a computer capable of running Backtrack as the Host OS, and then proceed to load multiple Guest OSes into VMWare Player. VMWare Player is a free download from VMWare, and the best choice I have found for running virtual machines (Virtual Box is good but doesn't run multiple VMs at once). Also, you can make copies of the parent folder of the VM in order to keep a fresh, untainted copy for incredibly easy restoration after you've jacked it up.

3. Do all of the exercises in the book! It isn't enough to just read about it. You need to do it. This will make reading the book take 4 times longer but you will get 10 times more out of it. It's ok to read through the book and then go back, but my experience has shown that doing while reading is by far the more productive/efficient approach.

Have fun!
Search Customer Reviews
Only search this product's reviews

Look for similar items by category


Feedback