The Penetration Tester's Guide
by David Kennedy, Jim O’Gorman, Devon Kearns, and Mati Aharoni July 2011, 328 pp. ISBN: 978-1-59327-288-3
The Metasploit Framework makes discovering, exploiting, and sharing vulnerabilities quick and relatively painless. But while Metasploit is used by security professionals everywhere, the tool can be hard to grasp for first-time users. Metasploit: The Penetration Tester's Guide fills this gap by teaching you how to harness the Framework and interact with the vibrant community of Metasploit contributors. Once you've built your foundation for penetration testing, you’ll learn the Framework's conventions, interfaces, and module system as you launch simulated attacks. You’ll move on to advanced penetration testing techniques, including network reconnaissance and enumeration, client-side attacks, wireless attacks, and targeted social-engineering attacks. Learn how to:
You'll even touch on exploit discovery for zero-day research, write a fuzzer, port existing exploits into the Framework, and learn how to cover your tracks. Whether your goal is to secure your own networks or to put someone else's to the test, Metasploit: The Penetration Tester's Guide will take you there and beyond. About the AuthorDavid Kennedy is Chief Information Security Officer at Diebold Incorporated and creator of the Social-Engineer Toolkit (SET), Fast-Track, and other open source tools. He is on the Back|Track and Exploit-Database development team and is a core member of the Social-Engineer podcast and framework. Kennedy has presented at a number of security conferences including Black Hat, DEF CON, ShmooCon, Security B-Sides, and more. Jim O'Gorman (Elwood) is a professional penetration tester, an instructor at Offensive Security, and manages Offensive Security’s consulting services. Jim has lived online from the times of BBS’s, to FidoNet, to when SLIP connections were the new hotness. Jim spends time on network intrusion simulation, digital investigations, and malware analysis. When not working on various security issues, Jim spends his time assisting his children in their attempts to fight Zombie hordes. Devon Kearns is an instructor at Offensive-Security, a Back|Track Linux developer, and administrator of The Exploit Database. He has contributed a number of Metasploit exploit modules and is the maintainer of the Metasploit Unleashed wiki. Mati Aharoni is the creator of the Back|Track Linux distribution and founder of Offensive-Security, the industry leader in security training. Table of ContentsChapter 1: The Absolute Basics of Penetration Testing View the detailed Table of Contents (PDF) View the Index (PDF) (top)Reviews"Takes current documentation further and provides a valuable resource for people who are interested in security but don't have the time or money to take a training class on Metasploit. Rating: 10/10" "Metasploit: The Penetration Tester's Guide is a great book about the Metasploit Framework." "For anyone who wants to get involved in the mechanics of penetration testing with Metasploit, this book is an excellent resource." "My recommendation: Get this book." "Very comprehensive and packed full of great advice." "Whether you are a penetration tester or a technical security professional, quality time spent working through this book will add valuable tools and insight to your professional repertoire." "For those looking to use the Metasploit to its fullest, Metasploit: The Penetration Tester's Guide is a valuable aid." "In case you've never used Metasploit or have limited experience with it, I highly recommend the No Starch Press book Metasploit: The Penetration Tester's Guide. It's a great book to get people started, has examples to walk through, and includes more advanced topics for experienced users." "This book provides all the key information you need to get going with Metasploit in one easily read and referenced package." "This title is nothing less than masterful; there is no nook or cranny for the program and its various third-party addons that is not covered." "What I really liked about the book was the incorporation of the Metasploit tools and capabilities with a penetration testing methodology." "A big thumbs up from me. It was worth every penny to learn the bits I did and to add clarity to other areas." "If you are new to Metasploit and want to get up to speed quickly, it's hard to imagine that you'll find a better book." "[The four co-authors] have rolled out their combined knowledge and experience in a smooth flow of chapters written in a straightforward, accessible style." "Whereas a lot of technology books make you feel like you're back in the class room, this one made me feel like I was down at my local coffee shop having a chat with four very good friends." "Should be on the shelf of any serious computer security professional." "The chapters are sized perfectly, giving the reader just enough time to become proficient in many of the different aspects of Metasploit." "Not only is this a great book for people looking into pentesting, it's also a great book to raise security awareness and how (easy) of a target you can be if you're not careful. Highly recommend." "An invaluable resource to get those that are new to this tool up and running while also providing experts with a great resource to turn to when help or ideas are needed." "The craft of penetration testing is covered deeply and broadly. The book's greatest source of value is how the concepts being applied are explained and demonstrated with well-annotated examples." "The book is written with a hands-on, tutorial-like style that is great for people like me who prefer to learn by doing." "On the short list of books I would recommend to any security practitioner." |
|||


