The Shellcoder's Handbook(2e druk 2007)
Samenvatting
In the technological arena, three years is a lifetime. Since the first edition of this book was published in 2004, built-in security measures on compilers and operating systems have become commonplace, but are still fat from perfect. Arbitrary-code execution vulnerabilities still allow attackers to run code of their choice o your system-with disastrous results.
In a nutshell this book is about code and data and what happens when the two become confused. You'll work with the basic building blocks of security bugs-assembler, source code, the stack, the heap, and so on. You'll experiment, explore, and understand the system you're running-and how to better protect them.
- Become familiar with security holes in windows, Linux, Solaris, Mac OS X, and Cisco's IOS
- Learn how to write customized tools to protect your systems, not just how to use ready-made ones
- Use a working exploit to verify your assessment when auditing a network
- Use proof-of-concept exploits to rate the significance of bugs in software you're developing
- Assess the quality of purchased security products by performing penetration tests based on the information in this book
- Understand how bugs are found and how exploit work at the lowest level
Specificaties
Inhoudsopgave
Acknowledgments.
Introduction to the Second Edition.
Part 1: Introduction to Exploitation: Linux on x86.
1. Before You Begin.
2. Stack Overflows.
3. Shellcode.
4. Introduction to Format String Bugs.
5. Introduction to Heap Overflows.
Part 2: Other Platforms-Windows, Solaris, OS/X, and Cisco.
6. The Wild World of Windows.
7. Windows Shellcode.
8. Windows Overflows.
9. Overcoming Filters.
10. Introduction to Solaris Exploitation.
11. Advanced Solaris Exploitation.
12. OS X Shellcode.
13. Cisco IOS Exploitation.
14. Protection Mechanisms.
Part 3: Vulnerability Discovery.
15. Establishing a Working Environment.
16. Fault Injection.
17. The Art of Fuzzing.
18. Source Code Auditing: Finding Vulnerabilities in C-Based Languages.
19. Instrumented Investigation: A Manual Approach.
20. Tracing for Vulnerabilities.
21. Binary Auditing: Hacking Closed Source Software.
Part 4: Advanced Materials.
22. Alternative Payload Strategies.
23. Writing Exploits that Work in the Wild.
24. Attacking Database Software.
25. Unix Kernel Overflows.
26. Exploiting Unix Kernel Vulnerabilities.
27. Hacking the Windows Kernel.
Index.
Anderen die dit boek kochten, kochten ook
Net verschenen
Rubrieken
- aanbestedingsrecht
- aansprakelijkheids- en verzekeringsrecht
- accountancy
- algemeen juridisch
- arbeidsrecht
- bank- en effectenrecht
- bestuursrecht
- bouwrecht
- burgerlijk recht en procesrecht
- europees-internationaal recht
- fiscaal recht
- gezondheidsrecht
- insolventierecht
- intellectuele eigendom en ict-recht
- management
- mens en maatschappij
- milieu- en omgevingsrecht
- notarieel recht
- ondernemingsrecht
- pensioenrecht
- personen- en familierecht
- sociale zekerheidsrecht
- staatsrecht
- strafrecht en criminologie
- vastgoed- en huurrecht
- vreemdelingenrecht