Acknowledgments |
|
xv | |
Introduction |
|
xvii | |
Chapter 1 Getting Started: Essential Knowledge |
|
1 | (42) |
|
|
2 | (20) |
|
|
2 | (10) |
|
|
12 | (10) |
|
Introduction to Ethical Hacking |
|
|
22 | (11) |
|
|
22 | (6) |
|
|
28 | (5) |
|
|
33 | (10) |
|
|
37 | (3) |
|
|
40 | (3) |
Chapter 2 Reconnaissance: Information Gathering for the Ethical Hacker |
|
43 | (36) |
|
|
44 | (4) |
|
|
46 | (2) |
|
|
48 | (1) |
|
Footprinting Methods and Tools |
|
|
48 | (23) |
|
|
49 | (6) |
|
Website and E-mail Footprinting |
|
|
55 | (3) |
|
|
58 | (9) |
|
|
67 | (3) |
|
|
70 | (1) |
|
|
71 | (8) |
|
|
74 | (2) |
|
|
76 | (3) |
Chapter 3 Scanning and Enumeration |
|
79 | (52) |
|
|
80 | (13) |
|
|
80 | (9) |
|
|
89 | (4) |
|
|
93 | (18) |
|
|
94 | (3) |
|
|
97 | (9) |
|
|
106 | (3) |
|
|
109 | (2) |
|
|
111 | (9) |
|
|
112 | (2) |
|
|
114 | (6) |
|
|
120 | (11) |
|
|
125 | (3) |
|
|
128 | (3) |
Chapter 4 Sniffing and Evasion |
|
131 | (46) |
|
|
132 | (12) |
|
Network Knowledge for Sniffing |
|
|
132 | (11) |
|
Active and Passive Sniffing |
|
|
143 | (1) |
|
Sniffing Tools and Techniques |
|
|
144 | (9) |
|
|
144 | (5) |
|
|
149 | (4) |
|
|
153 | (14) |
|
Devices Aligned Against You |
|
|
153 | (8) |
|
|
161 | (6) |
|
|
167 | (10) |
|
|
172 | (3) |
|
|
175 | (2) |
Chapter 5 Attacking a System |
|
177 | (40) |
|
|
178 | (15) |
|
Windows Security Architecture |
|
|
178 | (9) |
|
Linux Security Architecture |
|
|
187 | (4) |
|
|
191 | (2) |
|
|
193 | (17) |
|
Authentication and Passwords |
|
|
193 | (7) |
|
Privilege Escalation and Executing Applications |
|
|
200 | (3) |
|
Hiding Files and Covering Tracks |
|
|
203 | (7) |
|
|
210 | (7) |
|
|
213 | (3) |
|
|
216 | (1) |
Chapter 6 Web-Based Hacking: Servers and Applications |
|
217 | (38) |
|
|
218 | (16) |
|
|
218 | (4) |
|
|
222 | (1) |
|
|
223 | (6) |
|
|
229 | (5) |
|
Attacking Web Applications |
|
|
234 | (12) |
|
|
235 | (11) |
|
|
246 | (1) |
|
|
246 | (9) |
|
|
250 | (3) |
|
|
253 | (2) |
Chapter 7 Wireless Network Hacking |
|
255 | (32) |
|
|
256 | (16) |
|
Wireless Terminology, Architecture, and Standards |
|
|
256 | (8) |
|
|
264 | (8) |
|
|
272 | (7) |
|
Mobile Platforms and Attacks |
|
|
274 | (3) |
|
|
277 | (2) |
|
|
279 | (8) |
|
|
283 | (2) |
|
|
285 | (2) |
Chapter 8 Security in Cloud Computing |
|
287 | (18) |
|
|
288 | (11) |
|
|
292 | (3) |
|
|
295 | (4) |
|
|
299 | (6) |
|
|
302 | (2) |
|
|
304 | (1) |
Chapter 9 Trojans and Other Attacks |
|
305 | (34) |
|
|
306 | (13) |
|
|
308 | (5) |
|
|
313 | (6) |
|
|
319 | (9) |
|
|
320 | (3) |
|
|
323 | (5) |
|
|
328 | (11) |
|
|
334 | (2) |
|
|
336 | (3) |
Chapter 10 Cryptography 101 |
|
339 | (40) |
|
Cryptography and Encryption Overview |
|
|
340 | (11) |
|
Encryption Algorithms and Techniques |
|
|
341 | (10) |
|
PKI, the Digital Certificate, and Digital Signatures |
|
|
351 | (8) |
|
|
352 | (3) |
|
|
355 | (3) |
|
|
358 | (1) |
|
Encrypted Communication and Cryptography Attacks |
|
|
359 | (11) |
|
|
362 | (6) |
|
|
368 | (2) |
|
|
370 | (9) |
|
|
373 | (4) |
|
|
377 | (2) |
Chapter 11 Low Tech: Social Engineering and Physical Security |
|
379 | (30) |
|
|
380 | (16) |
|
|
381 | (6) |
|
|
387 | (7) |
|
|
394 | (2) |
|
|
396 | (7) |
|
|
396 | (7) |
|
|
403 | (6) |
|
|
405 | (3) |
|
|
408 | (1) |
Chapter 12 The Pen Test: Putting It All Together |
|
409 | (18) |
|
|
410 | (12) |
|
|
411 | (8) |
|
Security Assessment Deliverables |
|
|
419 | (1) |
|
|
420 | (1) |
|
|
420 | (2) |
|
|
422 | (5) |
|
|
424 | (2) |
|
|
426 | (1) |
Appendix A Tool, Sites, and References |
|
427 | (22) |
|
Vulnerability Research Sites |
|
|
427 | (1) |
|
|
428 | (2) |
|
|
428 | (1) |
|
|
428 | (1) |
|
Tracking Online Reputation |
|
|
428 | (1) |
|
Website Research/Web Updates Tools |
|
|
429 | (1) |
|
|
429 | (1) |
|
Traceroute Tools and Links |
|
|
429 | (1) |
|
Website Mirroring Tools and Sites |
|
|
430 | (1) |
|
|
430 | (1) |
|
|
430 | (1) |
|
Scanning and Enumeration Tools |
|
|
430 | (5) |
|
|
430 | (1) |
|
|
431 | (1) |
|
|
431 | (1) |
|
|
432 | (1) |
|
|
432 | (1) |
|
Proxy, Anonymizer, and Tunneling |
|
|
432 | (1) |
|
|
433 | (1) |
|
|
433 | (1) |
|
|
434 | (1) |
|
|
434 | (1) |
|
|
434 | (1) |
|
Windows Service Monitoring Tools |
|
|
434 | (1) |
|
File/Folder Integrity Checkers |
|
|
434 | (1) |
|
|
435 | (4) |
|
Default Password Search Links |
|
|
435 | (1) |
|
|
435 | (1) |
|
|
435 | (1) |
|
|
436 | (1) |
|
Keyloggers and Screen Capture |
|
|
436 | (1) |
|
|
436 | (1) |
|
|
437 | (1) |
|
|
437 | (1) |
|
|
437 | (1) |
|
|
438 | (1) |
|
|
438 | (1) |
|
|
438 | (1) |
|
|
438 | (1) |
|
Cryptography and Encryption |
|
|
439 | (1) |
|
|
439 | (1) |
|
|
439 | (1) |
|
|
439 | (1) |
|
|
440 | (1) |
|
|
440 | (1) |
|
|
440 | (1) |
|
|
440 | (1) |
|
|
441 | (1) |
|
|
441 | (1) |
|
|
441 | (1) |
|
|
441 | (3) |
|
|
441 | (1) |
|
|
441 | (1) |
|
|
442 | (1) |
|
|
442 | (1) |
|
|
442 | (1) |
|
|
442 | (1) |
|
Mobile Wireless Discovery |
|
|
443 | (1) |
|
|
443 | (1) |
|
|
443 | (1) |
|
|
443 | (1) |
|
|
444 | (1) |
|
Anti-Malware (AntiSpyware and Anitvirus) |
|
|
444 | (1) |
|
|
444 | (1) |
|
|
444 | (1) |
|
|
445 | (1) |
|
|
445 | (1) |
|
|
445 | (1) |
|
|
446 | (1) |
|
|
446 | (1) |
|
|
446 | (1) |
|
|
446 | (1) |
|
|
446 | (1) |
|
|
447 | (1) |
|
|
447 | (1) |
|
|
447 | (1) |
|
|
447 | (1) |
|
|
447 | (1) |
|
Tools, Sites, and References Disclaimer |
|
|
447 | (2) |
Appendix B About the CD-ROM |
|
449 | (2) |
|
|
449 | (1) |
|
Installing and Running Total Tester |
|
|
449 | (1) |
|
|
449 | (1) |
|
|
450 | (1) |
|
|
450 | (1) |
Glossary |
|
451 | (32) |
Index |
|
483 | |