Hacknotes - Windows Security Portable Reference (2003).pdf

(4918 KB) Pobierz
HACKNOTES
—Joel
Scambray,
coauthor of
Hacking Exposed 4
th
Edition, Hacking
Exposed Windows 2000,
and
Hacking Exposed Web Applications;
Senior Director of Security, Microsoft’s MSN
“HackNotes
Windows Security Portable Reference
distills into a small form factor
the encyclopedic information in the original
Hacking Exposed: Windows 2000.”
“HackNotes
Windows Security Portable Reference
takes a ‘Just the Facts,
Ma’am’ approach to securing your Windows infrastructure. It checks the overly
long exposition at the door, focusing on specific areas of attack and defense.
If you’re more concerned with securing systems than speed-reading
thousand-page tech manuals, stash this one in your laptop case now.”
—Chip
Andrews,
www.sqlsecurity.com, Black Hat Speaker, and
coauthor of
SQL Server Security
“No plan, no matter how well-conceived, survives contact with the enemy.
That’s why Michael O’Dea’s
HackNotes Windows Security Portable Reference
is a must-have for today’s over-burdened, always-on-the-move security
professional. Keep this one in your hip pocket. It will help you prevent your
enemies from gaining the initiative.”
—Dan
Verton,
author of
Black Ice: The Invisible Threat of
Cyber-Terrorism
and award-winning senior writer for
Computerworld
“HackNotes
Windows Security Portable Reference
covers very interesting
and pertinent topics, especially ones such as common ports and services,
NetBIOS name table definitions, and other very specific areas that are essential
to understand if one is to genuinely comprehend how Windows systems are
attacked. Author Michael O’Dea covers not only well-known but also more
obscure (but nevertheless potentially dangerous) attacks. Above all else, he
writes in a very clear, well-organized, and concise style—a style that very few
technical books can match.”
—Dr.
Eugene Schultz, Ph.D., CISSP, CISM,
Principle Computer Systems
Engineer, University of California-Berkeley, Prominent SANS speaker
About the Author
Michael O’Dea
is Project Manager of Product Services for the security firm
Foundstone, Inc. Michael has been immersed in information technology for
over 10 years, working with technologies such as enterprise data encryption, vi-
rus defense, firewalls, and proxy service solutions on a variety of UNIX and
Windows platforms. Currently, Michael develops custom integration solutions
for the Foundstone Enterprise vulnerability management product line. Prior to
joining Foundstone, Michael worked as a senior analyst supporting Internet se-
curity for Disney Worldwide Services, Inc., the data services arm of the Walt
Disney Company; and as a consultant for Network Associates, Inc., Michael has
contributed to many security publications, including
Hacking Exposed: Fourth
Edition
and
Special Ops: Internal Network Security.
About the Technical Editor
Arne Vidström
is an IT Security Research Scientist at the Swedish Defence Re-
search Agency. Prior to that he was a Computer Security Engineer at the
telecom operator Telia, doing penetration testing, source code security reviews,
security configuration testing, and creation of security configuration checklists.
Arne holds a University Diploma in Electronic Engineering and a B.Sc. in Math-
ematics from the University of Karlstad. In his spare time he runs the Windows
security web site ntsecurity.nu, where he publishes his own freeware security
tools and vulnerability discoveries.
HACKNOTES
Windows
MICHAEL
O’DEA
McGraw-Hill/Osborne
New York Chicago San Francisco
Lisbon London Madrid Mexico City Milan
New Delhi San Juan Seoul Singapore Sydney Toronto
McGraw-Hill/Osborne
th
2100 Powell Street, 10 Floor
Emeryville, California 94608
U.S.A.
To arrange bulk purchase discounts for sales promotions, premiums, or fund-
raisers, please contact
McGraw-Hill/Osborne
at the above address. For informa-
tion on translations or book distributors outside the U.S.A., please see the Interna-
tional Contact Information page immediately following the index of this book.
HackNotes Windows Security Portable Reference
Copyright © 2003 by The McGraw-Hill Companies. All rights reserved. Printed
in the United States of America. Except as permitted under the Copyright Act of
1976, no part of this publication may be reproduced or distributed in any form
or by any means, or stored in a database or retrieval system, without the prior
written permission of publisher, with the exception that the program listings
may be entered, stored, and executed in a computer system, but they may not be
reproduced for publication.
1234567890 DOC DOC 019876543
ISBN 0-07-222785-0
Publisher
Brandon A. Nordin
Vice President & Associate Publisher
Scott Rogers
Editorial Director
Tracy Dunkelberger
Executive Editor
Jane K. Brownlow
Project Editor
Jennifer Malnick
Executive Project Editor
Mark Karmendy
Acquisitions Coordinator
Athena Honore
Technical Editor
Arne Vidström
Series Editor
Mike Horton
Copy Editor
Andrea Boucher
Proofreader
Linda Medoff
Indexer
Jack Lewis
Composition
Lucie Ericksen
John Patrus
Illustrators
Kathleen Edwards
Dick Schwartz
Lyssa Wald
Series Design
Dick Schwartz
Peter F. Hancik
Cover Series Design
Dodie Shoemaker
TM
®
This book was composed with Corel VENTURA™ Publisher.
Information has been obtained by
McGraw-Hill/Osborne
from sources believed to be reliable. However,
because of the possibility of human or mechanical error by our sources,
McGraw-Hill/Osborne,
or others,
McGraw-Hill/Osborne
does not guarantee the accuracy, adequacy, or completeness of any information and is
not responsible for any errors or omissions or the results obtained from the use of such information.
Zgłoś jeśli naruszono regulamin