Web Penetration Testing with Kali Linux - Chapter 2 - Reconnaissance.pdf

(1528 KB) Pobierz
Web Penetration Testing with
Kali Linux
Joseph Muniz
Aamir Lakhani
Chapter No. 2
"Reconnaissance"
In this package, you will find:
A Biography of the authors of the book
A preview chapter from the book, Chapter NO.2 "Reconnaissance"
A synopsis of the book’s content
Information on where to buy this book
About the Authors
Joseph Muniz
is a technical solutions architect and security researcher. He started his
career in software development and later managed networks as a contracted technical
resource. Joseph moved into consulting and found a passion for security while meeting
with a variety of customers. He has been involved with the design and implementation
of multiple projects ranging from Fortune 500 corporations to large federal networks.
Joseph runs
TheSecurityBlogger.com
website, a popular resources regarding
security and product implementation. You can also find Joseph speaking at live events
as well as involved with other publications. Recent events include speaker for Social
Media Deception at the 2013 ASIS International conference, speaker for Eliminate
Network Blind Spots with Data Center Security webinar, speaker for Making Bring
Your Own Device (BYOD) Work at the Government Solutions Forum, Washington
DC, and an article on Compromising Passwords in PenTest Magazine – Backtrack
Compendium, July 2013.
For More Information:
www.packtpub.com/web-penetration-testing-with-kali-linux/book
Outside of work, he can be found behind turntables scratching classic vinyl
or on the soccer pitch hacking away at the local club teams.
This book could not have been done without the support of my charming
wife Ning and creative inspirations from my daughter Raylin. I also must
credit my passion for learning to my brother Alex, who raised me along
with my loving parents Irene and Ray. And I would like to give a final
thank you to all of my friends, family, and colleagues who have supported
me over the years.
Aamir Lakhani
is a leading Cyber Security and Cyber Counterintelligence architect.
He is responsible for providing IT security solutions to major commercial and federal
enterprise organizations.
Lakhani leads projects that implement security postures for Fortune 500 companies,
the US Department of Defense, major healthcare providers, educational institutions,
and financial and media organizations. Lakhani has designed offensive counter defense
measures for defense and intelligence agencies, and has assisted organizations in
defending themselves from active strike back attacks perpetrated by underground cyber
groups. Lakhani is considered an industry leader in support of detailed architectural
engagements and projects on topics related to cyber defense, mobile application threats,
malware, and Advanced Persistent Threat (APT) research, and Dark Security. Lakhani
is the author and contributor of several books, and has appeared on National Public Radio
as an expert on Cyber Security.
Writing under the pseudonym Dr. Chaos, Lakhani also operates the
DrChaos.com
blog.
In their recent list of 46 Federal Technology Experts to Follow on Twitter, Forbes
magazine described Aamir Lakhani as "a blogger, infosec specialist, superhero..., and
all around good guy."
I would like to dedicate this book to my parents, Mahmood and Nasreen, and
sisters, Noureen and Zahra. Thank you for always encouraging the little
hacker in me. I could not have done this without your support. Thank you
mom and dad for your sacrifices. I would also additionally like to thank my
friends and colleagues for your countless encouragement and mentorship.
I am truly blessed to be working with the smartest and most dedicated people
in the world.
For More Information:
www.packtpub.com/web-penetration-testing-with-kali-linux/book
Web Penetration Testing with
Kali Linux
Kali is a Debian Linux based Penetration Testing arsenal used by security professionals
(and others) to perform security assessments. Kali offers a range of toolsets customized
for identifying and exploiting vulnerabilities in systems. This book is written leveraging
tools available in Kali Linux released March 13th, 2013 as well as other open
source applications.
Web Penetration Testing with Kali Linux is designed to be a guide for professional
Penetration Testers looking to include Kali in a web application penetration engagement.
Our goal is to identify the best Kali tool(s) for a specific assignment, provide details
on using the application(s), and offer examples of what information could be obtained
for reporting purposes based on expert field experience. Kali has various programs and
utilities; however, this book will focus on the strongest tool(s) for a specific task at the
time of publishing.
The chapters in this book are divided into tasks used in real world web application
Penetration Testing.
Chapter 1, Penetration Testing and Setup,
provides an overview
of Penetration Testing basic concepts, professional service strategies, background on
the Kali Linux environment, and setting up Kali for topics presented in this book.
Chapters 2-6,
cover various web application Penetration Testing concepts including
configuration and reporting examples designed to highlight if topics covered can
accomplish your desired objective.
Chapter 7, Defensive Countermeasures,
serves as a remediation source on systems
vulnerable to attacks presented in previous chapters.
Chapter 8, Penetration Test
Executive Report,
offers reporting best practices and samples that can serve as
templates for building executive level reports. The purpose of designing the book
in this fashion is to give the reader a guide for engaging a web application penetration
with the best possible tool(s) available in Kali, offer steps to remediate vulnerability
and provide how data captured could be presented in a professional manner.
For More Information:
www.packtpub.com/web-penetration-testing-with-kali-linux/book
What This Book Covers
Chapter 1, Penetration Testing and Setup,
covers fundamentals of building a professional
Penetration Testing practice. Topics include differentiating a Penetration Test from
other services, methodology overview, and targeting web applications. This chapter
also provides steps used to set up a Kali Linux environment for tasks covered in
this book.
Chapter 2, Reconnaissance,
provides various ways to gather information about
a target. Topics include highlighting popular free tools available on the Internet
as well as Information Gathering utilities available in Kali Linux.
Chapter 3, Server Side Attacks,
focuses on identifying and exploiting vulnerabilities
in web servers and applications. Tools covered are available in Kali or other
open source utilities.
Chapter 4, Client Side Attacks,
targets hosts systems. Topics include social
engineering, exploiting host system vulnerabilities, and attacking passwords,
as they are the most common means to secure host systems.
Chapter 5, Attacking Authentication,
looks at how users and devices authenticate
to web applications. Topics include targeting the process of managing authentication
sessions, compromising how data is stored on host systems, and man-in-the-middle attack
techniques. This chapter also briefly touches on SQL and Cross-Site Scripting attacks.
Chapter 6, Web Attacks,
explores how to take advantage of web servers and
compromise web applications using exploits such as browser exploitation, proxy
attacks, and password harvesting. This chapter also covers methods to interrupt
services using denial of service techniques.
Chapter 7, Defensive Countermeasures,
provides best practices for hardening your
web applications and servers. Topics include security baselines, patch management,
password policies, and defending against attack methods covered in previous chapters.
This chapter also includes a focused forensics section, as it is important to properly
investigate a compromised asset to avoid additional negative impact.
Chapter 8, Penetration Test Executive Report,
covers best practices for developing
professional post Penetration Testing service reports. Topics include an overview
of methods to add value to your deliverable, document formatting, and templates
that can be used to build professional reports.
For More Information:
www.packtpub.com/web-penetration-testing-with-kali-linux/book
Zgłoś jeśli naruszono regulamin