Cart
Free Shipping in Australia
Proud to be B-Corp

Penetration Testing Kevin M. Henry

Penetration Testing By Kevin M. Henry

Penetration Testing by Kevin M. Henry


$65.99
Condition - New
Only 2 left

Summary

This book is a preparation guide for the CPTE examination, yet is also a general reference for experienced penetration testers, ethical hackers, auditors, security personnel and anyone else involved in the security of an organization's computer systems.

Penetration Testing Summary

Penetration Testing: Protecting Networks and Systems by Kevin M. Henry

Penetration testing is the simulation of an unethical attack of a computer system or other facility in order to prove the vulnerability of that system in the event of a real attack. The Certified Penetration Testing Engineer (CPTE) examination is a widely recognized certification for penetration testers. Penetration Testing: Protecting networks and systems is a preparation guide for the CPTE examination. It describes the range of techniques employed by professional pen testers, and also includes advice on the preparation and delivery of the test report. The author's in-the-field experiences, combined with other real-world examples, are used to illustrate common pitfalls that can be encountered during testing and reporting. Special attention is also paid to new technologies that improve business operations, but which can create new vulnerabilities, such as employee remote access, wireless communications and public-facing web applications. This book will give you a better understanding of how to conduct a penetration test, and also how to deliver a client-focused report that assesses the security of the system and whether the level of risk to the organization is within acceptable levels. Kevin Henry has 35 years' experience working on computer systems, initially as a computer operator, and then in various programmer and analyst roles, before moving into audit and security. Kevin currently provides security auditing, training and educational programs for major clients and governments around the world and is a frequent speaker on the security conference circuit. A business-aligned approach to penetration testing!

About Kevin M. Henry

Kevin Henry has 35 years' experience working on computer systems, initially as an operator on the largest mini-computer installation in Canada, and then in various programmer and analyst roles before moving into computer audit and security. Kevin currently provides security auditing, training and educational programs for major clients and governments around the world and is a frequent speaker on the security conference circuit.

Table of Contents

Introduction Chapter 1: Introduction to Penetration Testing Case study Security basics Risk management The threat environment Overview of the steps to penetration testing Penetration testing versus hacking Benefits of penetration testing Summary Key learning points Questions Chapter 2: Preparing to Conduct a Penetration Test Approval and scope Planning Summary Questions Chapter 3: Reconnaissance The start of the test Physical information gathering Other data sources Avoiding footprinting Key learning points Questions Chapter 4: Active Reconnaissance and Enumeration Port scanning Countermeasures to active reconnaissance Key learning points Questions Chapter 5: Vulnerability Assessments The attack vectors References and sources of vulnerabilities Using vulnerability assessment tools PCI DSS requirements Malicious code Reporting on the vulnerability assessment Key learning points Questions Chapter 6: Hacking Windows(R) and UNIX Having fun Common hacking initiatives Defeating data theft Protecting against unauthorized access Access controls Actions of the attacker Focus on UNIX/Linux Advanced attacks Source code review Case study: Attack on a Chinese bank Key learning points Questions Chapter 7: Launching the Attack Steps to an exploit Attacking wireless networks Pen testing wireless Network sniffing Firewalls Intrusion detection and prevention systems (IDS/IPS). Key learning points Questions Chapter 8: Attacking Web Applications The steps in attacking a web application Questions Chapter 9: Preparing the Report Determining risk levels Risk response Report confidentiality Delivering the report Key learning points Questions Appendix 1: Linux Appendix 2: Encryption Concepts of cryptography Appendix 3: Regulations and Legislation Examples of regulations and legislation Protection of intellectual property Appendix 4: Incident Management Concepts of incident management Additional Questions and Answers Answers References ITG Resources

Additional information

NLS9781849283717
9781849283717
1849283710
Penetration Testing: Protecting Networks and Systems by Kevin M. Henry
New
Paperback
IT Governance Publishing
2012-06-21
211
N/A
Book picture is for illustrative purposes only, actual binding, cover or edition may vary.
This is a new book - be the first to read this copy. With untouched pages and a perfect binding, your brand new copy is ready to be opened for the first time

Customer Reviews - Penetration Testing