Advanced penetration testing : hacking the world's most secure networks / / Wil Allsopp
| Advanced penetration testing : hacking the world's most secure networks / / Wil Allsopp |
| Autore | Allsopp Wil |
| Pubbl/distr/stampa | Indianapolis, Indiana : , : Wiley, , 2017 |
| Descrizione fisica | 1 online resource (287 pages) : illustrations (some color), tables |
| Disciplina | 005.8092 |
| Collana | THEi Wiley ebooks. |
| Soggetto topico |
Penetration testing (Computer security)
Computer networks - Security measures |
| ISBN |
1-119-36766-2
1-119-36774-3 1-119-36771-9 |
| Formato | Materiale a stampa |
| Livello bibliografico | Monografia |
| Lingua di pubblicazione | eng |
| Record Nr. | UNINA-9910271050203321 |
Allsopp Wil
|
||
| Indianapolis, Indiana : , : Wiley, , 2017 | ||
| Lo trovi qui: Univ. Federico II | ||
| ||
Advanced penetration testing : hacking the world's most secure networks / / Wil Allsopp ; [foreword by Hans Van de Looy]
| Advanced penetration testing : hacking the world's most secure networks / / Wil Allsopp ; [foreword by Hans Van de Looy] |
| Autore | Allsopp Wil |
| Edizione | [1st ed.] |
| Pubbl/distr/stampa | Wiley, 2017 |
| Descrizione fisica | 1 online resource (287 pages) : illustrations (some color), tables |
| Disciplina | 005.8092 |
| Collana | THEi Wiley ebooks. |
| Soggetto topico |
Penetration testing (Computer security)
Computer networks -- Security measures Hacking |
| ISBN |
1-119-36766-2
1-119-36774-3 1-119-36771-9 9781119367680 |
| Classificazione |
007.609
005.8 |
| Formato | Materiale a stampa |
| Livello bibliografico | Monografia |
| Lingua di pubblicazione | eng |
| Nota di contenuto |
Cover -- Title Page -- Copyright -- About the Author -- About the Technical Editor -- Credits -- Acknowledgments -- Contents at a glance -- Contents -- Foreword -- Introduction -- Coming Full Circle -- Advanced Persistent Threat (APT) -- Next Generation Technology -- "Hackers" -- Forget Everything You Think You Know About Penetration Testing -- How This Book Is Organized -- Chapter 1: Medical Records (In)security -- An Introduction to Simulating Advanced Persistent Threat -- Background and Mission Briefing -- Payload Delivery Part 1: Learning How to Use the VBA Macro -- How NOT to Stage a VBA Attack -- Examining the VBA Code -- Avoid Using Shellcode -- Automatic Code Execution -- Using a VBA/VBS Dual Stager -- Keep Code Generic Whenever Possible -- Code Obfuscation -- Enticing Users -- Command and Control Part 1: Basics and Essentials -- The Attack -- Bypassing Authentication -- Summary -- Exercises -- Chapter 2: Stealing Research -- Background and Mission Briefing -- Payload Delivery Part 2: Using the Java Applet for Payload Delivery -- Java Code Signing for Fun and Profit -- Writing a Java Applet Stager -- Create a Convincing Pretext -- Signing the Stager -- Notes on Payload Persistence -- Microsoft Windows -- Linux -- OSX -- Command and Control Part 2: Advanced Attack Management -- Adding Stealth and Multiple System Management -- Implementing a Command Structure -- Building a Management Interface -- The Attack -- Situational Awareness -- Using AD to Gather Intelligence -- Analyzing AD Output -- Attack Against Vulnerable Secondary System -- Credential Reuse Against Primary Target System -- Summary -- Exercises -- Chapter 3: Twenty-First Century Heist -- What Might Work? -- Nothing Is Secure -- Organizational Politics -- APT Modeling versus Traditional Penetration Testing -- Background and Mission Briefing.
Command and Control Part III: Advanced Channels and Data Exfiltration -- Notes on Intrusion Detection and the Security Operations Center -- The SOC Team -- How the SOC Works -- SOC Reaction Time and Disruption -- IDS Evasion -- False Positives -- Payload Delivery Part III: Physical Media -- A Whole New Kind of Social Engineering -- Target Location Profiling -- Gathering Targets -- The Attack -- Summary -- Exercises -- Chapter 4: Pharma Karma -- Background and Mission Briefing -- Payload Delivery Part IV: Client-Side Exploits 1 -- The Curse That Is Flash -- At Least You Can Live Without It -- Memory Corruption Bugs: Dos and Don'ts -- Reeling in the Target -- Command and Control Part IV: Metasploit Integration -- Metasploit Integration Basics -- Server Configuration -- Black Hats/White Hats -- What Have I Said About AV? -- Pivoting -- The Attack -- The Hard Disk Firewall Fail -- Metasploit Demonstration -- Under the Hood -- The Benefits of Admin -- Typical Subnet Cloning -- Recovering Passwords -- Making a Shopping List -- Summary -- Exercises -- Chapter 5: Guns and Ammo -- Background and Mission Briefing -- Payload Delivery Part V: Simulating a Ransomware Attack -- What Is Ransomware? -- Why Simulate a Ransomware Attack? -- A Model for Ransomware Simulation -- Asymmetric Cryptography -- Remote Key Generation -- Targeting Files -- Requesting the Ransom -- Maintaining C2 -- Final Thoughts -- Command and Control Part V: Creating a Covert C2 Solution -- Introducing the Onion Router -- The Torrc File -- Configuring a C2 Agent to Use the Tor Network -- Bridges -- New Strategies in Stealth and Deployment -- VBA Redux: Alternative Command-Line Attack Vectors -- PowerShell -- FTP -- Windows Scripting Host (WSH) -- BITSadmin -- Simple Payload Obfuscation -- Alternative Strategies in Antivirus Evasion -- The Attack -- Gun Design Engineer Answers Your Questions. Identifying the Players -- Smart(er) VBA Document Deployment -- Email and Saved Passwords -- Keyloggers and Cookies -- Bringing It All Together -- Summary -- Exercises -- Chapter 6: Criminal Intelligence -- Payload Delivery Part VI: Deploying with HTA -- Malware Detection -- Privilege Escalation in Microsoft Windows -- Escalating Privileges with Local Exploits -- Exploiting Automated OS Installations -- Exploiting the Task Scheduler -- Exploiting Vulnerable Services -- Hijacking DLLs -- Mining the Windows Registry -- Command and Control Part VI: The Creeper Box -- Creeper Box Specification -- Introducing the Raspberry Pi and Its Components -- GPIO -- Choosing an OS -- Configuring Full-Disk Encryption -- A Word on Stealth -- Configuring Out-of-Band Command and Control Using 3G/4G -- Creating a Transparent Bridge -- Using a Pi as a Wireless AP to Provision Access by Remote Keyloggers -- The Attack -- Spoofing Caller ID and SMS Messages -- Summary -- Exercises -- Chapter 7: War Games -- Background and Mission Briefing -- Payload Delivery Part VII: USB Shotgun Attack -- USB Media -- A Little Social Engineering -- Command and Control Part VII: Advanced Autonomous Data Exfiltration -- What We Mean When We Talk About "Autonomy" -- Means of Egress -- The Attack -- Constructing a Payload to Attack a Classified Network -- Stealthy 3G/4G Software Install -- Attacking the Target and Deploying the Payload -- Efficient "Burst-Rate" Data Exfiltration -- Summary -- Exercises -- Chapter 8: Hack Journalists -- Briefing -- Advanced Concepts in Social Engineering -- Cold Reading -- C2 Part VIII: Experimental Concepts in Command and Control -- Scenario 1: C2 Server Guided Agent Management -- Scenario 2: Semi-Autonomous C2 Agent Management -- Payload Delivery Part VIII: Miscellaneous Rich Web Content -- Java Web Start -- Adobe AIR -- A Word on HTML5 -- The Attack. Summary -- Exercises -- Chapter 9: Northern Exposure -- Overview -- Operating Systems -- Red Star Desktop 3.0 -- Red Star Server 3.0 -- North Korean Public IP Space -- The North Korean Telephone System -- Approved Mobile Devices -- The "Walled Garden": The Kwangmyong Intranet -- Audio and Video Eavesdropping -- Summary -- Exercises -- Index -- EULA. |
| Record Nr. | UNINA-9910826490903321 |
| Allsopp Wil | ||
| Wiley, 2017 | ||
| Lo trovi qui: Univ. Federico II | ||
| ||
Unauthorised access [[electronic resource] ] : physical penetration testing for IT security teams / / Wil Allsopp
| Unauthorised access [[electronic resource] ] : physical penetration testing for IT security teams / / Wil Allsopp |
| Autore | Allsopp Wil |
| Edizione | [1st edition] |
| Pubbl/distr/stampa | Chichester, : Wiley, 2009 |
| Descrizione fisica | 1 online resource (309 p.) |
| Disciplina | 005.8 |
| Soggetto topico |
Computer networks - Security measures
Local area networks (Computer networks) - Security measures |
| Soggetto genere / forma | Electronic books. |
| ISBN |
0-470-97002-2
1-282-35487-6 9786612354878 0-470-68272-8 |
| Formato | Materiale a stampa |
| Livello bibliografico | Monografia |
| Lingua di pubblicazione | eng |
| Nota di contenuto | Unauthorised Access; Contents; Preface; Acknowledgements; Foreword; 1 The Basics of Physical Penetration Testing; 2 Planning Your Physical Penetration Tests; 3 Executing Tests; 4 An Introduction to Social Engineering Techniques; 5 Lock Picking; 6 Information Gathering; 7 Hacking Wireless Equipment; 8 Gathering the Right Equipment; 9 Tales from the Front Line; 10 Introducing Security Policy Concepts; 11 Counter Intelligence; Appendix A: UK Law; Appendix B: US Law; Appendix C: EU Law; Appendix D: Security Clearances; Appendix E: Security Accreditations; Index |
| Record Nr. | UNINA-9910455304603321 |
Allsopp Wil
|
||
| Chichester, : Wiley, 2009 | ||
| Lo trovi qui: Univ. Federico II | ||
| ||
Unauthorised access [[electronic resource] ] : physical penetration testing for IT security teams / / Wil Allsopp
| Unauthorised access [[electronic resource] ] : physical penetration testing for IT security teams / / Wil Allsopp |
| Autore | Allsopp Wil |
| Edizione | [1st edition] |
| Pubbl/distr/stampa | Chichester, : Wiley, 2009 |
| Descrizione fisica | 1 online resource (309 p.) |
| Disciplina | 005.8 |
| Soggetto topico |
Computer networks - Security measures
Local area networks (Computer networks) - Security measures |
| ISBN |
0-470-97002-2
1-282-35487-6 9786612354878 0-470-68272-8 |
| Formato | Materiale a stampa |
| Livello bibliografico | Monografia |
| Lingua di pubblicazione | eng |
| Nota di contenuto | Unauthorised Access; Contents; Preface; Acknowledgements; Foreword; 1 The Basics of Physical Penetration Testing; 2 Planning Your Physical Penetration Tests; 3 Executing Tests; 4 An Introduction to Social Engineering Techniques; 5 Lock Picking; 6 Information Gathering; 7 Hacking Wireless Equipment; 8 Gathering the Right Equipment; 9 Tales from the Front Line; 10 Introducing Security Policy Concepts; 11 Counter Intelligence; Appendix A: UK Law; Appendix B: US Law; Appendix C: EU Law; Appendix D: Security Clearances; Appendix E: Security Accreditations; Index |
| Record Nr. | UNINA-9910778476203321 |
Allsopp Wil
|
||
| Chichester, : Wiley, 2009 | ||
| Lo trovi qui: Univ. Federico II | ||
| ||
Unauthorised access : physical penetration testing for IT security teams / / Wil Allsopp
| Unauthorised access : physical penetration testing for IT security teams / / Wil Allsopp |
| Autore | Allsopp Wil |
| Edizione | [1st edition] |
| Pubbl/distr/stampa | Chichester, : Wiley, 2009 |
| Descrizione fisica | 1 online resource (309 p.) |
| Disciplina | 005.8 |
| Soggetto topico |
Computer networks - Security measures
Local area networks (Computer networks) - Security measures |
| ISBN |
9786612354878
9780470970027 0470970022 9781282354876 1282354876 9780470682722 0470682728 |
| Formato | Materiale a stampa |
| Livello bibliografico | Monografia |
| Lingua di pubblicazione | eng |
| Nota di contenuto | Unauthorised Access; Contents; Preface; Acknowledgements; Foreword; 1 The Basics of Physical Penetration Testing; 2 Planning Your Physical Penetration Tests; 3 Executing Tests; 4 An Introduction to Social Engineering Techniques; 5 Lock Picking; 6 Information Gathering; 7 Hacking Wireless Equipment; 8 Gathering the Right Equipment; 9 Tales from the Front Line; 10 Introducing Security Policy Concepts; 11 Counter Intelligence; Appendix A: UK Law; Appendix B: US Law; Appendix C: EU Law; Appendix D: Security Clearances; Appendix E: Security Accreditations; Index |
| Altri titoli varianti |
Unauthorized access
Physical penetration testing for IT security teams |
| Record Nr. | UNINA-9911108986103321 |
Allsopp Wil
|
||
| Chichester, : Wiley, 2009 | ||
| Lo trovi qui: Univ. Federico II | ||
| ||
Unauthorised access : physical penetration testing for IT security teams / / Wil Allsopp
| Unauthorised access : physical penetration testing for IT security teams / / Wil Allsopp |
| Autore | Allsopp Wil |
| Edizione | [1st edition] |
| Pubbl/distr/stampa | Wiley, 2009 |
| Descrizione fisica | 1 online resource (309 p.) |
| Disciplina | 005.8 |
| Soggetto topico |
Computer networks - Security measures
Local area networks (Computer networks) - Security measures |
| ISBN |
9786612354878
9780470970027 0470970022 9781282354876 1282354876 9780470682722 0470682728 |
| Formato | Materiale a stampa |
| Livello bibliografico | Monografia |
| Lingua di pubblicazione | eng |
| Nota di contenuto | Unauthorised Access; Contents; Preface; Acknowledgements; Foreword; 1 The Basics of Physical Penetration Testing; 2 Planning Your Physical Penetration Tests; 3 Executing Tests; 4 An Introduction to Social Engineering Techniques; 5 Lock Picking; 6 Information Gathering; 7 Hacking Wireless Equipment; 8 Gathering the Right Equipment; 9 Tales from the Front Line; 10 Introducing Security Policy Concepts; 11 Counter Intelligence; Appendix A: UK Law; Appendix B: US Law; Appendix C: EU Law; Appendix D: Security Clearances; Appendix E: Security Accreditations; Index |
| Altri titoli varianti |
Unauthorized access
Physical penetration testing for IT security teams |
| Record Nr. | UNINA-9911146042703321 |
| Allsopp Wil | ||
| Wiley, 2009 | ||
| Lo trovi qui: Univ. Federico II | ||
| ||