更新时间:2021-07-14 10:23:05
封面
版权页
Credits
About the Author
Acknowledgments
About the Reviewer
www.PacktPub.com
eBooks discount offers and more
Preface
What this book covers
What you need for this book
Who this book is for
Conventions
Reader feedback
Customer support
Downloading the color images of this book
Errata
Piracy
Questions
Chapter 1. Introducing Penetration Testing
Security testing
An abstract testing methodology
Reporting
Myths and misconceptions about pen testing
Summary
Chapter 2. Choosing the Virtual Environment
Open source and free environments
Commercial environments
Image conversion
Converting from a physical to a virtual environment
Chapter 3. Planning a Range
Planning
Identifying vulnerabilities
Chapter 4. Identifying Range Architectures
Building the machines
Selecting network connections
Choosing range components
Readers' challenge
Chapter 5. Identifying a Methodology
The OSSTMM
CHECK
NIST SP-800-115
Chapter 6. Creating an External Attack Architecture
Configuring firewall architectures and establishing layered architectures
Chapter 7. Assessment of Devices
Assessing routers
Evaluating switches
Attacking the firewall
Tricks to penetrate filters
Chapter 8. Architecting an IDS/IPS Range
Deploying a network-based IDS
Security Incident and Event Management (SIEM)
Implementing the host-based IDS and endpoint security
Working with virtual switches
Evasion
Chapter 9. Assessment of Web Servers and Web Applications
OWASP top ten attacks
Analysing web applications with Burp Suite
Penetrating web application firewalls
Tools
Chapter 10. Testing Flat and Internal Networks
The role of vulnerability scanners
Dealing with host protection
Chapter 11. Testing Servers
Common protocols and applications for servers
Database assessment
OS platform specifics
Chapter 12. Exploring Client-Side Attack Vectors
Client-side attack methods
Chapter 13. Building a Complete Cyber Range
Creating the layered architecture
Integrating decoys and honeypots
Attacking the cyber range
Recording the attack data for further training and analysis