Mastering Kali Linux for Web Penetration Testing
暫譯: 精通 Kali Linux 網頁滲透測試

Michael McPhee

  • 出版商: Packt Publishing
  • 出版日期: 2017-06-28
  • 定價: $1,650
  • 售價: 8.0$1,320
  • 語言: 英文
  • 頁數: 338
  • 裝訂: Paperback
  • ISBN: 1784395072
  • ISBN-13: 9781784395070
  • 相關分類: 資訊安全kali-linuxLinux
  • 立即出貨 (庫存=1)

買這商品的人也買了...

相關主題

商品描述

Master the art of exploiting advanced web penetration techniques with Kali Linux 2016.2

About This Book

  • Make the most out of advanced web pen-testing techniques using Kali Linux 2016.2
  • Explore how Stored (a.k.a. Persistent) XSS attacks work and how to take advantage of them
  • Learn to secure your application by performing advanced web based attacks.
  • Bypass internet security to traverse from the web to a private network.

Who This Book Is For

This book targets IT pen testers, security consultants, and ethical hackers who want to expand their knowledge and gain expertise on advanced web penetration techniques. Prior knowledge of penetration testing would be beneficial.

What You Will Learn

  • Establish a fully-featured sandbox for test rehearsal and risk-free investigation of applications
  • Enlist open-source information to get a head-start on enumerating account credentials, mapping potential dependencies, and discovering unintended backdoors and exposed information
  • Map, scan, and spider web applications using nmap/zenmap, nikto, arachni, webscarab, w3af, and NetCat for more accurate characterization
  • Proxy web transactions through tools such as Burp Suite, OWASP's ZAP tool, and Vega to uncover application weaknesses and manipulate responses
  • Deploy SQL injection, cross-site scripting, Java vulnerabilities, and overflow attacks using Burp Suite, websploit, and SQLMap to test application robustness
  • Evaluate and test identity, authentication, and authorization schemes and sniff out weak cryptography before the black hats do

In Detail

You will start by delving into some common web application architectures in use, both in private and public cloud instances. You will also learn about the most common frameworks for testing, such as OWASP OGT version 4, and how to use them to guide your efforts. In the next section, you will be introduced to web pentesting with core tools and you will also see how to make web applications more secure through rigorous penetration tests using advanced features in open source tools. The book will then show you how to better hone your web pentesting skills in safe environments that can ensure low-risk experimentation with the powerful tools and features in Kali Linux that go beyond a typical script-kiddie approach. After establishing how to test these powerful tools safely, you will understand how to better identify vulnerabilities, position and deploy exploits, compromise authentication and authorization, and test the resilience and exposure applications possess.

By the end of this book, you will be well-versed with the web service architecture to identify and evade various protection mechanisms that are used on the Web today. You will leave this book with a greater mastery of essential test techniques needed to verify the secure design, development, and operation of your customers' web applications.

Style and approach

An advanced-level guide filled with real-world examples that will help you take your web application’s security to the next level by using Kali Linux 2016.2.

商品描述(中文翻譯)

**掌握使用 Kali Linux 2016.2 利用先進的網路滲透技術的藝術**

## 本書介紹
- 利用 Kali Linux 2016.2 最大化先進的網路滲透測試技術
- 探索儲存型(即持久型)XSS 攻擊的運作方式及如何利用它們
- 學習透過執行先進的網路攻擊來保護您的應用程式
- 繞過網路安全,從網路進入私有網路

## 本書適合誰
本書針對 IT 滲透測試人員、安全顧問和道德駭客,旨在擴展他們對先進網路滲透技術的知識和專業技能。具備滲透測試的先前知識將會有幫助。

## 您將學到什麼
- 建立一個功能齊全的沙盒,以進行測試排練和無風險的應用程式調查
- 利用開源資訊提前獲得帳戶憑證的枚舉、潛在依賴關係的映射,以及發現意外的後門和暴露資訊
- 使用 nmap/zenmap、nikto、arachni、webscarab、w3af 和 NetCat 對網路應用程式進行映射、掃描和蜘蛛爬行,以獲得更準確的特徵描述
- 通過 Burp Suite、OWASP 的 ZAP 工具和 Vega 等工具代理網路交易,以揭示應用程式的弱點並操控回應
- 使用 Burp Suite、websploit 和 SQLMap 部署 SQL 注入、跨站腳本、Java 漏洞和溢出攻擊,以測試應用程式的穩健性
- 評估和測試身份、認證和授權方案,並在黑帽駭客之前嗅探出弱加密

## 詳細內容
您將開始深入了解在私有和公共雲實例中使用的一些常見網路應用程式架構。您還將學習最常用的測試框架,例如 OWASP OGT 版本 4,以及如何使用它們來指導您的工作。在接下來的部分中,您將接觸到使用核心工具進行網路滲透測試,並了解如何通過使用開源工具中的先進功能進行嚴格的滲透測試來提高網路應用程式的安全性。本書將展示如何在安全環境中更好地磨練您的網路滲透測試技能,這些環境可以確保使用 Kali Linux 中強大工具和功能進行低風險實驗,超越典型的腳本小子方法。在確立如何安全測試這些強大工具後,您將了解如何更好地識別漏洞、定位和部署利用、妥協認證和授權,以及測試應用程式的韌性和暴露性。

在本書結束時,您將熟悉網路服務架構,以識別和避開當今網路上使用的各種保護機制。您將帶著對驗證客戶網路應用程式安全設計、開發和運行所需的基本測試技術的更高掌握離開本書。

## 風格與方法
這是一本高級指南,充滿了現實世界的範例,將幫助您利用 Kali Linux 2016.2 將您的網路應用程式安全提升到一個新的水平。