• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    Wireshark for Security Professionals

    Using Wireshark and the Metasploit Framework

    AvJessey Bullock,Jeff T. Parker

    Häftad, Engelska, 2017

    402 kr

    Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

    Beskrivning

    Master Wireshark to solve real-world security problems If you don’t already use Wireshark for a wide range of information security tasks, you will after this book. Mature and powerful, Wireshark is commonly used to find root cause of challenging network issues. This book extends that power to information security professionals, complete with a downloadable, virtual lab environment.Wireshark for Security Professionals covers both offensive and defensive concepts that can be applied to essentially any InfoSec role. Whether into network security, malware analysis, intrusion detection, or penetration testing, this book demonstrates Wireshark through relevant and useful examples.Master Wireshark through both lab scenarios and exercises. Early in the book, a virtual lab environment is provided for the purpose of getting hands-on experience with Wireshark. Wireshark is combined with two popular platforms: Kali, the security-focused Linux distribution, and the Metasploit Framework, the open-source framework for security testing. Lab-based virtual systems generate network traffic for analysis, investigation and demonstration. In addition to following along with the labs you will be challenged with end-of-chapter exercises to expand on covered material.Lastly, this book explores Wireshark with Lua, the light-weight programming language. Lua allows you to extend and customize Wireshark’s features for your needs as a security professional. Lua source code is available both in the book and online. Lua code and lab source code are available online through GitHub, which the book also introduces. The book’s final two chapters greatly draw on Lua and TShark, the command-line interface of Wireshark.By the end of the book you will gain the following: Master the basics of WiresharkExplore the virtual w4sp-lab environment that mimics a real-world networkGain experience using the Debian-based Kali OS among other systemsUnderstand the technical details behind network attacksExecute exploitation and grasp offensive and defensive activities, exploring them through WiresharkEmploy Lua to extend Wireshark features and create useful scriptsTo sum up, the book content, labs and online material, coupled with many referenced sources of PCAP traces, together present a dynamic and robust manual for information security professionals seeking to leverage Wireshark.

    Produktinformation

    • Utgivningsdatum:2017-05-12
    • Mått:185 x 234 x 20 mm
    • Vikt:476 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:288
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781118918210

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT
    • IT-säkerhet inom Data och IT

    Mer om författaren

    JESSEY BULLOCK is a Senior Application Security Engineer with a game company. Having previously worked at both NGS and iSEC Partners as a consultant, he has a deep understanding of application security and development, operating systems internals, and networking protocols. Jessey has experience working across multiple industry sectors, including health care, education, and security. Jessey holds multiple security certifications, including CISSP, CCNA, CWNA, GCFE, CompTIA Security+, CompTIA A+, OSCP, GPEN, CEH, and GXPN. JEFF T. PARKER is a seasoned IT security consultant with a career spanning 3 countries and as many Fortune 1OO companies. Now in Halifax, Canada, Jeff enjoys life most with his two young children, hacking professionally while they're in school.

    Innehållsförteckning

    • Introduction xiiiChapter 1 Introducing Wireshark 1What Is Wireshark? 2A Best Time to Use Wireshark? 2Avoiding Being Overwhelmed 3The Wireshark User Interface 3Packet List Pane 5Packet Details Pane 6Packet Bytes Pane 8Filters 9Capture Filters 9Display Filters 13Summary 17Exercises 18Chapter 2 Setting Up the Lab 19Kali Linux 20Virtualization 22Basic Terminology and Concepts 23Benefits of Virtualization 23Virtual Box 24Installing VirtualBox 24Installing the VirtualBox Extension Pack 31Creating a Kali Linux Virtual Machine 33Installing Kali Linux 40The W4SP Lab 46Requirements 46A Few Words about Docker 47What Is GitHub? 48Creating the Lab User 49Installing the W4SP Lab on the Kali Virtual Machine 50Setting Up the W4SP Lab 53The Lab Network 54Summary 55Exercises 56Chapter 3 The Fundamentals 57Networking 58OSI Layers 58Networking between Virtual Machines 61Security 63The Security Triad 63Intrusion Detection and Prevention Systems 63False Positives and False Negatives 64Malware 64Spoofing and Poisoning 66Packet and Protocol Analysis 66A Protocol Analysis Story 67Ports and Protocols 71Summary 73Exercises 74Chapter 4 Capturing Packets 75Sniffing 76Promiscuous Mode 76Starting the First Capture 78TShark 82Dealing with the Network 86Local Machine 87Sniffing Localhost 88Sniffing on Virtual Machine Interfaces 92Sniffing with Hubs 96SPAN Ports 98Network Taps 101Transparent Linux Bridges 103Wireless Networks 105Loading and Saving Capture Files 108File Formats 108Ring Buffers and Multiple Files 111Recent Capture Files 116Dissectors 118W4SP Lab: Managing Nonstandard HTTP Traffic 118Filtering SMB Filenames 120Packet Colorization 123Viewing Someone Else’s Captures 126Summary 127Exercises 128Chapter 5 Diagnosing Attacks 129Attack Type: Man-in-the-Middle 130Why MitM Attacks Are Effective 130How MitM Attacks Get Done: ARP 131W4SP Lab: Performing an ARP MitM Attack 133W4SP Lab: Performing a DNS MitM Attack 141How to Prevent MitM Attacks 147Attack Type: Denial of Service 148Why DoS Attacks Are Effective 149How DoS Attacks Get Done 150How to Prevent DoS Attacks 155Attack Type: Advanced Persistent Threat 156Why APT Attacks Are Effective 156How APT Attacks Get Done 157Example APT Traffic in Wireshark 157How to Prevent APT Attacks 161Summary 162Exercises 162Chapter 6 Offensive Wireshark 163Attack Methodology 163Reconnaissance Using Wireshark 165Evading IPS/IDS 168Session Splicing and Fragmentation 168Playing to the Host, Not the IDS 169Covering Tracks and Placing Backdoors 169Exploitation 170Setting Up the W4SP Lab with Metasploitable 171Launching Metasploit Console 171VSFTP Exploit 172Debugging with Wireshark 173Shell in Wireshark 175TCP Stream Showing a Bind Shell 176TCP Stream Showing a Reverse Shell 183Starting ELK 188Remote Capture over SSH 190Summary 191Exercises 192Chapter 7 Decrypting TLS, Capturing USB, Keyloggers, and Network Graphing 193Decrypting SSL/TLS 193Decrypting SSL/TLS Using Private Keys 195Decrypting SSL/TLS Using Session Keys 199USB and Wireshark 202Capturing USB Traffic on Linux 203Capturing USB Traffic on Windows 206TShark Keylogger 208Graphing the Network 212Lua with Graphviz Library 213Summary 218Exercises 219Chapter 8 Scripting with Lua 221Why Lua? 222Scripting Basics 223Variables 225Functions and Blocks 226Loops 228Conditionals 230Setup 230Checking for Lua Support 231Lua Initialization 232Windows Setup 233Linux Setup 233Tools 234Hello World with TShark 236Counting Packets Script 237ARP Cache Script 241Creating Dissectors for Wireshark 244Dissector Types 245Why a Dissector Is Needed 245Experiment 253Extending Wireshark 255Packet Direction Script 255Marking Suspicious Script 257Snooping SMB File Transfers 260Summary 262Index 265