Computing Reviews

Ethical hacking and penetration testing guide
Baloch R., Auerbach Publications,Boston, MA,2014. 531 pp.Type:Book
Date Reviewed: 07/01/15

Any book with “hacking” in the title is bound to evoke some interest and curiosity. The term has been overused in good and bad ways. Some of the world’s best programmers are considered the best hackers, and so are the evil people who break into computers for monetary or espionage reasons.

This book is meant for white hat hackers who protect companies by seeing patterns and identifying attacks. One needs to know how a black hat hacker attacks systems to thwart it. This book is a comprehensive one, with 12 long chapters. It starts off with fundamental concepts, explaining various aspects of the jargon, and goes in depth into Linux systems.

Any good hacker needs to know the innards of the Unix system, and Linux is a popular variant of the operating system. The theory behind various concepts is also explained, such as transmission control protocol (TCP) handshakes and scans. All of the commands and sample screen shots are given. I wish they were given in color and not in black and white, which is sometimes hard to read due to contrast.

Some of the vulnerability scanners and sniffing packets are addressed in detail. Again, for any good hacker, understanding packet captures is must-have knowledge. A lot of practical hacks are explained, and the book goes into the mechanics in detail. One example is exploiting cross-site scripting (XSS). What it takes, how a hack is conceived, what information is gathered, how packets flow, and how to reverse-engineer are all explained in detail.

Overall, this book is a great source for students and security professionals alike. Readers can deepen their knowledge by using the concepts explained in the book and get a good sense of security hacks and how to prevent them. The book takes an in-depth look at the concepts and doesn’t gloss over them at the surface level. I highly recommend it to any budding security engineer.

More reviews about this item: Amazon, Goodreads

Reviewer:  Naga Narayanaswamy Review #: CR143573 (1510-0852)

Reproduction in whole or in part without permission is prohibited.   Copyright 2024 ComputingReviews.com™
Terms of Use
| Privacy Policy