Dominant Systems - Michigan Network Solutions Provider Dominant Systems - Michigan Network Solutions Provider
Dominant Systems - Michigan Network Solutions Provider Dominant Systems - Michigan Network Solutions Provider
ARCSPIDER SEARCH
Enter Keywords:

Powered by Arc Spider - Smart Product Search Services 
Privacy Statement
PARTNER LINKS

Buy.com Coupons

Sony VAIO PC Special Offers

The Hottest Notebook Deals Are Here!


Hack the Stack: Using Snort and Ethereal to Master the 8 Layers of an Insecure Network
Home > Computer/ Network Books > Comptia Network+ > Item 19
View Previous Product in Comptia Network+ View Next Product in Comptia Network+

Click here to buy Hack the Stack: Using Snort and Ethereal to Master the 8 Layers of an Insecure Network by  Michael Gregg. Hack the Stack: Using Snort and Ethereal to Master the 8 Layers of an Insecure Network
by Michael Gregg
Sales Rank: 539744
Discount: 24 %
List Price: $49.95
$37.96
At Amazon
Get More Info On Hack the Stack: Using Snort and Ethereal to Master the 8 Layers of an Insecure Network! Buy Hack the Stack: Using Snort and Ethereal to Master the 8 Layers of an Insecure Network Now!

  • Paperback: 416 pages
  • Publisher: Syngress October 17, 2006
  • Language: English
  • ISBN-10: 1597491098
  • ISBN-13: 978-1597491099
  • Product Dimensions: 8.8 x 7 x 1.4 inches
  • Shipping Weight: 1.4 pounds

    Book Description
    This book looks at network security in a new and refreshing way. It guides readers step-by-step through the "stack" -- the seven layers of a network. Each chapter focuses on one layer of the stack along with the attacks, vulnerabilities, and exploits that can be found at that layer. The book even includes a chapter on the mythical eighth layer: The people layer.

    This book is designed to offer readers a deeper understanding of many common vulnerabilities and the ways in which attackers exploit, manipulate, misuse, and abuse protocols and applications. The authors guide the readers through this process by using tools such as Ethereal (sniffer) and Snort (IDS). The sniffer is used to help readers understand how the protocols should work and what the various attacks are doing to break them. IDS is used to demonstrate the format of specific signatures and provide the reader with the skills needed to recognize and detect attacks when they occur.

    What makes this book unique is that it presents the material in a layer by layer approach which offers the readers a way to learn about exploits in a manner similar to which they most likely originally learned networking. This methodology makes this book a useful tool to not only security professionals but also for networking professionals, application programmers, and others. All of the primary protocols such as IP, ICMP, TCP are discussed but each from a security perspective. The authors convey the mindset of the attacker by examining how seemingly small flaws are often the catalyst of potential threats. The book considers the general kinds of things that may be monitored that would have alerted users of an attack.

    * Remember being a child and wanting to take something apart, like a phone, to see how it worked? This book is for you then as it details how specific hacker tools and techniques accomplish the things they do.

    * This book will not only give you knowledge of security tools but will provide you the ability to design more robust security solutions

    * Anyone can tell you what a tool does but this book shows you how the tool works

    About The Author
    Michael Gregg is the President of Superior Solutions, Inc. and has more than 20 years experience in the IT field. He holds two associates degrees, a bachelors degree, and a masters degree and is certified as: CISSP, MCSE, MCT, CTT+, A+, N+, Security+, CNA, CCNA, CIW Security Analyst, CCE, CEH, CHFI, CEI, DCNP, ES Dragon IDS, ES Advanced Dragon IDS, and TICSA.

    Customer Reviews & Comments
    I teach a course called "TCP/IP Weapons School" that involves walking students up the OSI model. We look at network traces generated by tools and techniques to defeat security measures. When I saw "Hack the Stack" (HTS) I thought it might make a good resource for my class, since HTS seemed to advocate a similar approach. Unfortunately, technical errors, shoddy production, internal repetition and poor organization, and a lack of original material make me question the value of HTS. A critical aspect of a security book is technical accuracy, but HTS does not deliver. In some cases the book is half-right, or it omits important elements. For example, p 9 implies only port 20 TCP is used for TCP data; that's true for the server in active FTP, but passive FTP uses arbitrary ports. p 15 says SOCKS is "Windows Sockets," when SOCKS is a proxy protocol. p 71 says CSMA/CA (wireless) is similar to CSMA/CD (traditional Ethernet), but the two protocols are very different; CSMA/CA is much more complex. p 115 should say IP proto 41 is "IPv6 in IPv4", and not imply that IP proto 41 is somehow "IPv6". p 118 says "ICMP messages cannot be sent in response to other ICMP messages." That's not true; otherwise, ICMP echo would not be able to elicit an ICMP echo reply. (The authors meant ICMP error messages cannot elicit ICMP errors.) Several times the book makes odd statements. p 14 says the first virus concept appeared in 1984, but non-PC viruses existed in the 1970s and the first PC virus (Elk Cloner) was in the wild in 1982. p 3 says "IDS has a short history" by citing Dorothy Denning's work in 1983, but ignores James Anderson's 1980 work for the Air Force as the first real IDS pioneer. p 119 says "consider disabling ICMP," which ignores breaking path MTU discovery and other crucial ICMP services. p 131 says idle scans were developed in 1988; it's 1998. p 131 also says a SYN to a closed port elicits a RST response, but it's really a RST ACK. On the production side, Syngress did a very poor job publishing screen shots. HTS advertises "using Snort and Ethereal" in the book's subtitle, but many of the Ethereal screen captures are either too tiny or fuzzy or blacked out to be legible. This defeats the purpose of including them. As far as organization goes, HTS is supposed to take a layer-by-layer look at security issues. However, material that should stay in one section is sometimes repeated or introduced in other sections. For example, there is no need to be discussing ARP (layer 2) manipulation in the layer 5 chapter, or again in the layer 6 chapter. HTTP interception tools should not appear in the layer 6 chapter when they fit properly in layer 7. SYN floods should not pop up in layer 4 and 5 chapters; pick one and consolidate coverage there. p 162 even says "Exchanges at the Transport layer are typically in clear text... FTP is a good example of this." The first assertion is wrong, and why is FTP appearing in the layer 4 chapter anyway? p 92 should recognize that PGP is not "Pretty Good Protection." I didn't think it made sense to introduce Ethereal in ch 3, and then split coverage of Snort between ch 5 and ch 6. Furthermore, HTS made the mistake frequently repeated elsewhere of configuring Snort to log directly to a database. Without using unified logging with a spool reader like Barnyard, such a setup is only useful in demonstration purposes where packet loss is not an issue. To the extent necessary, Ethereal and Snort should have appeared in appendices and not the main "layer" text. Finally, I did not find anything in the technical realm I had not read elsewhere. All of the tools (Nmap, Nessus, Hping, Amap, etc.) are familiar to most every network security practitioner, or they have been documented in great books like Anti-Hacker Toolkit or even other Syngress titles. It's ok to cover such tools if they are used in a novel way, but that didn't happen in HTS. I hoped to read something more original, say in the layer 4 chapter. Instead HTS discusses port scanning, OS fingerprinting, and SYN floods. The two chapters which may be of interest to readers include those on layer 1 and "layer 8." Layer 1 offers some basic lock picking information as well as the sort of physical security suggestions you'd find in a CISSP book. On a sad note, the vignette on Rick Rescorla on p 35 doesn't mention that he tragically died on 9/11. Layer 8 discusses policies, social engineering, and related "people issues." Overall, I think there is room for a book like HTS. It's too bad this one did not deliver what I was expecting. I do appreciate the authors citing my network security monitoring methodology on p 232. Comment | Permalink | (Report this)

  • Hack the Stack: Using Snort and Ethereal to Master the 8 Layers of an Insecure Network
    List Price: $49.95
    Discount: 24 %
    Available from Amazon
    Price: $37.96
    Get More Info On Hack the Stack: Using Snort and Ethereal to Master the 8 Layers of an Insecure Network! Buy Hack the Stack: Using Snort and Ethereal to Master the 8 Layers of an Insecure Network Now!
    Home |  About Us |  Network Services |  Security Services |  Testimonials |  Case Studies
    Tips & Tools |  Press Room |  Newsletters |  Employment |  Contact Us

    Copyright © 2008, Dominant Systems Corporation

    Dominant Systems Corporation