martes, 4 de diciembre de 2007

Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research

With the arrival of Metasploit Framework Version 3.0 (MSF 3.0), the entire approach to information security testing is likely to be revolutionalized. MSF 3.0 is not only an exploit platform but also a security tool development platform. This book introduces the reader to the main features of the tool, outlines the steps for its installation, and discusses how to use it to run exploits. The book also includes content on advanced usage to automate exploits and run custom payloads and commands on exploited systems. The book covers the entire gamut of security testing—recon modules to determine vulnerable hosts and interface with scanners such as Nmap and Nessus, exploits and payloads to attack the specific vulnerabilities, and post-exploitation goodies to stealthily own the system, and possibly the entire network.

Edición: Syngress (2007)
Idioma: Inglés
Formato: PDF

Contenido:

  1. Introduction to Metasploit
  2. Architecture, Environment, and Installation
  3. Metasploit Framework and Advanced Environment Configurations
  4. Advanced Payloads and Add-on Modules
  5. Adding New Payloads
  6. Case Study 1: RaXnet Cacti Remote Command Execution
  7. Case Study 2: Mercur Messaging 2005 SP3 IMAP Remote Buffer Overflow (CVE –2006-1255)
  8. Case Study 3: SlimFTPd String Concatenation Overflow
  9. Case Study 4: WS-FTP Server 5.03 MKD Overflow
  10. Case Study 5: MailEnable HTTP Authorization Header Buffer Overflow
  11. Appendix A: Advantages of Network Vulnerability Testing with Metasploit 3.0
  12. Appendix B: Building a Test Lab for Penetration Testing
  13. Appendix C: Glossary of Technology and Terminology

Descarga/Download

No hay comentarios: