Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Programming Linux Hacker Tools Uncovered: Exploits, Backdoors, Scanners, Sniffers, Brute-Forcers, Rootkits (Uncovered series) Review

Programming Linux Hacker Tools Uncovered: Exploits, Backdoors, Scanners, Sniffers, Brute-Forcers, Rootkits (Uncovered series)
Average Reviews:

(More customer reviews)
Are you looking to buy Programming Linux Hacker Tools Uncovered: Exploits, Backdoors, Scanners, Sniffers, Brute-Forcers, Rootkits (Uncovered series)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Programming Linux Hacker Tools Uncovered: Exploits, Backdoors, Scanners, Sniffers, Brute-Forcers, Rootkits (Uncovered series). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Programming Linux Hacker Tools Uncovered: Exploits, Backdoors, Scanners, Sniffers, Brute-Forcers, Rootkits (Uncovered series) ReviewI cracked the book to start reading and you are immediately shoved into programming an xping program. I had to stop and learn the parts of C that I am not as familier with. If you are looking for a great book to get you started on writing sec tools, then this is it!Programming Linux Hacker Tools Uncovered: Exploits, Backdoors, Scanners, Sniffers, Brute-Forcers, Rootkits (Uncovered series) OverviewUncovering the development of the hacking toolset under Linux, this book teaches programmers the methodology behind hacker programming techniques so that they can think like an attacker when developing a defense. Analyses and cutting-edge programming are provided of aspects ofeach hacking item and its source code—including ping and traceroute utilities, viruses, worms, Trojans, backdoors, exploits (locals and remotes), scanners (CGI and port), smurf and fraggle attacks, and brute-force attacks.In addition to information on how to exploit buffer overflow errors in the stack, heap and BSS, and how to exploit format-string errors and other less common errors, this guide includes the source code of all the described utilities on the accompanying CD-ROM.

Want to learn more information about Programming Linux Hacker Tools Uncovered: Exploits, Backdoors, Scanners, Sniffers, Brute-Forcers, Rootkits (Uncovered series)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Applied Cryptography: Protocols, Algorithms, and Source Code in C, Second Edition Review

Applied Cryptography: Protocols, Algorithms, and Source Code in C, Second Edition
Average Reviews:

(More customer reviews)
Are you looking to buy Applied Cryptography: Protocols, Algorithms, and Source Code in C, Second Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on Applied Cryptography: Protocols, Algorithms, and Source Code in C, Second Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Applied Cryptography: Protocols, Algorithms, and Source Code in C, Second Edition ReviewBruce Schneier's APPLIED CRYPTOGRAPHY is an excellent book for anyone interested in cryptology from an amateur level to actually being involved in the development of new encryption mechanisms. Schneier's book begins with a simple discussion of what is cryptography, and then he proceeds through the history of various encryption algorithms and their functioning. The last portion of the book contains C code for several public-domain encryption algorithms.
A caveat: this is not a textbook of cryptography in the sense that it teaches everything necessary to understand the mathematical basis of the science. Schneier does not discuss number theory because he expects those who use the relevant chapters of the book will already have training in higher maths. Nonetheless, the book does contain a wealth of information even for the layman.
One helpful part of Schneier's book is his opinion of which encryption algorithms are already broken by the National Security Agency, thus letting the reader know which encryption programs to avoid. There will always be people who encrypt to 40-bit DES even though it is flimsy and nearly instantly breakable, but the readers of APPLIED CRYPTOGRAPHY can greatly improve the confidentiality of their messages and data with this book. Discussion of public-key web-of-trust is essential reading for anyone confused by how public-key signatures work.
APPLIED CRYPTOGRAPHY was published in 1995 and some parts are already out of date. It is ironic that he hardly mentions PGP, when PGP went on to become the most renowned military-strength encryption program available to the public, although it is being superseded by GnuPG. Another anachronism is Schneier's assurance that quantum computing is decades away. In the years since publication of APPLIED CRYPTOGRAPHY we have seen some strides in quantum computer, even the creation of a quantum computer that can factor the number 15. While this publicly known quantum computer is not at all anything to get excited about, it is certain that more powerful quantum computers are in development and classified by NSA. Because a quantum computer can break virtually any traditional cipher, hiding the message (steganography) is becoming more important than ever. In the era of Schneier's book steganography was unnecessary because ciphertext could withstand brute-force attacks, but with advances in computing power steganography is becoming vital to secure communications. It would be nice to see the book updated with this topic, because cryptography and steganography can no longer be regarded as two distinct fields.
All in all, in spite of its age, APPLIED CRYPTOGRAPHY is recommended to anyone interested in cryptography. It ranks among the essential books on the field, although an updated version is certainly hoped for.Applied Cryptography: Protocols, Algorithms, and Source Code in C, Second Edition Overview

Want to learn more information about Applied Cryptography: Protocols, Algorithms, and Source Code in C, Second Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Giant Black Book of Computer Viruses Review

The Giant Black Book of Computer Viruses
Average Reviews:

(More customer reviews)
Are you looking to buy The Giant Black Book of Computer Viruses? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Giant Black Book of Computer Viruses. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Giant Black Book of Computer Viruses ReviewMark Ludwig is rekoned to be one of the worlds leading experts in the field of computer viruses and this book (with disk) goes to prove that he is. Written for those with a good understanding of computer languages, this is no trip for the feint hearted. I recommend this to anyone wanting to know how they can improve their systems form malicious attack, BUT dont use the disk if you don't know what you are doing as the demo viruses contained COULD do serious damage. Defineatly a recommended read.The Giant Black Book of Computer Viruses Overview

Want to learn more information about The Giant Black Book of Computer Viruses?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

IBM WebSphere DataPower SOA Appliance Handbook Review

IBM WebSphere DataPower SOA Appliance Handbook
Average Reviews:

(More customer reviews)
Are you looking to buy IBM WebSphere DataPower SOA Appliance Handbook? Here is the right place to find the great deals. we can offer discounts of up to 90% on IBM WebSphere DataPower SOA Appliance Handbook. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

IBM WebSphere DataPower SOA Appliance Handbook ReviewI purchased this book at Amazon to use as a reference for a DataPower implementation and to supplement basic DataPower training. It has been very helpful as a reference and has an easy-to-read style (for a technical book) that has made it possible to read it from cover to cover. The book provides numerous examples with screen snapshots. Interestingly, the examples typically are associated with a book purchase service :). Our project is using DataPower systems for web services security, service virtualization, routing, web service enabling MQ®, logging and complex XML transformation. These topics are covered extensively in the book. I strongly recommend this book if you are launching a DataPower project.IBM WebSphere DataPower SOA Appliance Handbook OverviewExpert Guide to Deploying, Using, and Managing DataPower SOA AppliancesIBM® WebSphere® DataPower® appliances can simplify SOA deployment, strengthen SOA security, enhance SOA performance, and dramatically improve SOA return on investment. In this book, a team of IBM's leading experts show how to make the most of DataPower SOA appliances in any IT environment.The authors present IBM DataPower information and insights that are available nowhere else. Writing for working architects, administrators, and security specialists, they draw extensively on their deep experience helping IBM customers use DataPower technologies to solve challenging system integration problems.IBM WebSphere DataPower SOA Appliance Handbook begins by introducing the rationale for SOA appliances and explaining how DataPower appliances work from network, security, and Enterprise Service Bus perspectives. Next, the authors walk through DataPower installation and configuration; then they present deep detail on DataPower's role and use as a network device.Using many real-world examples, the authors systematically introduce the services available on DataPower devices, especially the "big three": XML Firewall, Web Service Proxy, and Multi-Protocol Gateway. They also present thorough and practical guidance on day-to-day DataPower management, including, monitoring, configuration build and deploy techniques.Coverage includes• Configuring DataPower's network interfaces for common scenarios• Implementing DataPower deployment patterns for security gateway, ESB, and Web service management applications• Proxying Web applications with DataPower• Systematically addressing the security vulnerabilities associated with Web services and XML• Integrating security with WebSphere Application Server• Mastering DataPower XSLT custom programming• Troubleshooting using both built-in and external tools

Want to learn more information about IBM WebSphere DataPower SOA Appliance Handbook?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Hacking: The Art of Exploitation, 2nd Edition Review

Hacking: The Art of Exploitation, 2nd Edition
Average Reviews:

(More customer reviews)
Are you looking to buy Hacking: The Art of Exploitation, 2nd Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on Hacking: The Art of Exploitation, 2nd Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Hacking: The Art of Exploitation, 2nd Edition Review
Contents
This is the second edition of a well known book about hacking and contains a lot about hacking. Jon Erickson has expanded the book from the first edition doubling the number of pages to 450 pages and a Linux based Live-CD is also included.
I don't own the first edition, since I had to choose between Hacking by Jon Erickson and The Shellcoders Handbook (first edition, it is also in 2nd ed. now). I choose the Shellcoders handbook, which I have considered my bible for buffer overflows and hacking.
Now that I have read Jon Ericksons book about hacking I have two bibles, both excellent and well written, both covering some of the same stuff - but in very different ways.
This book details the steps done to perform buffer overflows on Linux on the x86 architecture. So detailed that any computer science student can do it, and they should. Every computer science student or aspiring programmer should be forced to read this book along with another book called 19 deadly sins of software programming.
That alone would improve internet security and program reliability in the future. Why you may ask, because this book teaches hacking, and how you can get started hacking.
Not hacking as doing criminal computer break ins, but thinking like an old-school hacker - doing clever stuff, seeing the things others don't. This book contains the missing link back to the old days, where hackers were not necessarily bad guys. Unfortunately today the term hacker IS dead in the public eye, it HAS been maimed, mutilated and the war about changing it back to the old meaning is over. (Actually this war was fought in the 1990's but some youngsters new to hacking still think it can be won, don't waste your time.) The word hacking can still be used in both ways, just make sure the receiver knows what you are talking about :-)
This book teaches hacking in the old sense of the word and contains the explanation that most others books don't - and at the same time it introduces all the basic skills for performing various types of overflow attacks. Then the book also digress into some wireless security and even WEP cracking, but this part is pretty slim, not bad, just only a few pages. This is OK, since I think of this more as an example of extending the hacking into new areas and hopefully inspires more people to look into wireless security.
The best part about this book is that it is not just a book with a random Live-CD. It is an inspiration and your fingers will itch to get started trying the examples explained and experiment with the programs. This alone is the single feature that makes this book worth it, you will do the exercises and learn from them. Learn a lot.
To sum it up this books contains clever tricks and easy to follow exercises, so you can learn to apply them.
Target audience
This book is for anyone interested in hacking and developing exploits. While the primary target audience is newcomers to this field I benefitted from the thorough walkthrough of the basics once again. This book kept reminding me about things I have forgotten and also some new things and tricks I hadn't thought of myself.Conclusion
If you are a beginning hacker and want to get started, but was confused
by various text files found on the internet, this is the book to buy.
If you want to learn how to do basic stuff and get started thinking like a hacker, this is the book to buy.
If you are a software programmer that has started to think about software security, this is the book to buy.
This book goes from beginning hacker to inspired intermediate hacker and explains everything in depth and is well planned and you will be able to extract an awful lot of information about the way programs really work after reading this book.
If you read this book from cover to cover you will be able to follow most other references about hacking, books, papers, zines etc. from the internet.
So this book is recommended for anyone interested in hacking and could be a nice start to having your own library about hacking. Reading this book first will also help you understand other books about hacking better and get more information from them by thinking in the right way.
Then later you could expand this library with books like, Steven Levy Hackers, Steven Levy Crypto, Shellcoders Handbook, Clifford Stoll Cuckoos Egg and other references.
I am not missing much from this book, but a short explanation how you could run this CD along with your usual operating system, using something like VMware Player would have been nice.
Links:
The home page for this book is: http://www.nostarch.com/hacking2.htm
Hacking: The Art of Exploitation, 2nd Edition Overview
Hacking is the art of creative problem solving, whether that means finding an unconventional solution to a difficult problem or exploiting holes in sloppy programming. Many people call themselves hackers, but few have the strong technical foundation needed to really push the envelope.

Rather than merely showing how to run existing exploits, author Jon Erickson explains how arcane hacking techniques actually work. To share the art and science of hacking in a way that is accessible to everyone, Hacking: The Art of Exploitation, 2nd Edition introduces the fundamentals of C programming from a hacker's perspective.

The included LiveCD provides a complete Linux programming and debugging environment-all without modifying your current operating system. Use it to follow along with the book's examples as you fill gaps in your knowledge and explore hacking techniques on your own. Get your hands dirty debugging code, overflowing buffers, hijacking network communications, bypassing protections, exploiting cryptographic weaknesses, and perhaps even inventing new exploits. This book will teach you how to:

Program computers using C, assembly language, and shell scripts
Corrupt system memory to run arbitrary code using buffer overflows and format strings
Inspect processor registers and system memory with a debugger to gain a real understanding of what is happening
Outsmart common security measures like nonexecutable stacks and intrusion detection systems
Gain access to a remote server using port-binding or connect-back shellcode, and alter a server's logging behavior to hide your presence
Redirect network traffic, conceal open ports, and hijack TCP connections
Crack encrypted wireless traffic using the FMS attack, and speed up brute-force attacks using a password probability matrix

Hackers are always pushing the boundaries, investigating the unknown, and evolving their art. Even if you don't already know how to program, Hacking: The Art of Exploitation, 2nd Edition will give you a complete picture of programming, machine architecture, network communications, and existing hacking techniques. Combine this knowledge with the included Linux environment, and all you need is your own creativity.


Want to learn more information about Hacking: The Art of Exploitation, 2nd Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

New 4 Channel Embedded Linux US411L H.264 Network DVR With No Hard Drive, Real time True Triplex with built web server for remote viewing and operation, backup and operation 4CH DVR 120FPS SATA ready. Review

New 4 Channel Embedded Linux US411L H.264 Network DVR With No Hard Drive, Real time True Triplex with built web server for remote viewing and operation, backup and operation 4CH DVR 120FPS SATA ready.
Average Reviews:

(More customer reviews)
Are you looking to buy New 4 Channel Embedded Linux US411L H.264 Network DVR With No Hard Drive, Real time True Triplex with built web server for remote viewing and operation, backup and operation 4CH DVR 120FPS SATA ready.? Here is the right place to find the great deals. we can offer discounts of up to 90% on New 4 Channel Embedded Linux US411L H.264 Network DVR With No Hard Drive, Real time True Triplex with built web server for remote viewing and operation, backup and operation 4CH DVR 120FPS SATA ready.. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

New 4 Channel Embedded Linux US411L H.264 Network DVR With No Hard Drive, Real time True Triplex with built web server for remote viewing and operation, backup and operation 4CH DVR 120FPS SATA ready. ReviewI've had this unit for a few weeks, and I've been experimenting with camera positions and lighting. This Security DVR has worked perfectly.
All features work, as advertised, and are well implemented.
PROS:
-Motion detection with pre-record (pre-time stamps motion event) works great. I really like the function which allows you to fast forward at 32x, and the unit slows right down to 1x right before a car or person walks on my property, then resumes FF when it leaves the frame. I can spend 20 minutes after work, and see every person or vehicle that has entered my property for the past 9 hours I've been at work. Very cool!
-I can access the unit from any computer in my house. The software included allows access to the DVR menu functions as well. Streaming video over my LAN has been glitch free and solid full motion. I haven't tried accessing the box away from home yet. I will update my review if there are any problems with that. (I doubt there will be. The firmware and software have been well de-bugged, for the most part)
CONS:
I only have a couple of gripes about the unit:
-The menu is a little hard to understand, and you have to experiment with certain menu functions to discover what they actually do.(This is obviously a translation issue.) Once you have figured out what does what,
the menu settings are easy to use, and well implemented.
-The compression used by the unit does degrade the resolution a bit, when streaming or recording. Not by much though. The streaming video has very little degradation, and the recorded video is a little worse, with some slight pixelation on the "Best" setting. I understand that this is a compromise between picture quality and disk space, however, I wish it had a better resolution recording option. Large disk drives are relatively cheap anyway. This may become an issue if you are trying to identify a face in the distance. We'll see . . .
Overall, I'm extremely pleased with this Security DVR.
It is well built, and does pretty much everything I would want.
It would be nice to have the USB Flash Drive backup on this one,
but you have to move up to a more expensive model to get that functionality.
For the price, this DVR is an absolute BARGAIN! I've seen VERY similar Security DVRs for $180 and up. (sans drive)
I highly recommend this unit.New 4 Channel Embedded Linux US411L H.264 Network DVR With No Hard Drive, Real time True Triplex with built web server for remote viewing and operation, backup and operation 4CH DVR 120FPS SATA ready. Overview

Want to learn more information about New 4 Channel Embedded Linux US411L H.264 Network DVR With No Hard Drive, Real time True Triplex with built web server for remote viewing and operation, backup and operation 4CH DVR 120FPS SATA ready.?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...