Have one to sell? Sell yours here
Hack Attacks Revealed: A Complete Reference for UNIX, Windows, and Linux with Custom Security Toolkit, Second Edition
 
 
Tell the Publisher!
I'd like to read this book on Kindle

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Hack Attacks Revealed: A Complete Reference for UNIX, Windows, and Linux with Custom Security Toolkit, Second Edition [Paperback]

John Chirillo (Author)
3.9 out of 5 stars  See all reviews (14 customer reviews)


Available from these sellers.


Textbook Student FREE Two-Day Shipping for Students. Learn more


Book Description

0471232823 978-0471232827 August 21, 2002 2
The much-anticipated second edition of the bestselling book that details network security through the hacker's eye
Since the first edition of Hack Attacks Revealed was published, many new attacks have been made on all operating systems, including UNIX, Windows XP, Mac OS, and Linux, and on firewalls, proxies, and gateways. Security expert John Chirillo is ready to tackle these attacks with you again. He has packed the Second Edition of his all-in-one reference with forty percent new material.
In this fascinating new edition, you'll discover:
* The hacker's perspective on security holes in UNIX, Linux, and Windows networks
* Over 170 new vulnerabilities and exploits
* Advanced discovery techniques
* A crash course in C for compiling hacker tools and vulnerability scanners
* The top seventy-five hack attacks for UNIX and Windows
* Malicious code coverage of Myparty, Goner, Sircam, BadTrans, Nimda, Code Red I/II, and many more
* TigerSuite Professional 3.5 (full suite single license)


Editorial Reviews

Review

&well worth the read& -- r

“…well worth the read…” (Slashdot, 6 March 2003)

From the Back Cover

The much-anticipated second edition of the bestselling book that details network security through the hacker's eye

Since the first edition of Hack Attacks Revealed was published, many new attacks have been made on all operating systems, including UNIX, Windows XP, Mac OS, and Linux, and on firewalls, proxies, and gateways. Security expert John Chirillo is ready to tackle these attacks with you again. He has packed the Second Edition of his all-in-one reference with forty percent new material.

In this fascinating new edition, you'll discover:
* The hacker's perspective on security holes in UNIX, Linux, and Windows networks
* Over 170 new vulnerabilities and exploits
* Advanced discovery techniques
* A crash course in C for compiling hacker tools and vulnerability scanners
* The top seventy-five hack attacks for UNIX and Windows
* Malicious code coverage of Myparty, Goner, Sircam, BadTrans, Nimda, Code Red I/II, and many more
* TigerSuite Professional 3.5 (full suite single license)

Product Details

  • Paperback: 960 pages
  • Publisher: Wiley; 2 edition (August 21, 2002)
  • Language: English
  • ISBN-10: 0471232823
  • ISBN-13: 978-0471232827
  • Product Dimensions: 9.4 x 7.7 x 2 inches
  • Shipping Weight: 3.6 pounds
  • Average Customer Review: 3.9 out of 5 stars  See all reviews (14 customer reviews)
  • Amazon Best Sellers Rank: #1,292,881 in Books (See Top 100 in Books)

More About the Author

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

14 Reviews
5 star:
 (8)
4 star:
 (2)
3 star:
 (1)
2 star:
 (1)
1 star:
 (2)
 
 
 
 
 
Average Customer Review
3.9 out of 5 stars (14 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

24 of 25 people found the following review helpful:
1.0 out of 5 stars Doesn't deliver what it promises..., July 11, 2003
By A Customer
Amazon Verified Purchase(What's this?)
This review is from: Hack Attacks Revealed: A Complete Reference for UNIX, Windows, and Linux with Custom Security Toolkit, Second Edition (Paperback)
Reviewed: Hack Attacks Revealed, 2nd Edition, 2002

I must say I am thoroughly disappointed with this book. The book's description, as well as other readers' comments led me to believe that this book would have been more than just a compilation of information that could be freely obtained at the dozens of security related web sites. Sadly, this was not the case.

The bulk of the book merely describes (mostly outdated) common
attacks/vulnerabilities, without getting into much detail why they exist and the underlying explanations on how they are exploited. As such the book reads like "For Vulnerability X, Install patch Y" without getting into more detail. Heck, even Microsoft's Security Bulletins give more info that this!

Many of the "75 Top Hack Attacks" that the book promises can be freely found online (check CERT's site).

The general impression I get from reading this book is that the author tried his best to fill up space in order to deliver an impressively thick book. Was it a requirement that he include SCREENSHOTS of various hacking tools/trojans, including step-by-step INSTALL SCREENSHOTS for the included TigerSuite software? (If you don't know how to install software then you need to develop more skills before learning about hacking!). Did he HAVE to include the useless 10 year old 'how to build a modem filter' BBS textfile (which by the way doesn't filter noise on modern modems)? Did the publisher mandate that he include 9 PAGES of Decimal-to-Hex conversion tables when you could use, say, Windows Calculator to do any needed conversions?

Another thing I disliked was that Windows XP as well as Wireless networks (802.11/WEP were glossed over) were not really covered in the sort of detail that I desired.

And, although I appreciate that a basic understanding of the x86 instruction set is required for better understanding low level security issues, I really don't see the point to Chapter 13's discussion on programming "How to Draw Circles in DOS mode" using the VESA bios interface. This is, in my opinion, not relevant considering the book's topic, so why include it? (A better choice would be explaining how the stack is used in high level languages (C, C++) and how buffer overrun hacks work). If you want to learn C, Assembly, or graphics programming buy a book dedicated to these topics. I think it's safe to say that the average reader will NOT become a programmer after reading the "Crash course in C" - it's an unreaslistic expectation.

And to top it all off, the final insult to readers is the interruption of the author's hacking experience "Intuitive Intermission" with the phrase "... to be continued in: Hack Attacks Denied, 2nd Edition". I guess both the author and publisher want you to buy both books!

My chief complaint with the book is that it doesn't seem to know who the reader is. In some areas the author gets down-and-dirty technical (x86 assembly/C programming) while in others he doesn't really explain details or just mentions things in passing (case in point: nowhere does he explain workings of a typical buffer overrun exploit, etc). Also, the author really does not give advice on how to secure or harden systems, aside from "install the update patch". For a book whose focus is security/hacking that's a pretty fatal flaw.

Like I said earlier, this book really seems to me like the author just threw any material that he could find that was remotely related to hacking and presto, one hacking book ready to ship!

If you are new to either the computer or security-related fields then perhaps this book may be of some value to you. If you are not an absolute beginner and know how to search the web, then I'd say that you probably don't need this book. Even if you do buy this book, it, like any security related book, will become technically obsolete as new software/exploits/patches are found.

Quote: (under "Who should read this book?")

"The hacking enthusiast and admirer of such films as Sneakers, The Matrix, Hackers, and Swordfish"

If you still need another reason not to purchase this book, the above quote says it all!
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


10 of 11 people found the following review helpful:
1.0 out of 5 stars Author does not understand his subject, September 22, 2004
By 
A reader (Ottawa,Ontario,Canada) - See all my reviews
This review is from: Hack Attacks Revealed: A Complete Reference for UNIX, Windows, and Linux with Custom Security Toolkit, Second Edition (Paperback)
This book has done nothing to dispell my theory that the information
content of a book is often inversely proportional to the number of pages
in the book. I'm 200 pages into it and that's as far as I'm
going to get. I expected some basic filler/theory in the first few
pages, but plowed on in the hopes that the author understood
the theory he was presenting and would use it later to explain security
exploits. However, I lost all confidence in the book when
I reached page 167, where the author demonstrates that he doesn't
understand ping and/or DNS. I don't bring this up to nitpick. I bring it up
because I think that anybody with pretensions to
being a security expert had better know the basics of how the
Internet works. How is anybody to make sense of, say, DNS spoofing,
without knowing how DNS works?

In case it's not obvious, the author confuses and muddles together
the actions of resolving a DNS domain name to an IP
address, and then using that IP address to send an ICMP echo
request to the destination. This may seem like a minor thing,
but its not just a typo (he makes the same mistake in three
different places on page 167), and security is a confusing
enough business without muddled descriptions like these.

On a more minor note, I do not see the point in filling page
after page with pretty pictures of the GUIs that hackers use
at their end. The publishers probably know better than I do
what sells today, but I don't understand why they and/or the
authors apparently feel that the thicker a book is, the better.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


9 of 10 people found the following review helpful:
5.0 out of 5 stars Computer security made simpler......, October 15, 2002
By 
Kelly Larsen (Augusta Georgia) - See all my reviews
This review is from: Hack Attacks Revealed: A Complete Reference for UNIX, Windows, and Linux with Custom Security Toolkit, Second Edition (Paperback)
I have been teaching Windows 2000 and Unix security for the U.S. Army for 3 years. I am constantly searching for a book that will provide true insight into the hacker mindset and methods. Most books dawdle in the routine and well known hacks and still leave you wanting. "Hack Attacks Revealed, 2nd edition", takes you to the next level. It is the single best security reference book that I've seen.

You rarely find a book that provides indepth coverage of Windows, Unix, and Linux security. Hack Attacks Revealed's information, tutorials, and tools provide you with everything you would need to test and secure a computer system or network. As a bonus, the fully licensed TigerSuite Professional (version 3.5) is included on the accompanying CD. This is an amazing grouping of tools to analyze and test the security of a computer network. In class, I routinely use TigerSuite to demonstrate security shortfalls. My students are so impressed that they immediately ask me where I got it and how can they get it.

"Hack Attacks Revealed" has something for every skill level, whether it is teaching you how to subnet, compile a security tool or walking you through a buffer overflow. The First edition was great and John Chirillo found a way to go it one better.

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews











Only search this product's reviews



Inside This Book (learn more)
First Sentence:
Approximately 30 years ago, communication protocols were developed so that individual stations could be connected to form a local area network (LAN). Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
complete system compromise, breach detection, hostname sshd, targ addr, ovactiond process, compensation attack detector, virtual server simulator, unsigned char color, arbitrary code execution, dtspcd daemon, known malicious traffic, sufficient input validation, source code referenced, daemon privilege, unauthorized root access, active display page, many buffer overflow conditions, nonmandatory attributes, other vulnerable systems, remote control daemon, int loh, available node addresses, scanner program reports, hostname authentication, struct udphdr
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Hack State, Token Ring, Microsoft Windows, Code Red, Internet Explorer, Visual Basic, Denial-of-Service Attack Synopsis, United States, Fast Ethernet, Gigabit Ethernet, Back Orifice, Basic Rate, Conversion Table, Internet Information Server, Microsoft Excel, Network Associates, End Delimiter, Portal of Doom, Start Delimiter, Subprocess Control, Advanced Server, Back Construction, Communication Sniffer, Microsoft Corporation, Red Hat Linux
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:




What Other Items Do Customers Buy After Viewing This Item?


Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product).
 
(23)
(17)

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums



So You'd Like to...


Create a guide


Look for Similar Items by Category


Look for Similar Items by Subject