or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
Sell Back Your Copy
For a $1.24 Gift Card
Trade in
More Buying Choices
Have one to sell? Sell yours here
Hack the Stack: Using Snort and Ethereal to Master The 8 Layers of An Insecure Network
 
 
Tell the Publisher!
I'd like to read this book on Kindle

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Hack the Stack: Using Snort and Ethereal to Master The 8 Layers of An Insecure Network [Illustrated] [Paperback]

Michael Gregg (Author), Stephen Watkins (Author), George Mays (Author), Chris Ries (Author), Ronald M. Bandes (Author), Brandon Franklin (Author)
3.5 out of 5 stars  See all reviews (6 customer reviews)

List Price: $51.95
Price: $34.87 & this item ships for FREE with Super Saver Shipping. Details
You Save: $17.08 (33%)
  Special Offers Available
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Only 1 left in stock--order soon (more on the way).
Want it delivered Monday, January 30? Choose One-Day Shipping at checkout. Details
Textbook Student FREE Two-Day Shipping for Students. Learn more


Book Description

1597491098 978-1597491099 December 27, 2006 1
This book looks at network security in a new and refreshing way. It guides readers step-by-step through the "stack" -- the seven layers of a network. Each chapter focuses on one layer of the stack along with the attacks, vulnerabilities, and exploits that can be found at that layer. The book even includes a chapter on the mythical eighth layer: The people layer.

This book is designed to offer readers a deeper understanding of many common vulnerabilities and the ways in which attacker's exploit, manipulate, misuse, and abuse protocols and applications. The authors guide the readers through this process by using tools such as Ethereal (sniffer) and Snort (IDS). The sniffer is used to help readers understand how the protocols should work and what the various attacks are doing to break them. IDS is used to demonstrate the format of specific signatures and provide the reader with the skills needed to recognize and detect attacks when they occur.

What makes this book unique is that it presents the material in a layer by layer approach which offers the readers a way to learn about exploits in a manner similar to which they most likely originally learned networking. This methodology makes this book a useful tool to not only security professionals but also for networking professionals, application programmers, and others. All of the primary protocols such as IP, ICMP, TCP are discussed but each from a security perspective. The authors convey the mindset of the attacker by examining how seemingly small flaws are often the catalyst of potential threats. The book considers the general kinds of things that may be monitored that would have alerted users of an attack.

* Remember being a child and wanting to take something apart, like a phone, to see how it worked? This book is for you then as it details how specific hacker tools and techniques accomplish the things they do.

* This book will not only give you knowledge of security tools but will provide you the ability to design more robust security solutions

* Anyone can tell you what a tool does but this book shows you how the tool works

Special Offers and Product Promotions

  • Buy $50 in qualifying physical textbooks, get $5 in Amazon MP3 Credit. Here's how (restrictions apply)

Frequently Bought Together

Hack the Stack: Using Snort and Ethereal to Master The 8 Layers of An Insecure Network + Managing Security with Snort and IDS Tools + Snort IDS and IPS Toolkit (Jay Beale's Open Source Security)
Price For All Three: $92.43

Show availability and shipping details

Buy the selected items together
  • In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Managing Security with Snort and IDS Tools $26.50

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Snort IDS and IPS Toolkit (Jay Beale's Open Source Security) $31.06

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details



Editorial Reviews

About the Author

Michael Gregg is the President of Superior Solutions, Inc. and has more than 20 years' experience in the IT field. He holds two associate's degrees, a bachelor's degree, and a master's degree and is certified as CISSP, MCSE, MCT, CTT+, A+, N+, Security+, CNA, CCNA, CIW Security Analyst, CCE, CEH, CHFI, CEI, DCNP, ES Dragon IDS, ES Advanced Dragon IDS, and TICSA. Michael's primary duty is to serve as project lead for security assessments, helping businesses and state agencies secure their IT resources and assets. Michael has authored four books, including Inside Network Security Assessment, CISSP Prep Questions, CISSP Exam Cram2, and Certified Ethical Hacker Exam Prep2. He has developed four high-level security classes, including Global Knowledge's Advanced Security Boot Camp, Intense School's Professional Hacking Lab Guide, ASPE's Network Security Essentials, and Assessing Network Vulnerabilities. He has written over 50 articles featured in magazines and Web sites, including Certification Magazine, GoCertify, The El Paso Times, and SearchSecurity. Michael is also a faculty member of Villanova University and creator of Villanova's college-level security classes, including Essentials of IS Security, Mastering IS Security, and Advanced Security Management. He also serves as a site expert for four TechTarget sites, including SearchNetworking, SearchSecurity, SearchMobileNetworking, and SearchSmallBiz. He is a member of the TechTarget Editorial Board.

Stephen Watkins (CISSP) is an Information Security Professional with more than 10 years of relevant technology experience, devoting eight of these years to the security field. He currently serves as Information Assurance Analyst at Regent University in southeastern Virginia. Before coming to Regent, he led a team of security professionals, providing in-depth analysis for a global-scale government network. Over the last eight years, he has cultivated his expertise with regard to perimeter security and multilevel security architecture. His Check Point experience dates back to 1998 with FireWall-1 version 3.0b. He earned his B.S. in Computer Science from Old Dominion University and his M.S. in Computer Science, with Concentration in InfoSec, from James Madison University.

George Mays (CISSP, CCNA, A+, Network+, Security+, INet+) is an independent consultant with 35 years' experience in computing, data communications, and network security. He holds a B.S. in Systems Analysis. He is a member of the IEEE, CompTIA, and Internet Society.

Chris Ries is a Security Research Engineer for VigilantMinds Inc., a managed security services provider and professional consulting organization based in Pittsburgh. His research focuses on the discovery, exploitation, and remediation of software vulnerabilities, analysis of malicious code, and evaluation of security software. Chris has published a number of advisories and technical white papers based on his research and has contributed to several books on information security. Chris holds a bachelor's degree in Computer Science with a Mathematics Minor from Colby College, where he completed research involving automated malicious code detection. Chris has also worked as an analyst at the National Cyber-Forensics & Training Alliance (NCFTA), where he conducted technical research to support law enforcement.

Ronald M. Bandes (CISSP, CCNA, MCSE, Security+) is an independent security consultant. Before becoming an independent consultant, he performed security duties for Fortune 100 companies such as JP Morgan, Dun and Bradstreet, and EDS. Ron holds a B.A. in Computer Science.

Brandon Franklin (GCIA, MCSA, Security+) is a network administrator with KIT Solutions, Inc. KIT (Knowledge Based Inormation Technology) Solutions, Inc. creates intelligent systems for the health and human services industry that monitor and measure impact and performance outcomes and provide knowledge for improved decision making. A KIT system enables policy makers, government agencies, private foundations, researchers, and field practitioners to implement best practices and science-based programs, demonstrate impacts, and continuously improve outcomes. Brandon formerly served as the Team Lead of Intrusion Analysis at VigilantMinds Inc., a Pittsburgh-based managed security services provider.


Product Details

  • Paperback: 416 pages
  • Publisher: Syngress; 1 edition (December 27, 2006)
  • Language: English
  • ISBN-10: 1597491098
  • ISBN-13: 978-1597491099
  • Product Dimensions: 8.8 x 7 x 1.4 inches
  • Shipping Weight: 1.4 pounds (View shipping rates and policies)
  • Average Customer Review: 3.5 out of 5 stars  See all reviews (6 customer reviews)
  • Amazon Best Sellers Rank: #1,125,650 in Books (See Top 100 in Books)

 

Customer Reviews

6 Reviews
5 star:
 (1)
4 star:
 (1)
3 star:
 (4)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
3.5 out of 5 stars (6 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

25 of 28 people found the following review helpful:
3.0 out of 5 stars Good idea, inadequate execution, November 5, 2006
This review is from: Hack the Stack: Using Snort and Ethereal to Master The 8 Layers of An Insecure Network (Paperback)
I teach a course called "TCP/IP Weapons School" that involves walking students up the OSI model. We look at network traces generated by tools and techniques to defeat security measures. When I saw "Hack the Stack" (HTS) I thought it might make a good resource for my class, since HTS seemed to advocate a similar approach. Unfortunately, technical errors, shoddy production, internal repetition and poor organization, and a lack of original material make me question the value of HTS.

A critical aspect of a security book is technical accuracy, but HTS does not deliver. In some cases the book is half-right, or it omits important elements. For example, p 9 implies only port 20 TCP is used for TCP data; that's true for the server in active FTP, but passive FTP uses arbitrary ports. p 15 says SOCKS is "Windows Sockets," when SOCKS is a proxy protocol. p 71 says CSMA/CA (wireless) is similar to CSMA/CD (traditional Ethernet), but the two protocols are very different; CSMA/CA is much more complex. p 115 should say IP proto 41 is "IPv6 in IPv4", and not imply that IP proto 41 is somehow "IPv6". p 118 says "ICMP messages cannot be sent in response to other ICMP messages." That's not true; otherwise, ICMP echo would not be able to elicit an ICMP echo reply. (The authors meant ICMP error messages cannot elicit ICMP errors.)

Several times the book makes odd statements. p 14 says the first virus concept appeared in 1984, but non-PC viruses existed in the 1970s and the first PC virus (Elk Cloner) was in the wild in 1982. p 3 says "IDS has a short history" by citing Dorothy Denning's work in 1983, but ignores James Anderson's 1980 work for the Air Force as the first real IDS pioneer. p 119 says "consider disabling ICMP," which ignores breaking path MTU discovery and other crucial ICMP services. p 131 says idle scans were developed in 1988; it's 1998. p 131 also says a SYN to a closed port elicits a RST response, but it's really a RST ACK.

On the production side, Syngress did a very poor job publishing screen shots. HTS advertises "using Snort and Ethereal" in the book's subtitle, but many of the Ethereal screen captures are either too tiny or fuzzy or blacked out to be legible. This defeats the purpose of including them.

As far as organization goes, HTS is supposed to take a layer-by-layer look at security issues. However, material that should stay in one section is sometimes repeated or introduced in other sections. For example, there is no need to be discussing ARP (layer 2) manipulation in the layer 5 chapter, or again in the layer 6 chapter. HTTP interception tools should not appear in the layer 6 chapter when they fit properly in layer 7. SYN floods should not pop up in layer 4 and 5 chapters; pick one and consolidate coverage there. p 162 even says "Exchanges at the Transport layer are typically in clear text... FTP is a good example of this." The first assertion is wrong, and why is FTP appearing in the layer 4 chapter anyway? p 92 should recognize that PGP is not "Pretty Good Protection."

I didn't think it made sense to introduce Ethereal in ch 3, and then split coverage of Snort between ch 5 and ch 6. Furthermore, HTS made the mistake frequently repeated elsewhere of configuring Snort to log directly to a database. Without using unified logging with a spool reader like Barnyard, such a setup is only useful in demonstration purposes where packet loss is not an issue. To the extent necessary, Ethereal and Snort should have appeared in appendices and not the main "layer" text.

Finally, I did not find anything in the technical realm I had not read elsewhere. All of the tools (Nmap, Nessus, Hping, Amap, etc.) are familiar to most every network security practitioner, or they have been documented in great books like Anti-Hacker Toolkit or even other Syngress titles. It's ok to cover such tools if they are used in a novel way, but that didn't happen in HTS. I hoped to read something more original, say in the layer 4 chapter. Instead HTS discusses port scanning, OS fingerprinting, and SYN floods.

The two chapters which may be of interest to readers include those on layer 1 and "layer 8." Layer 1 offers some basic lock picking information as well as the sort of physical security suggestions you'd find in a CISSP book. On a sad note, the vignette on Rick Rescorla on p 35 doesn't mention that he tragically died on 9/11. Layer 8 discusses policies, social engineering, and related "people issues."

Overall, I think there is room for a book like HTS. It's too bad this one did not deliver what I was expecting. I do appreciate the authors citing my network security monitoring methodology on p 232.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4 of 4 people found the following review helpful:
3.0 out of 5 stars Now exactly what I expected, but a good reference starter, December 12, 2006
This review is from: Hack the Stack: Using Snort and Ethereal to Master The 8 Layers of An Insecure Network (Paperback)
I anticipated the book going more in depth in certain areas, but the overview it provided for each section was a great starter. I do agree with another reviewer that stated it was missing references to certain website links or direction to where to gather more information. This was a downside, mainly in dealing with large technical references such as this book. An index or glossary, noting the pages used and full definitions would have gone a long way.

I did like some of the directions on testing and building of products, scripts or other methods to verify your own environment however. I do realize you can only fit so much detail, but some definition areas needed more explanation that a simple paragraph. I would have looked to eliminate those and expand on others to give the feeling of deeper information.

Now saying all that, I appreciated the adding of the 8th layer that is not mentioned anywhere else. The reading was fairly straightforward and simple for the intermediate level technical administrator. Some of the references are not for the basic entry level, as it jumps right into topics that assume basic knowledge of networks, protocols and even mail and messaging.

I shared this with some staff in the office for reading of particular areas and will be keeping it on the bookshelf (which means it is a keeper)
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


2 of 2 people found the following review helpful:
4.0 out of 5 stars Unique Concept - Good Introduction to Topics, February 9, 2007
This review is from: Hack the Stack: Using Snort and Ethereal to Master The 8 Layers of An Insecure Network (Paperback)
Hack the Stack is a Syngress title that primarily focuses on security topics layer by layer. The book takes a concept most people know, the OSI model, and uses that approach to discuss security exploits, vulnerabilities, and defenses. I liked the concept and the manner in which the material was presented. The books takes the 7 layer model and adds one more for people, this made sense to me.

The book starts out with the physical layer and continues up through each layer. The final chapter is a kind of checklist that reviews the material covered in the other chapters. Each chapter provides a hands-on security project. The ones on Snort and Bluetooth were my favorites. The book uses a number of Open Source or free tools like Snort and Wireshark to explain concepts I often wondered about. The authors seem to know the material but as others have said I wish they would have provided more resources and a glossary. With that in mind I rated this book four stars.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews




Only search this product's reviews



Inside This Book (learn more)
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
burp proxy, code listing, tunnel mode, packet structure, acknowledgment sequence number, header format, capture options, source sequence number, port knocking, nop sled, passive sniffing, canary value, exploit string, active sniffing, idle host, session teardown, weak configurations, idle scan, session startup, overwrite the return address, victim server, alert tcp, rule header, questions about this chapter, authoritative server
Key Phrases - Capitalized Phrases (CAPs): (learn more)
The Application Layer, The Transport Layer, The People Layer, The Network Layer, The Presentation Layer, The Physical Layer, The Session Layer, The Data Link Layer, Network Security, Frequently Asked Questions, Transmission Control Protocol, Solutions Fast Track, Transport Mode, Internet Protocol, Ask the Author, Denial of Service, John the Ripper, Internet Control Message Protocol, Hypertext Transfer Protocol, Address Resolution Protocol, Security Project, Simple Mail Transfer Protocol, User Datagram Protocol, Secure Shell, Output System
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Surprise Me!
Search Inside This Book:


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums





Look for Similar Items by Category


Look for Similar Items by Subject