Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.
Hacking Exposed Cisco Networks and over 300,000 other books are available for Amazon Kindle – Amazon’s new wireless reading device. Learn more

 

or
Sign in to turn on 1-Click ordering.
 
   
More Buying Choices
40 used & new from $9.60

Have one to sell? Sell yours here
 
   
Hacking Exposed Cisco Networks: Cisco Security Secrets & Solutions
 
 
Start reading Hacking Exposed Cisco Networks on your Kindle in under a minute.

Don’t have a Kindle? Get yours here.
 
  

Hacking Exposed Cisco Networks: Cisco Security Secrets & Solutions (Paperback)

by Andrew Vladimirov (Author), Konstantin Gavrilenko (Author), Andrei Mikhailovsky (Author) "The task of securing a corporate or organizational network with multiple routers, switches, servers, workstations, and other more exotic hosts is not easy to accomplish..." (more)
Key Phrases: echo request seq, rogue router, arp inspection, Risk Rating, Cisco Catalyst, Hacking Exposed (more...)
4.3 out of 5 stars See all reviews (10 customer reviews)

List Price: $49.99
Price: $34.99
You Save: $15.00 (30%)
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Only 5 left in stock--order soon (more on the way).

Want it delivered Monday, July 13? Choose One-Day Shipping at checkout. Details
24 new from $26.43 16 used from $9.60
Also Available in: List Price: Our Price: Other Offers:
Kindle Edition (Kindle Book) $31.49

Frequently Bought Together

Hacking Exposed Cisco Networks: Cisco Security Secrets & Solutions + Hacking Exposed Wireless: Wireless Security Secrets & Solutions + Hacking Exposed VoIP: Voice Over IP Security Secrets & Solutions
Price For All Three: $101.47

Show availability and shipping details


Customers Who Bought This Item Also Bought

Hacking Exposed VoIP: Voice Over IP Security Secrets & Solutions

Hacking Exposed VoIP: Voice Over IP Security Secrets & Solutions

by David Endler
4.3 out of 5 stars (3)  $31.49
Hacking Exposed Computer Forensics: Computer Forensics Secrets & Solutions

Hacking Exposed Computer Forensics: Computer Forensics Secrets & Solutions

by Chris Davis
4.0 out of 5 stars (7)  $34.94
Hacking Exposed Windows: Microsoft Windows Security Secrets and Solutions, Third Edition

Hacking Exposed Windows: Microsoft Windows Security Secrets and Solutions, Third Edition

by Joel Scambray
4.6 out of 5 stars (5)  $31.49
Windows Server 2003 (Hacking Exposed)

Windows Server 2003 (Hacking Exposed)

by Joel Scambray
Hacking Exposed Linux, 3rd Edition

Hacking Exposed Linux, 3rd Edition

by ISECOM
3.7 out of 5 stars (7)  $31.49
Explore similar items

Editorial Reviews

Product Description
Here is the first book to focus solely on Cisco network hacking, security auditing, and defense issues. Using the proven Hacking Exposed methodology, this book shows you how to locate and patch system vulnerabilities by looking at your Cisco network through the eyes of a hacker. The book covers device-specific and network-centered attacks and defenses and offers real-world case studies.

From the Back Cover

Implement bulletproof Cisco security the battle-tested Hacking Exposed way

Defend against the sneakiest attacks by looking at your Cisco network and devices through the eyes of the intruder. Hacking Exposed Cisco Networks shows you, step-by-step, how hackers target exposed systems, gain access, and pilfer compromised networks. All device-specific and network-centered security issues are covered alongside real-world examples, in-depth case studies, and detailed countermeasures. It’s all here--from switch, router, firewall, wireless, and VPN vulnerabilities to Layer 2 man-in-the-middle, VLAN jumping, BGP, DoS, and DDoS attacks. You’ll prevent tomorrow’s catastrophe by learning how new flaws in Cisco-centered networks are discovered and abused by cyber-criminals. Plus, you’ll get undocumented Cisco commands, security evaluation templates, and vital security tools from hackingexposedcisco.com.

  • Use the tried-and-true Hacking Exposed methodology to find, exploit, and plug security holes in Cisco devices and networks
  • Locate vulnerable Cisco networks using Google and BGP queries, wardialing, fuzzing, host fingerprinting, and portscanning
  • Abuse Cisco failover protocols, punch holes in firewalls, and break into VPN tunnels
  • Use blackbox testing to uncover data input validation errors, hidden backdoors, HTTP, and SNMP vulnerabilities
  • Gain network access using password and SNMP community guessing, Telnet session hijacking, and searching for open TFTP servers
  • Find out how IOS exploits are written and if a Cisco router can be used as an attack platform
  • Block determined DoS and DDoS attacks using Cisco proprietary safeguards, CAR, and NBAR
  • Prevent secret keys cracking, sneaky data link attacks, routing protocol exploits, and malicious physical access


See all Editorial Reviews

Product Details

  • Paperback: 400 pages
  • Publisher: McGraw-Hill Osborne Media; 1 edition (December 15, 2005)
  • Language: English
  • ISBN-10: 0072259175
  • ISBN-13: 978-0072259179
  • Product Dimensions: 9.1 x 7.3 x 1.4 inches
  • Shipping Weight: 2.2 pounds (View shipping rates and policies)
  • Average Customer Review: 4.3 out of 5 stars See all reviews (10 customer reviews)
  • Amazon.com Sales Rank: #551,056 in Books (See Bestsellers in Books)

Inside This Book (learn more)
First Sentence:
The task of securing a corporate or organizational network with multiple routers, switches, servers, workstations, and other more exotic hosts is not easy to accomplish. Read the first page
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
echo request seq, rogue router, arp inspection, network security elements, protocol decode listening, denied tcp, routing suite, permitted icmp, hacked router, verbose output suppressed, malicious route, hopping attack, open chargen, payload file, guess probability, failover cable, malicious updates, backup designated router, passive sniffing, network enumeration, root bridge elections, bypassing traffic, branch routers, eigrp packets, router configuration files
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Risk Rating, Cisco Catalyst, Hacking Exposed, Cisco Aironet, Cisco Torch Mass Scanner, Cisco Guard, Cisco Internetwork Operating System Software, Checksum Sum, Access Registrar, Load Meter, Open Shortest Path First, Simple Network Management Protocol, Trivial File Transfer Protocol, Border Gateway Protocol, Chunk Manager, Compiled Wed, Device Manager, Generic Routing Encapsulation, Interior Gateway Routing Protocol, Microsoft Windows, Network Registrar, Cisco Discovery Protocol, Cisco Traffic Anomaly Detector, Internet Control Message Protocol, Internet Protocol
New!
Books on Related Topics | Concordance | Text Stats
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:



Books on Related Topics (learn more)
 
 

What Do Customers Ultimately Buy After Viewing This Item?


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
Check the boxes next to the tags you consider relevant or enter your own tags in the field below.

Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

 

Customer Reviews

10 Reviews
5 star:
 (4)
4 star:
 (5)
3 star:
 (1)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.3 out of 5 stars (10 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
14 of 14 people found the following review helpful:
4.0 out of 5 stars A strong book, with decent concepts, but needs some polishing, February 26, 2006
Hacking Exposed Cisco Networks" (HECN) by Vladimirov, Gavrilenko, Vizulis and Mikhailovsky is the first book of it's kind to focus entirely on hacking the Cisco product line. The book offers a novel concept, and goes into some undocumented areas, but please do not expect to be seeing the enable-mode router prompt by page 50.

My first impression of Hacking Exposed Cisco Networks is that the book was simply 'rushed' to market. The book begins with an intro by Michael Lynn, who made a name for himself at the 2005 Black Hat Briefings by 'publicly demonstrating the ability to reliably exploit buffer overflows on Cisco routers.' My feeling is that after the Black Hat Briefings, a rush was put on HECN to have it published simply to ride on this wave.

The book is divided into 3 Parts and 1 Appendix and includes a total of 14 chapters. The first section, Foundations, gives a review of Cisco design models, different security elements (firewall, IDS, VPN and AAA) and examples of real world security issues.

The second section (and the main section of the book) is titled `Hacking the Box' and dives into various methods of penetrating Cisco devices. The first chapter in this section discusses using different information sources to develop a profile (what to search for on a web search engine, autonomous system discovery, Internet routing servers and tables, etc..). Next, a 50 page chapter discusses enumerating and fingerprinting Cisco devices. Subsequent chapters discuss password attacks, SNMP community string attacks, wardialing, IOS exploitation and password cracking. After penetrating a device, the next chapter shows how to exploit and preserve access.

The last section discusses protocol exploitation, which needs not be focused solely on Cisco devices; most of these attacks are common across all vendors. This includes chapters on exploiting Vlans, GRE packet injection, EAP-LEAP cracking. The last chapter discusses routing protocol exploitation including exploits for RIP, EIGRP and BGP. The Appendix includes listing undocumented Cisco commands. While these commands can also be found on the web, the book discusses ways to use the commands in context of a hacking exploit.

Some of the items I found useful from HECN:
* Chapter 4 provides a respectable list of AS profiling techniques. Starting on page 108 is an excellent introduction to a tool to help sniff routing updates (the autonomous system scanner).
* Chapter 5 provides a great chart on Cisco specific protocols (page 124). The chapter also has a very good discussion on Cisco fingerprinting.
* Chapter 8 provides a one-of-a-kind discussion on IOS memory dissection. I was extremely impressed by the discussion on stack heaps. The TFTP buffer overflow on page 281 is a great example of where the future of Cisco IOS hacking may lie. While some believe buffer overflows are soooo 2005, I think believe there is amply room to further explore this within the context of Cisco devices.

HECN also has some weak areas:
* page 24 - mentions all routers support NTP - not true, some of the lower-end IOSs only support SNTP.
* page 28 - mentions `extra flags' for UDP connections. UDP has no flags, but certainly TCP does.
* page 133 - mentions a tool, the "ST-divine tool", as available on the book's website, but the tool is not listed at the book's website.
* Chapters 1 and 3 really don't offer anything new, and only distract from the overall quality of the book.

These and other such typos/editorial mistakes don't distract too much from the overall focus of HECN. The book tries to be a proof-of-concept with many different exploits. One feels that the authors were huddled around a few Cisco boxes, trying whatever exploits they could find to bust the box. It would be very easy to rack up some routers and switches, copy the configurations provided in the book, and follow them page by page as they perform various hacking techniques.

As an owner of over 50 books dedicated to Cisco, this book goes into an area not covered by any other book in my library. And, for that fact alone, I have to respect the book. However, I have to believe that if HECN had only gone through a further round of editing, that the overall structure of the book would be much better. In the end, I do recommend this book, simply because of the novelty of the subject and due to the amount of effort that is apparent throughout the text.

I give this book 4 pings out of 5:
!!!.!
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
11 of 11 people found the following review helpful:
4.0 out of 5 stars A good first cut at Cisco-centric attack and defense, March 10, 2006
I've always been a fan of Osborne's Hacking Exposed books (although subjects like "Computer Forensics" don't seem to fit the spirit of the series). I previously read Wi-Foo: The Secrets of Wireless Hacking by the same authors who wrote Hacking Exposed: Cisco Networks (HECN). Comparing the two books, I agree with previous reviewer Sean E. Connelly; I think HECN was rushed to market. The book needs better technical review, proofreading, and copyediting as well. Nevertheless, I still recommend reading HECN -- it's a unique book on a critical subject.

One of the more striking aspects of HECN is the amount of original research committed to the book. Sure, the authors document already known Cisco vulnerabilities. However, they also developed a suite of tools to implement attacks discussed in HECN. They demonstrate how to apply various tools and when those applications are realistic. HECN's authors discovered a variety of new exploits (documented at the book Web site) which they submitted to Cisco's PSIRT. I appreciated this degree of originality.

HECN is on the leading edge of attacks happening right now. While reading the book I assisted with an incident response involving a Cisco switch. It appeared that bot net command-and-control traffic was originating from a switch on a client network. Upon closer inspection, I could tell that unknown intruders were bouncing IRC traffic through the management interface of the switch, probably using a variant of the ciscoBNC tool introduced in Ch 10. HECN also describes the possibilities offered by Tcl scripting on Cisco routers, which I expect to see intruders abuse.

I had two sorts of problems with HECN. First, the text can be somewhat confusing to follow. In some parts this is caused by the authors' writing style. In others confusion is caused by the authors' unwillingness to fully describe sensitive exploitation techniques. For example, they mention ways to reverse engineer and/or patch IOS binary images, but they are deliberately vague. This helps the authors stay out of trouble with Cisco, but it leaves the reader frustrated. The second problem with HECN involves the tone of the book. In some places I was left wondering why the authors made certain comments. A good example of material that should simply be dropped is the final "case study" at the end of the book.

Some minor technical issues should be fixed in future editions. In addition to those outlined by previous reviewers, I would add the item on p 460 that says AH is IP proto 49; it should be 51. I also thought the Nmap scanning recommendations on p 136 were somewhat silly. It's best to stick with the simplest scan possible and avoid the poorly-named "stealth" options Nmap offers. Finally, some of the screen shots were too fuzzy. Images taken from Ethereal in Ch 4 are examples of this problem.

Overall, I would still buy HECN. Administrators and security professionals must recognize that Cisco equipment (along with infrastructure from other vendors) are actively targeted, exploited, and abused by intruders. HECN explains how this happens and what you can do to prevent, or at least detect, these compromises. It's like 1999 all over again -- get the Hacking Exposed title that will help you mitigate a new class of threats!
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
4 of 4 people found the following review helpful:
5.0 out of 5 stars Excellent Book!!!, February 13, 2006
I found this book super and rather helpful in my CCIE Security exam preparations. After all, this seems to be the only source on Cisco-related attacks available in print. The attacks are well-outlined and supplied with appropriate countermeasures; the fact that the authors did not dwell on common knowledge generic attacks like ARP injections (although the countermeasures against these are provided) is also good, since I can read about them elsewhere. I was also quite surprised to see the bold attempts at supplying two algorithms for constructing IOS worms. Perhaps, such data should not be put onto the public domain, but than, won't the Black Hats think along the same lines anyway ?

As to the comments above, the scans of devices are limited to a single chapter where they rightfuly belong. And "ip inspect tcp max-incomplete host block" is by no means a panacea. First of all, TCP scanning is not limited to the SYN scans. Second, before setting a limit on the TCP half-connects one has to baseline the network behavior first and find out how common the half-connects to the protected hosts are and why do they occur, otherwise there could be connectivity troubles. So, in my opinion, the methods of hiding your routers from attackers described in the book are quite sufficient.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

4.0 out of 5 stars A good reference on Cisco security
If you are a cisco security expert maybe this book will not have any new information for you, but since most of us are not, I would recommend it for anyone who is trying to... Read more
Published 21 months ago by Eric

4.0 out of 5 stars Pretty good
I really nice first attempt at zeroing in on and attacking Cisco devices, something I do for a living. Read more
Published on February 17, 2007 by Richard Campbell

4.0 out of 5 stars Not a great book - not a bad book either
"Hacking Exposed: Cisco Networks" is not bad but then again not great. What caused it to only get 4 out 5 stars was that many of the tools and links no longer work and this... Read more
Published on March 29, 2006 by H. Nussbacher

5.0 out of 5 stars Great Overall View of the Situation
I think that it is difficult, perhaps impossible, to build a modern network that does include at least some Cisco equipment. Read more
Published on March 11, 2006 by John Matlock

5.0 out of 5 stars Quite useful
It's good to have all-in-one reference to Cisco-related attacks, and generally the book seems to be quite useful to all kinds of pentesters, especially if internal security audits... Read more
Published on February 16, 2006 by Alex Lee

5.0 out of 5 stars Excellent book
I work with Cisco routers and switches every day and never considered them to be insecure as long as strong usernames and passwords are set. Read more
Published on February 13, 2006 by Robert Black

3.0 out of 5 stars Informative
This book is pretty informative, however I feel that it is incomplete in more than a few ways. While I have absolutely NO doubt that the authors are very well versed in using... Read more
Published on January 29, 2006 by Relative Unknown

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]


Active discussions in related forums
   


Product Information from the Amapedia Community

Beta (What's this?)



Look for Similar Items by Category


Let Toro Clear the Snow

Let Toro Clear the Snow
Rely on Toro for top-quality snow throwers and power shovels to make snow removal a breeze.

Shop all Toro

 

Big Savings in Books

Bargain Books
Find great titles at fantastic prices in our Bargain Books Store.
 

Buy Three Books, Get a Fourth Free

4-for-3 Books
Order any four eligible books under $10 and get the lowest-price book free in our 4-for-3 Books Store. See more details.
 

Best Books

Best of the Month
See our editors' picks and more of the best new books on our Best of the Month page.
 

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Glenn Beck's Common Sense
Glenn Beck's Common Sense
Darkfever
Darkfever by Karen Marie Moning
The Adventures of Sherlock Holmes
The Adventures of Sherlock Holmes by Arthur Conan, Sir, 1859-1930 Doyle

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates