Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - REVIEW: "Network Security Assessment", Chris McNab

 
Thread Tools Search this Thread
Old 10-15-2004, 06:07 PM   #1
Default REVIEW: "Network Security Assessment", Chris McNab


BKNTSCAS.RVW 20040511

"Network Security Assessment", Chris McNab, 2004, 0-596-00611-X,
U$39.95/C$57.95
%A Chris McNab
%C 103 Morris Street, Suite A, Sebastopol, CA 95472
%D 2004
%G 0-596-00611-X
%I O'Reilly & Associates, Inc.
%O U$39.95/C$57.95 707-829-0515 fax: 707-829-0104
%O http://www.amazon.com/exec/obidos/AS...bsladesinterne
http://www.amazon.co.uk/exec/obidos/...bsladesinte-21
%O http://www.amazon.ca/exec/obidos/ASI...bsladesin03-20
%P 507 p.
%T "Network Security Assessment"

In general, "learn to hack in order to secure" books provide very
little useful material for helping security administrators to protect
their systems. McNab's work is somewhat different: his descriptions
(though not perfect) have a conceptual component, and the details
often use accessible system tools, rather than relying on blackhat
tools (of unknown reliability) or an extensive range of commercial
utilities.

Chapter one defines network security assessment somewhere between
vulnerability scanning and penetration testing, and outlines the
general campaign. A list of scanning tools, with very terse
descriptions, is in chapter two. The querying of public information,
using search engines and network information centres, is in chapter
three. Chapter four provides details on IP network scanning, although
the explanations are not always clear, seemingly missing particulars
or skipping steps. This lack of description is even more evident in
the material on remote information services (DNS - Domain Name
Services, SNMP - Simple Network Management Protocol, LDAP -
Lightweight Directory Access Protocol, and the like) in chapter five.

Chapter six provides content on obtaining information about a number
of Web utilities, products, and services, and lists a number of
specific exploits. Chapter seven gives advice on identifying and
exploiting specific terminal and terminal-like remote services. ftp
and database exploits are listed in chapter eight. Chapter nine
describes some tools for assessing and exploiting network (and
particularly SMB (Server Message Block) services in Windows NT and
2000. Gathering information from SMTP (Simple Mail Transfer Protocol)
is described in chapter ten, as well as a way to code MIME
(Multipurpose Internet Mail Extensions) fields in order to defeat
virus scanning on email. The exploits for VPN (Virtual Private
Network) products, in chapter eleven are product specific and
unstructured. Chapter twelve lists certain UNIX RPC (Remote Procedure
Call) bugs. The explanation of general overflow and overwriting
attacks in chapter thirteen provides thorough descriptions, but relies
unnecessarily on coded C language references rather than broader
explanations, reducing the conceptual clarity. Chapter fourteen
reviews a combination of some of the techniques listed earlier in the
book as an integrated attack example.

The material could be helpful to security instructors, and fascinating
for those interested in the topic, but may not be presented in a
manner useful to network security administrators as direction for
protection of their resources. The book is demanding of the reader,
but it does do a better job than most of demonstrating the value of
knowing how to find weaknesses in order to build defence.

copyright Robert M. Slade, 2004 BKNTSCAS.RVW 20040511

--
======================

============= for back issues:
[Base URL] site http://victoria.tc.ca/techrev/
or mirror http://sun.soci.niu.edu/~rslade/
CISSP refs: [Base URL]mnbksccd.htm
Security Dict.: [Base URL]secgloss.htm
Book reviews: [Base URL]mnbk.htm
Review mailing list: send mail to techbooks-
or techbooks-



Rob Slade, doting grandpa of Ryan and Trevor
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Computer Security Information and What You Can Do To Keep Your SystemSafe! Ann.Anderson.group.com@gmail.com A+ Certification 0 12-06-2007 01:55 AM
Computer Security aldrich.chappel.com.use@gmail.com A+ Certification 0 11-27-2007 02:11 AM
TheDigitalReview: BABE SPECIAL EDITION - DVD REVIEW (User Review) Mike McGee DVD Video 0 12-04-2003 04:52 AM
TheDigitalReview: HUD - DVD REVIEW Mike McGee DVD Video 0 11-22-2003 10:34 AM
TheDigitalReview: THE JAMIE KENNEDY EXPERIMENT - COMPLETE FIRST SEASON - DVD REVIEW Mike McGee DVD Video 0 11-21-2003 12:07 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46