Metasploit The Penetration Tester's Guide

Ranked #5,341 in Books, Poetry & Writing, #195,593 overall

Metasploit: The Penetration Tester's Guide book

Paperback: 328 pages
Publisher: No Starch Press; 1 edition (July 22, 2011)
David Kennedy, Jim O'Gorman, Devon Kearns, Mati Aharoni
Language: English
ISBN: 978-1593272883

This book teaches you how to hack using ready made tools and scripts. If you are a security professional or you intend to be a hacker in your spare time, this book is for you if you wish to know what is the Metasploit framework.

Metasploit is a powerful framework for executing Penetration Tests. The authors introduce a few phrases of Penetration Test in Chapter 1, then quickly turn to the main dish in Chapter 2 - Metasploit.

The main working environment of Metasploit is a text-based interface, called MSFConsole. The tasks under MSFConsole mainly are to setup target IP addresses to attack, the Exploit and Payload and trigger the attack.

Buy the book from Amazon

Loading

Metasploit: The Penetration Tester's Guide book review

When I ordered Metasploit: The Penetration Tester's Guide I thought that the book is the only printed reference of the Metasploit Unleashed online training and was planning to keep it for the reference only. When I finally received the book and began reading, I understood that the book is not only the reference material, it actually contains the core components of the penetration testing framework. Also, I noticed that the authors of the Metasploit Penetration Tester's Guide describe the art of the penetration testing using simple words and uncover sophisticated exploitation techniques throughout the book.

The first chapter describes the building blocks of the Penetration Testing Execution Standard. Pre-engagement interactions, intelligence gathering vulnerability analysis and exploitation are just some terms that fully covered by the authors and introduce the reader to the penetration testing.

The second chapter introduces the reader to the various tools within the Metasploit Framework that can be used to conduct a penetration testing. The third chapter shows the ways how the Metasploit can be used to conduct an intelligence gathering phase of a penetration test. The fourth chapter takes the reader through identifying vulnerabilities and using vulnerability scanning technologies.

The fifth chapter uncovers the Metasploit target exploitation techniques that can be used to successfully check a discovered vulnerability. The sixth chapter walks the security enthusiasts through the Meterpreter commands and explains how to run them without mistakes.

The seventh chapter focuses on the main principles of the antivirus evasion techniques that can be very interesting to the people who rely on the host based protection. The eight chapter describes how to exploit an operating system using client-side attacks. The chapter explains in details the mechanism of the Internet Explorer Aurora exploit along with the file format exploits.

The ninth chapter introduces the reader to the anatomy of the auxiliary modules inside of the Metasploit framework. The tenth chapter probably will be interesting to the penetration testers who specialize on social-engineering and practice different web penetration techniques such as java applets, client-side web exploits, user name and password harvesting, tabnabbing, web jacking etc. I have a deep feeling that Dave Kennedy was the main contributor to the paragraph ten which is fully dedicated to the Social Engineer toolkit.

Paragraph eleven goes through the Fast-Track exploitation framework and explains how to compromise a SQL server using different techniques. Also, the paragraph uncovers the way to exploit multiple clients using Fast-Track. Paragraph twelve walks the reader through the client exploitation using the Karmetasploit. The paragraph thirteen and fourteen explain how to build a module and create an exploit inside of the Metasploit exploitation framework.

In paragraph fifteen the readers will learn how to port different exploits to Metasploit Framework. The sixteenth paragraph fully uncovers Meterpreter scripting. It teaches readers how the Meterpreter scripts work and how to manipulate API and receive needed output. The seventeenth paragraph put all the pieces of the penetration testing puzzle together and delivers simulated penetration test using the time proven technique and obviously Metasploit Penetration Testing framework.

In conclusion, I just would like to say that every Information Security Professional has to read Metasploit: The penetration Tester's Guide book. The book helps to become familiar with the latest computer systems exploitation techniques, aids to recognize attempts to penetrate a security perimeter and explains how to merge together Metasploit Penetration Testing framework tools with the Penetration Testing Execution Standard to conduct a successful security assessment.


Get this book from Amazon.com

Metasploit Class Video

Loading

Rate this book

Metasploit: The Penetration Tester's Guide book

Let's hear from you your opinion of this book. Give us your honest rating from 1 to 5.

Loading poll. Please Wait...

More Security Books

Loading

Readers' Comments

Do you like this book?

  • sukkran Mar 14, 2012 @ 3:48 pm | delete
    very interesting read on metasploit , love your vid

by

GOT

I'm Andrew from Singapore. I created these sites for fun in my spare time. Favourite my site if you like it. Thanks for your support.

Feeling creative? Create a Lens!