Friday, September 11, 2009

Pen Testing Resources

I have decided to start tracking tools I find useful. To try and conform with the basic phases outlined for the CEH:


  • Footprinting
  • Scanning
  • Enumeration
  • Penetration
  • Denial of service
  • Escalation of Privilege
  • Obscuring (Covering tracks)
  • Backdoors

The following list will have two parts: 1) Tools and 2) Books

Tools

Books

  • Advanced Windows Debugging
  • Assembly Language for Intel-Based Computers
  • Assembly Language Step-by-step: Programming with DOS and Linux
  • BIOS Disassembly Ninjutsu Uncovered
  • Buffer Overflow Attacks: Detect, Exploit, Prevent
  • Build Your Own Security Lab: A Field Guide for Network Testing
  • Chained Exploits: Advanced Hacking Attacks from Start to Finish
  • Counter Hack Reloaded: A Step-by-Step Guide to Computer Attacks and Effective Defenses
  • Crackproof Your Software: Protect Your Software Against Crackers
  • Developing Drivers with the Windows Driver Foundation
  • Disassembling Code: IDA Pro and SoftICE
  • Exploiting Software: How to Break Code
  • File System Forensic Analysis
  • Fuzzing for Software Security Testing and Quality Assurance
  • Fuzzing: Brute Force Vulnerability Discovery
  • Hacker Disassembling Uncovered: Powerful Techniques To Safeguard Your Programming
  • Hacking for Dummies - Kevin McClure
  • Hacking Exposed Computer Forensics: Computer Forensics Secrets & Solutions
  • Hacking Windows Server 2003 Exposed - Joel Scambray, Stuart McClure
  • How Debuggers Work: Algorithms, Data Structures, and Architecture
  • Identifying Malicious Code Through Reverse Engineering
  • Internet Forensics
  • Know Your Enemy: Learning about Security Threats
  • Linkers and Loaders
  • Malware Forensics: Investigating and Analyzing Malicious Code
  • Malware: Fighting Malicious Code
  • Mastering Windows Network Forensics and Investigation
  • Memory Dump Analysis Anthology
  • Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research
  • Microsoft Windows Internals (4th Edition): Microsoft Windows Server 2003, Windows XP, and Windows 2000
  • Professional Assembly Language
  • Professional Pen Testing for Web Applications - Andres Andreu
  • Professional Rootkits
  • Reverse Engineering Code with IDA Pro
  • Reversing: Secrets of Reverse Engineering
  • Rootkits: Subverting the Windows Kernel
  • Secure Programming with Static Analysis
  • Security Data Visualization: Graphical Techniques for Network Analysis
  • Security Power Tools
  • Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks
  • Sockets, Shellcode, Porting, and Coding: Reverse Engineering Exploits and Tool Coding for Security Professionals
  • The Art of Computer Virus Research and Defense
  • The IDA Pro Book: The Unofficial Guide to the World's Most Popular Disassembler
  • The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System
  • The Shellcoder's Handbook: Discovering and Exploiting Security Holes
  • Windows Forensic Analysis DVD Toolkit, Second Edition
  • Writing Security Tools and Exploits
  • XSS Attacks: Cross Site Scripting Exploits and Defense

Links

http://yehg.net/hwd/?id=h

0 comments:

Post a Comment