Re: REVIEW: "Network Security for Dummies", Chey Cobb

From: jealous xmp (jealousxmp_at_aol.commonplace)
Date: 03/15/04


Date: 15 Mar 2004 16:46:09 GMT

Nice review. Some of the Linux for Dummies are pretty decent, esp Slackware
one. I hate the Windows ones, the old ones were written by Rathbone and simply
terrible.

Here's some I would recommend:

Hack Proofing Your Network:
This is edited / written by Ryan Russell and includes contributions from
Guninski, RFP, and Hoglund. It is very good, but assumes some knowledge of
basic networking and OS. Unfortunately it's $50 list and that's a lot for a
book of this size. I see the PDF version at Amazon for $35. The good thing
about this book is that it covers some cool stuff like buffer overflows. Some
books seem to spend pages on nmap switches or SYN/ACK handshake diagrams.
However, Hack Proofing contains stuff that has more substance.

TCP/IP Illustrated Volume I:
I haven't finished this, but it's the one of the best overviews. It's $60
which is reasonable given it's size. I ran across a cheap introduction "TCP/IP
in 24 Hours" which covers the basic protocols. Another which looks good is
"TCP/IP Bible" but it's $50 so why not get Illustrated instead.

Hacking Exposed / Counter Hack / Anti Hacker Toolkit / etc.
I've lumped these together because there are a lot of similar guides out there.
 They all cover similar material like nmap, sniffers, and trojans. I wouldn't
buy more than one of these type books unless it contains unique material.

Art of Deception by Mitnick
This is a very good book on social engineering. Very light read, and
entertaining. IMHO this contains some real world techniques. For example,
some of the material in the book is almost exactly how a certain 3 letter ISP
was compromised in numerous attacks in 2000 and 2002, which were covered by
media. It's great to be an expert on firewalling, and OS security, but
attackers often tunnel right past them by exploiting employees instead.

A couple of books I'm thinking of getting are "Network Security Assessment" by
so1o and "Security Warrior" (another O'reilly publication).

Michael



Relevant Pages

  • RE: [Full-Disclosure] Tons of help for You, the Truth is Out The re!
    ... This is a good basic first step and in every 1,000 mile ... Good books are out there on Firewalls, AV, IDS, TCP/IP and network security. ...
    (Full-Disclosure)
  • RE: TCP/IP skills
    ... knowledge of the network layer are needed for specific job-duties. ... security specialists as normally falling into one of the following ... non-technical controls than on anything having to do with TCP/IP ... Network skills ...
    (Pen-Test)
  • Re: NetBEUI and security
    ... NetBEUI only serves as a replacement for NetBIOS over TCP/IP traffic. ... > I'm considering using NetBEUI on a small network with internet access, ... > My motivation for this is simply another layer of security, ...
    (comp.security.firewalls)
  • SecurityFocus Microsoft Newsletter #50
    ... Subject: SecurityFocus Microsoft Newsletter #50 ... Specialist in Microsoft's Security Services Partner Program, ... Network Monitoring for Intrusion Detection ... Relevant URL: ...
    (Focus-Microsoft)
  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.backoffice.smallbiz2000)