Practical Social Engineering: A Primer for the Ethical Hacker

Gray, Joe

  • 出版商: No Starch Press
  • 出版日期: 2022-06-14
  • 定價: $1,300
  • 售價: 8.0$1,040
  • 語言: 英文
  • 頁數: 230
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 171850098X
  • ISBN-13: 9781718500983
  • 相關分類: 駭客 Hack
  • 立即出貨 (庫存 < 4)

商品描述

An ethical introduction to social engineering, an attack technique that leverages psychology, deception, and publicly available information to breach the defenses of a human target in order to gain access to an asset. Social engineering is key to the effectiveness of any computer security professional.

Social engineering is the art of capitalizing on human psychology to compromise systems, not technical vulnerabilities. It's an effective method of attack because even the most advanced security detection teams can do little to defend against an employee clicking a malicious link or opening a file in an email and even less to what an employee may say on a phone call. This book will show you how to take advantage of these ethically sinister techniques so you can better understand what goes into these attacks as well as thwart attempts to gain access by cyber criminals and malicious actors who take advantage of human nature.

Author Joe Gray, an award-winning expert on the subject, shares his Social Engineering case studies, best practices, OSINT tools, and templates for both orchestrating (ethical) attacks and reporting them to companies so they can better protect themselves. His methods maximize influence and persuasion with creative techniques, like leveraging Python scripts, editing HTML files, and cloning a legitimate website to trick users out of their credentials. Once you've succeeded in harvesting information on your targets with advanced OSINT methods, Gray guides you through the process of using this information to perform real Social Engineering, then teaches you how to apply this knowledge to defend your own organization from these types of attacks.

You'll learn:
- How to use Open Source Intelligence tools (OSINT) like Recon-ng and whois
- Strategies for capturing a target's info from social media, and using it to guess their password
- Phishing techniques like spoofing, squatting, and standing up your own webserver to avoid detection
- How to collect metrics about the success of your attack and report them to clients
- Technical controls and awareness programs to help defend against social engineering

Fast-paced, hands-on and ethically focused, Practical Social Engineering is a book every pentester can put to use immediately.

商品描述(中文翻譯)

一本道德導向的社交工程入門書,介紹了一種利用心理學、欺騙和公開可得的資訊來攻擊人類目標以獲取資產的技術。社交工程對於任何電腦安全專業人員的效力至關重要。

社交工程是利用人類心理學來破壞系統,而不是技術漏洞的藝術。它是一種有效的攻擊方法,因為即使是最先進的安全檢測團隊也無法防止員工點擊惡意鏈接或在電子郵件中打開文件,更不用說員工在電話中可能說些什麼了。本書將向您展示如何利用這些道德上陰險的技術,以便更好地了解這些攻擊的內容,並阻止黑客和惡意行為者利用人類本性來獲取訪問權限。

作者Joe Gray是這個領域的獲獎專家,他分享了他的社交工程案例研究、最佳實踐、開放源代碼情報工具和模板,用於組織(道德)攻擊以及向公司報告,以便他們能夠更好地保護自己。他的方法最大程度地利用影響力和說服力,例如利用Python腳本、編輯HTML文件和克隆合法網站來欺騙用戶獲取他們的憑據。一旦您成功地使用先進的開放源代碼情報方法收集了目標的信息,Gray將指導您如何使用這些信息進行真實的社交工程,然後教您如何應用這些知識來保護自己的組織免受此類攻擊。

您將學到:
- 如何使用開放源代碼情報工具(OSINT),如Recon-ng和whois
- 從社交媒體中捕獲目標信息並使用它來猜測他們的密碼的策略
- 像偽造、搶注和建立自己的網頁伺服器以避免檢測的釣魚技術
- 如何收集有關攻擊成功的指標並向客戶報告
- 技術控制和意識計劃,以幫助防禦社交工程攻擊

這本節奏快、實踐性強且道德導向的《實用社交工程》是每個測試人員都可以立即使用的書籍。

作者簡介

Joe Gray is a veteran of the U.S. Navy. He is the Founder/Principal Instructor of The OSINTion, the Founder/Principal Investigator of Transparent Intelligence Services, and the inaugural winner of the DerbyCon Social Engineering CTF. A member of the Password Inspection Agency, he also won the TraceLabs OSINT Search Party at DEFCON 28, and recently authored the OSINT and OPSEC tools - DECEPTICON Bot and WikiLeaker.

作者簡介(中文翻譯)

Joe Gray是美國海軍的老兵。他是The OSINTion的創始人/主要講師,Transparent Intelligence Services的創始人/主要調查員,以及DerbyCon Social Engineering CTF的首屆獲獎者。作為Password Inspection Agency的成員,他還贏得了DEFCON 28的TraceLabs OSINT Search Party比賽,最近還撰寫了OSINT和OPSEC工具- DECEPTICON Bot和WikiLeaker。