5 ms·
Do you have any comments on it (or is it still a preorder)? I see we can't even have a peek on the table of contents. By the way, HN, what would be your advise
by plesn 17y ago
Do you have any comments on it (or is it still a preorder)? I see we can't even have a peek on the table of contents.
By the way, HN, what would be your advise for a good technical book on "cracking". I mean, not a collection of ad-hoc recepies, but some generic knowledge, however something where you don't hesitate to open your gdb/wireshark/etc.. : for example I remember I enjoyed reading http://insecure.org/stf/smashstack.html http://insecure.org/stf/smashstack.html a long time ago.
- bretthoerner 17y agoYou can peek on Amazon, and it's $26 pre-order (available on 23rd, it seems?). http://www.amazon.com/Gray-Hat-Python-Programming-Engineers/dp/1593271921/ref=reg_hu-wl_item-added http://www.amazon.com/Gray-Hat-Python-Programming-Engineers/...
- j2d2 17y agoI would get under the hood of metasploit and see where that takes you. Or read the old phracks. Even four years ago phrack was talking about inserting kernel modules without root perms. Neat stuff!
- streblo 17y agoI'm taking a course right now in operating systems, a big section of which is on security. All of our required readings for this section have come from metasploit/phrack/insecure.
- tptacek 17y agoPermit me to geek out for a moment and point out that this trick goes back more than 10 years: http://bit.ly/1kQu07 http://bit.ly/1kQu07 What's more, in 1996: * amodload worked under the (then) closed-sourced SunOS * it was written in SPARC assembly * it shimmed its own kernel module loader through devkmem It's basically the first real Unix virus. What's depressing is that almost everything it did was pedestrian for virus authors 5 years prior to it.
- j2d2 17y agoGreat link! Thanks!
- tptacek 17y agoThe industry standard answer to that question is "The Shellcoders Handbook", though I think you'd be better off with "The Art Of Software Security Assessment" and a lot of man pages.
- yan 17y ago+1 for TAOSSA. Fantastic reference.
- utnick 17y agoShellcoders Handbook Was one of the textbooks in my cs security undergrad course. Good overview, very technical, gdb will come into play.