LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Security Week: June 29th, 2009
Linux Advisory Watch: June 26th, 2009
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Review: Hacking Exposed Linux, Third Edition Print E-mail
User Rating:      How can I rate this item?
Posted by Bill Keys   
Article Index
Review: Hacking Exposed Linux, Third Edition
Page 2
Book Reviews “Hacking Exposed Linux” by ISECOM (Institute for Security and Open Methodologies) is a guide to help you secure your Linux environment. This book does not only help improve your security it looks at why you should. It does this by showing examples of real attacks and rates the importance of protecting yourself from being a victim of each type of attack.


Date: August 2008

Vitals:

Title:
Author: ISECOM (Institute for Security and Open Methodologies)
Pages: 613
ISBN-10: 978-0-07-226257-5
Publisher: McGraw Hill
Edition: 3nd Edition
Purchase: Hacking Linux Exposed



Bill Keys


Overview

“Hacking Exposed Linux” by ISECOM (Institute for Security and Open Methodologies) is a guide to help you secure your Linux environment. This book does not only help improve your security it looks at why you should. It does this by showing examples of real attacks and rates the importance of protecting yourself from being a victim of each type of attack.

The reader will gain a better understanding of the types of attacks that are out there, and learn new ways to protect their system. Those who are thinking about using this book should have a Linux machine that needs to be secured. However, anyone that is interested in computer security will learn more about the different types of threats which are there. Now that you have a introduction on what this book is about I will look deeper into each part of it.

Review Summary

Part 1 titled “Security and Controls” starts with a section that outlines the building blocks of computer security; visibility, access, and trust. Then it looks at authentication, indemnification, subjugation, continuity, and resilience. The author goes into detail how indemnification is controlling the value of resources through law or insurance to reclaim the real value of loss. I also goes into detail of subjugation which is local control over the protection and restrictions of interactions by the asset responsible. Then the author discusses that continuity is a control of assuring service is still available after a disaster and to assure that a service fails securely. Those five interactive controls are important parts to security and are discussed in detail in this part of the book. Then it goes into detail about process controls to improve the user's security assets on their system.

Part 2 is titled “Hacking the System” and starts with a section on local access control. It outlines some configuration changes and add-ons that can help physical security. It looks at examples of physical attacks which attackers can use. This part answers the question “how can I limit the damage that can be caused by this type of attack?” In the next section of this book the author talks about data network security. It looks at strategies which users can implement to increase the security of their network. The main idea in this section is to add security from the start by setting up least access. But this part also answers the question “what should I do if I get attacked?” It shows the user some forensic techniques any Linux user can use. How to recover from an attack quickly is also covered. The real strength of this section is showing the user a variation of different types of attacks for example, software vulnerability exploitation and password login attacks.

Part 3 is titled “Hacking the Users”, which is the one that I found most interesting. It looks at three services that are vulnerable to attack; web application, Email and DNS. First this part looks at threats to web applications. It goes into detail about the different types of threats, for example, insufficient data validation and how to help prevent them. Also it looks at some new security risks like Web 2.0 threats particularly AJAX attacks. The author makes a good point that web application security is more than just border security like firewalls. It's also important to protect your application from man-in-the-middle attacks. I found the man-in-the-middle examples to be a good way to learn why users need to protect themselves and how to prevent this type of attack. The next service looked at in this part is Email, which is one of the most important services to make secure. With virus, trojans, phishing and other attacks which all can be quickly spread via Email, it's a service that the author goes into detail about the threats and how to help prevent them. This section stresses the importance of implementing controls to this service. The author states threats to Email which are common to all services but also goes into detail on how to prevent them with Email specific security techniques like graylists. Since most email is sent in clear text this section sheds light on encryption implementation, for example, OpenPGP. The last service that the author looks at is the name service or DNS. This section stresses the importance of DNS to the Internet as a whole and the types of attack that are out there which are a threat to this service. Also the author looks at attacks against users of DNS. One security idea that I found interesting was DNS and encryption. We all know that encryption is used to protect important data but I did not know that it can be used in DNS too. With the increasing threat to the DNS service this section does a good jobs at explaining what that threat is and the importance to secure it.

The last part of this book is called “Care and Maintenance” which looks at C code security and Linux kernel security. If you are interested in kernel security tweaks, this is the section for you. It starts at the bottom with ways to improve the security of C code. Programmers know that C code needs special attention when it comes to making it secure. The author shows the user how make their C programs more secure. One way this section explains how to secure ones code is by using code analysis tools. The next section looks at security in the Linux kernel. The author does not go into a lot of detail on the security features of the kernel but, does give the reader enough information to know what each features role is.

In conclusion, if you or anyone you know is interested in Linux security and the threat of attack then “Hacking Exposed Linux, Third Edition” is a valuable resource to read and add to your Linux book collection. You will find in this book many examples of computer attacks and ways to improves ones own Linux security.

Comments
http://www.wow-powerleveling-wow.com/Written by wow gold on 2008-10-11 05:35:32
good!wow gold
http://www.mmorpgvip.comWritten by wow gold on 2009-03-09 02:14:32
http://www.faysale.com  
http://www.mmorpgvip.com 
RE:wow goldWritten by wow gold on 2009-04-08 05:05:11
http://www.thewowgold.net  
http://www.thplay.com  
http://www.gamesalevip.com 
http://www.nikemine.com 
http://www.watchessell.com 
ogdealWritten by rs on 2009-04-26 15:35:55
Sell MMORPG Gold And Money to us to get real money! 
Dear player, 
OGDEAL is buying mmorpg virtual currency. We will offer high price to buy your game gold.You can sell WOW gold, sell warhammer gold, sell eve online isk: www.eve-online-isk.com , sell silkroad gold, sell maple story mesos, sell lotro gold, sell lotro europe gold, sell aoc gold, sell Lineage 2 adena, sell EverQuest 2 platinum, sell FFXI gil, sell SWG credits, sell gaia gold, sell 2moons dil, sell cabal online alz, sell kalonline geons to : www.ogdeal.com . 
Any questions please Contact our site’s live support chat or MSN: ogdeal@hotmail.com , AIM: ogdeal .Thanks ! 
mrWritten by vivek on 2009-05-14 06:16:07
really wonderful review. i will consider buying this book.
fake designer handbagsWritten by fake designer handbags on 2009-05-26 03:35:37
[URL=http://www.fake-designer.com]fake designer handbags[/URL] 
[URL=http://www.fake-designer.com]replica louis vuitton handbags[/URL] 
[URL=http://www.fake-designer.com]designer replica handbags[/URL] 
[URL=http://www.fake-designer.com]replica handbags[/URL] 
[URL=http://www.fake-designer.com]replica designer handbags[/URL] 
[URL=http://www.fake-designer.com]replica designer bags[/URL]
fake designer handbagsWritten by fake designer handbags on 2009-05-26 03:36:26
fake designer handbags 
replica louis vuitton handbags 
fake bags 
cheap handbags 
replica handbags 
fake designer handbagsWritten by fake designer handbags on 2009-05-26 03:37:10
[a/]http://www.fake-designer.com[a]fake designer handbags[/a] 
[a/]http://www.fake-designer.com[a]replica louis vuitton handbags[/a] 
[a/]http://www.fake-designer.com[a]fake bags[/a] 
[a/]http://www.fake-designer.com[a]fake designer handbags[/a] 
[a/]http://www.fake-designer.com[a]cheap handbags[/a] 
[a/]http://www.fake-designer.com[a]replica handbags[/a]
cheap wow power levelingWritten by wow power leveling on 2009-05-26 09:16:21
www.wow-power-lvl.com is the professional website for Wow power leveling. We have been in wow power leveling service for over 3  
 
years and made so many customers be our friends. Professional wow power leveling cheap , fast, and secure service. We power level  
 
your character according to your special requirements with no extra charges or hidden fees. Help you get your favor is our goal.  
 
And we are so happy that customers trust us because we upgrade your toons by experience levelers only. Enjoy World of Warcraft,  
 
Enjoy our service of World of Warcraft power leveling.  
We provide a cheap WoW Power Leveling service for any level to level 80 (wow power leveling 1 80). The price of WoW Power  
 
leveling for the two new races is as the same as the original races. We are sure that you will get a satisfaction with our  
 
outstanding World Of Warcraft 12 Power Leveling service.  
http://www.wow-power-lvl.com 
http://www.wow-power-lvl.com 
http://www.cheap-powerleveling.com 
http://www.cheap-powerleveling.com 
http://www.cheap-powerleveling.com/wow-honor-powerleveling.html 
http://www.wow-power-lvl.com/Warhammer-Online-Powerleveling-US.html 
http://www.wow-power-lvl.com/WoW-US-PVP-Honor-Power-Leveling.html 
http://www.wow-power-lvl.com/WoW-Arena-Powerleveling.html 
http://www.cheap-powerleveling.com/wow-arena-powerleveling.html 
http://www.wow-power-lvl.com/World-of-Warcraft-Powerleveling-US.html 
http://www.cheap-powerleveling.com/Buy-WOW-Gold.html 
 
wow honor points 
buy honor points 
WoW Honor Powerleveling 
WoW Professions Powerleveling 
Professions Powerleveling 
Warhammer Online Powerleveling 
Warhammer Renown Powerleveling 
Warhammer Renown Rank Powerleveling 
EQ2 Powerleveling 
Ever Quest 2 Powerleveling 
wow T8 PowerLeveling 
wow T8 PowerLeveling 
Requiem Online Powerleveling 
Requiem Online Powerleveling 
Cabal Online Powerleveling 
Star Wars Galaxies Powerleveling 
Silkroad Powerleveling 
Silkroad Powerleveling 
world of warcraft powerleveling 
Honor Power Leveling 
Honor Powerleveling 
cheap wow powerleveling 
World of Warcraft Gold 
wow gold 
cheao and fast runescape gold form www.rWritten by www.rsgolddeal.com on 2009-06-04 01:59:42
Why Buy Runescape Money & Runescape Gold ?  
 
 
Can you bear with yourself being called noobie in RuneScape? 
 
Are your looking for unofficial RuneScape cheats or RuneScape guides in order to get RuneScape gold faster?  
 
Can you make millions of RuneScape Gold in a day? 
 
Even if you know how to farm rs money , you have to prepare enough Runescape Gold first to buy RuneScape Items, to level your Runescape characters. 
 
Then, why NOT buying RuneScape gold From us? 
 
http://www.runescape2coin.com is offering cheapest RuneScape gold or Buy RuneScape to our clients. 
 
We update Price every single day to be the lowest in market. 
 
Nowhere else can you find such a great price and service and Fast Delivery Runescape gold. 
 
We understand what our buyers need.  
 
We have available stock of RuneScape gold , so we can do a really instant delivery in game. 
 
And we have RuneScape items, RS item, RuneScape PowerLeveling, RuneScape account, Runescape Questhelp, Buy RuneScape, RuneScape money and other services 1m Free Gold on rs.  
 
Because We are 24 X 7 Online, if you have any questions with buying RuneScape Gold , you can contact us anytime and we will try our best to help you. 
 
No business too small, no problem too big.  
 
 
Important Of Runescape Gold & Runescape Coin^-^ 
 
Buying runescape money is a method to save time. Many runescape pkers, clan leaders etc who understand the fun of runescape the most always buy runescape money from us. Spending time grinding for levels or equipments is realy opposite to the spirit of runescape playing. And buying runescape gold is somehow helping the game economy. It also increases consumption which definitely help developping the whole in game industry. 
 
Are you struggling in runescape for runescape gold? Have you ever got hacked due to using runescape hacks or runescape bots autominers? Can you make millions of runescape money in days? Even if you know how to farm runescape money, you have to prepare enough runescape gp first to buy runescape gold, to level your runescape characters.  
 
Then why not buy runescape money from us? In runescape it's the quickest way for you to get rich. We are online 24 hours a day ready to power up your runescape accounts with cheap runescape money, you are at the same time extremely powered in runescape, So buying runescape money means you are playing as a higher level gamer class as well. Have as much fun as you can!  
 
 
 
 
Fast runescape money From http://www.rsgolddeal.com 
cheap runescape gold From http://www.runescape2coin.com 
runescape 2 gold From http://runescape2-gold-money-coin.blogspot.com 
runescape powerleveling From http://www.runescape2coin.com/powerleveling.html 
runescape power leveling From http://www.rsgolddeal.com/cheap-runescape-powerleveling.html 
buy runescape accounts From http://www.runescape2coin.com/accounts.html 
buy runescape equipment From http://www.runescape2coin.com/accounts.html 
runescape money maker free downloads From http://runescape2coin.wordpress.com 
runescape money hacking program From http://www.rsgolddeal.com 
buy runescape money by phoneFrom http://www.runescape2coin.com 
 
 
 
 
 
 
http://www.rsgolddeal.com 
http://www.runescape2coin.com 
http://runescape2-gold-money-coin.blogspot.com 
http://www.runescape2coin.com/powerleveling.html 
http://runescape2coin.wordpress.com
wow goldWritten by wow gold on 2009-06-04 04:03:13
http://www.uswotlk.com 
http://www.pvpvip.com 
http://www.igcome.com 



 
< Prev   Next >
    
Partner:

 

Latest Features
Review: Googling Security: How Much Does Google Know About You
A Secure Nagios Server
Never Installed a Firewall on Ubuntu? Try Firestarter
Review: Hacking Exposed Linux, Third Edition
Security Features of Firefox 3.0
Review: The Book of Wireless
April 2008 Open Source Tool of the Month: sudo
Yesterday's Edition

QuickLinks: Comunity , HOWTOs , Blogs , Features , Book Reviews , Networking ,
  Security Projects ,   Latest News ,  Newsletters ,  SELinux ,  Privacy ,  Home,
 Hardening ,   About Us,   Advertise,   Legal Notice,   RSS,   Guardian Digital
  Home Security Systems, Surveillance Cameras

(c)Copyright 2009 Guardian Digital, Inc. All rights reserved.