A Bug Hunter's Diary: A Guided Tour Through the Wilds of Software Security (Paperback)
暫譯: 漏洞狩獵者的日記:軟體安全的探索之旅 (平裝本)
Tobias Klein
- 出版商: No Starch Press
- 出版日期: 2011-10-11
- 售價: $1,570
- 貴賓價: 9.5 折 $1,492
- 語言: 英文
- 頁數: 200
- 裝訂: Paperback
- ISBN: 1593273851
- ISBN-13: 9781593273859
-
相關分類:
資訊安全
已絕版
買這商品的人也買了...
-
$680$666 -
$360$281 -
$250$213 -
$580$493 -
$450$383 -
$580$493 -
$520$442 -
$420$357 -
$600$468 -
$680$537 -
$780$663 -
$680$530 -
$520$442 -
$580$458 -
$560$437 -
$490$323 -
$480$408 -
$750$593 -
$580$493 -
$580$383 -
$480$379 -
$320$272 -
$850$672 -
$680$578 -
$350$298
相關主題
商品描述
"Give a man an exploit and you make him a hacker for a day; teach a man to exploit bugs and you make him a hacker for a lifetime."
–Felix 'FX' Lindner
Seemingly simple bugs can have drastic consequences, allowing attackers to compromise systems, escalate local privileges, and otherwise wreak havoc on a system.
A Bug Hunter's Diary follows security expert Tobias Klein as he tracks down and exploits bugs in some of the world's most popular software, like Apple's iOS, the VLC media player, web browsers, and even the Mac OS X kernel. In this one-of-a-kind account, you'll see how the developers responsible for these flaws patched the bugs—or failed to respond at all. As you follow Klein on his journey, you'll gain deep technical knowledge and insight into how hackers approach difficult problems and experience the true joys (and frustrations) of bug hunting.
Along the way you'll learn how to:
- Use field-tested techniques to find bugs, like identifying and tracing user input data and reverse engineering
- Exploit vulnerabilities like NULL pointer dereferences, buffer overflows, and type conversion flaws
- Develop proof of concept code that verifies the security flaw
- Report bugs to vendors or third party brokers
A Bug Hunter's Diary is packed with real-world examples of vulnerable code and the custom programs used to find and test bugs. Whether you're hunting bugs for fun, for profit, or to make the world a safer place, you'll learn valuable new skills by looking over the shoulder of a professional bug hunter in action.
商品描述(中文翻譯)
「給一個人一個漏洞,他會成為一天的駭客;教一個人如何利用漏洞,他會成為一生的駭客。」
—Felix 'FX' Lindner
看似簡單的漏洞可能會帶來嚴重的後果,讓攻擊者能夠入侵系統、提升本地權限,並對系統造成破壞。
《漏洞獵人的日記》跟隨安全專家 Tobias Klein,追蹤並利用一些世界上最受歡迎的軟體中的漏洞,如 Apple 的 iOS、VLC 媒體播放器、網頁瀏覽器,甚至是 Mac OS X 核心。在這本獨特的書中,你將看到負責這些缺陷的開發者如何修補漏洞——或根本沒有回應。隨著你跟隨 Klein 的旅程,你將獲得深入的技術知識,了解駭客如何處理困難的問題,並體驗漏洞獵捕的真正樂趣(和挫折)。
在這個過程中,你將學會如何:
- 使用經過實地測試的技術來尋找漏洞,例如識別和追蹤用戶輸入數據以及逆向工程
- 利用漏洞,如 NULL 指標解引用、緩衝區溢出和類型轉換缺陷
- 開發驗證安全缺陷的概念驗證代碼
- 向供應商或第三方經紀人報告漏洞
《漏洞獵人的日記》充滿了現實世界中脆弱代碼的範例以及用於尋找和測試漏洞的自訂程式。無論你是為了樂趣、獲利,還是為了讓世界變得更安全,你都將通過觀察專業漏洞獵人的實際行動,學到寶貴的新技能。