Penetration Testing mailing list archives

Re: Network Security Assessment 2nd Edition


From: Chris McNab <chris.mcnab () trustmatta com>
Date: Tue, 20 Nov 2007 21:22:29 +0000

Hi Pete,

Thanks for this -- no need to worry however!! I was notified by Evgeny and Cesar that Argeniss had sold their 0day pack to GLEG after I had written most of the book. However, the two packs are still separate products and haven't yet been merged, so I deal with them as separate packs, with a note that GLEG should be contacted to purchase both of the packs

Chris


Pete Finnigan wrote:
Hey Chris,

Hate to tell you this but one of the blow items is out of date already. Argeniss sold their 0-day exploit pack to Gleg some time ago.

cheers

Pete

Chris McNab wrote:
Hi,

A shameless plug, but I wanted you to all be aware that I finally finished the 2nd edition of my book, which was published last week by O'Reilly. About half of the book content is browsable online at:

http://books.google.com/books?id=zKhCEYRGFuYC&printsec=frontcover

New features of the 2nd edition include:

- Exploitation framework support, including IMPACT, CANVAS, and MSF
- 0day exploit pack support (GLEG and Argeniss in particular)
- A Nessus chapter
- A web application testing chapter
- A completely re-written VPN chapter (by Roy Hills)
- Full CVE compatibility; all of the bugs in the book have CVE references (which involved around 20 new CVE's being created also)

It is designed and written as a desktop reference for network-based IP assessment, covering all the latest bugs, and removing a lot of old, obsolete material that was present in the first edition (such as bugs in IIS 4.0, etc.)

I'd like to keep the book as accurate as possible, so if there are any errors that you want to report, please submit them at http://www.oreilly.com/catalog/9780596510305/errata/

Many thanks,

Chris




--
Chris McNab
Technical Director

Matta Consulting Limited
Falstaff House
34 Bardolph Road
Richmond upon Thames
TW9 2LH

T: 08700 77 11 00
W: www.trustmatta.com

The information contained in this email is intended only for the person(s) to whom it is addressed and may contain confidential or privileged material or information that is exempt from disclosure under applicable law. Information and attachments may be used only for the purpose for which they are sent, and copying, disclosure or distribution of any information contained herein is strictly prohibited.

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: