<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Any books to give me overview about penetration testing in Career Discussions</title>
    <link>https://community.isc2.org/t5/Career-Discussions/Any-books-to-give-me-overview-about-penetration-testing/m-p/3786#M297</link>
    <description>&lt;P&gt;Loved NoStrach ever since they published the TCP/IP guide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another book to&lt;FONT face="arial,helvetica,sans-serif"&gt; conside&lt;/FONT&gt;r might be the '&lt;SPAN class="a-size-extra-large"&gt;CEH v9: Certified Ethical Hacker Version 9 Study Guide&lt;/SPAN&gt; &lt;SPAN class="a-size-large a-color-secondary a-text-normal"&gt;3rd Edition' &amp;nbsp;its been around a bit and 'Gray Hat Hacking - Forth Edition'.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2017 15:59:45 GMT</pubDate>
    <dc:creator>Early_Adopter</dc:creator>
    <dc:date>2017-11-20T15:59:45Z</dc:date>
    <item>
      <title>Any books to give me overview about penetration testing</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Any-books-to-give-me-overview-about-penetration-testing/m-p/3754#M290</link>
      <description>&lt;P&gt;I prefer reading then viewing a video. If there are any books I can read about penetration testing, ethical hacking I would be glad to take any recommendations. I have bought a course on networking and working on that. Also I have a laptop running Kali. I just wish to read something about hacking. I was thinking about, Hacking The Art of Exploitation, but I feel like it would be out of date.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Nov 2017 03:29:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Any-books-to-give-me-overview-about-penetration-testing/m-p/3754#M290</guid>
      <dc:creator>Chaotic</dc:creator>
      <dc:date>2017-11-19T03:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Any books to give me overview about penetration testing</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Any-books-to-give-me-overview-about-penetration-testing/m-p/3762#M293</link>
      <description>Try Georgia Weidman's "Penetration Testing" -- &lt;A href="https://www.nostarch.com/pentesting" target="_blank"&gt;https://www.nostarch.com/pentesting&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;That should give you a good overivew of process and procedure, some lab activities to play with, etc. (assuming you can get some Win7 or XP VMs stood up).&lt;BR /&gt;&lt;BR /&gt;The book you mention is pretty good, but exploit mitigations such as ASLR and DEP make some of the simple buffer overflow stuff out of date... although FreeBSD doesn't have ASLR or W^X, so most of your basic ABO-type buffer overflow stuff works there. They do have stack smashing protection (cookies, non-executable stack, etc) -- but ROP beats all that. But it sounds like you have a way to go before that becomes relevant though.</description>
      <pubDate>Sun, 19 Nov 2017 23:09:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Any-books-to-give-me-overview-about-penetration-testing/m-p/3762#M293</guid>
      <dc:creator>Badfilemagic</dc:creator>
      <dc:date>2017-11-19T23:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Any books to give me overview about penetration testing</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Any-books-to-give-me-overview-about-penetration-testing/m-p/3776#M295</link>
      <description>&lt;P&gt;The books, Art of Intrusion and the Art of Deception by Kevin Mitnick are good books to read. While not specifically about penetration testing computers they offer insight to "penetration testing" of people, which will help you understand the thought process you will need while doing pentests. Most successful areas of pentesting are the people (i.e. getting them to plug in a USB drive with your payload on it, getting them to click an infected link, allowing them to give you access to their computer, etc.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 13:02:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Any-books-to-give-me-overview-about-penetration-testing/m-p/3776#M295</guid>
      <dc:creator>CISOScott</dc:creator>
      <dc:date>2017-11-20T13:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: Any books to give me overview about penetration testing</title>
      <link>https://community.isc2.org/t5/Career-Discussions/Any-books-to-give-me-overview-about-penetration-testing/m-p/3786#M297</link>
      <description>&lt;P&gt;Loved NoStrach ever since they published the TCP/IP guide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another book to&lt;FONT face="arial,helvetica,sans-serif"&gt; conside&lt;/FONT&gt;r might be the '&lt;SPAN class="a-size-extra-large"&gt;CEH v9: Certified Ethical Hacker Version 9 Study Guide&lt;/SPAN&gt; &lt;SPAN class="a-size-large a-color-secondary a-text-normal"&gt;3rd Edition' &amp;nbsp;its been around a bit and 'Gray Hat Hacking - Forth Edition'.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 15:59:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Career-Discussions/Any-books-to-give-me-overview-about-penetration-testing/m-p/3786#M297</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-11-20T15:59:45Z</dc:date>
    </item>
  </channel>
</rss>

