A Hacker's Guide to Capture, Analysis, and Exploitation
James Forshaw

#Network
#Network_Protocols
#Attack
#security
#network_traffic
#bug_hunter
#hunter
🧠 این کتاب یک بررسی عمیق از امنیت network protocolهاست که از دید مهاجم نوشته شده؛ نوشتهی James Forshaw (یکی از برجستهترین محققان باگ و عضو تیم Google Project Zero). هدف کتاب اینه که بهت کمک کنه پروتکلهای شبکه رو تحلیل کنی، آسیبپذیریهاشون رو پیدا کنی، exploit کنی و در نهایت بهتر ازشون دفاع کنی.
⚙️ مسیر کتاب از مبانی شبکه شروع میشه؛ مثل نحوه capture کردن ترافیک و درک جریان ارتباطات. بعد کمکم وارد تحلیلهای پیشرفتهتر میشی: بررسی ساختار پروتکلها، تحلیل استاتیک و داینامیک، رمزنگاری، و مدلهای امنیتی پروتکلها.
🔍 در ادامه تمرکز کتاب میره روی دنیای واقعی حملات؛ یعنی جایی که با fuzzing، debugging، reverse engineering و حملات exhaustion میتونی رفتار پروتکلها رو دستکاری کنی و ضعفهاشون رو پیدا کنی.
🧰 در طول کتاب یاد میگیری چطور:
📦 پکتها رو capture، تغییر و replay کنی
🧪 ابزارهایی برای dissect کردن ترافیک و reverse engineering پروتکلها بسازی
💥 آسیبپذیریهایی مثل memory corruption، authentication bypass و denial of service رو پیدا و exploit کنی
🌐 از ابزارهایی مثل Wireshark استفاده کنی و حتی proxyهای اختصاصی برای manipulation ترافیک توسعه بدی
📚 فهرست مطالب
1. مبانی شبکه
2. کپچر کردن ترافیک اپلیکیشن
3. ساختار پروتکلهای شبکه
4. کپچر پیشرفته ترافیک اپلیکیشن
5. تحلیل از روی wire
6. مهندسی معکوس اپلیکیشن
7. پیادهسازی پروتکل شبکه
8. امنیت پروتکلهای شبکه
9. ریشههای آسیبپذیریها
10. پیدا کردن و exploit کردن آسیبپذیریهای امنیتی
📝 نقد و بررسی
💬 «یکی از بهترین منابع مرجع در این حوزه، اگر نگیم بهترین.»
— Andrew Swoboda
💬 «بسیار خوانا و قابل فهم؛ حتی برای توسعهدهندههایی که صرفاً به امنیت علاقه دارن هم ارزشمند است.»
— I Programmer
💬 «یک راهنمای خوب برای pentesterها و developerهایی که میخوان بفهمن چه اشتباهاتی نباید انجام بدن.»
— Sven Dietrich
💬 «مختصر، دقیق و قابل دنبال کردن.»
— Nicky Lim
👨💻 درباره نویسنده
👨💻 James Forshaw یک محقق امنیتی برجسته در تیم Google Project Zero است. او خالق ابزار تحلیل پروتکل شبکه Canape بوده و به خاطر کشف آسیبپذیریهای پیچیده در ویندوز، یکی از بالاترین جایزههای bug bounty مایکروسافت (100,000 دلار) را دریافت کرده است. همچنین در کنفرانسهای مهمی مثل BlackHat، CanSecWest و Chaos Computer Congress به ارائه تحقیقات خود پرداخته است.
Attacking Network Protocols is a deep dive into network protocol security from James Forshaw, one of the world’s leading bug hunters. This comprehensive guide looks at networking from an attacker’s perspective to help you discover, exploit, and ultimately protect vulnerabilities.
You’ll start with a rundown of networking basics and protocol traffic capture before moving on to static and dynamic protocol analysis, common protocol structures, cryptography, and protocol security. Then you’ll turn your focus to finding and exploiting vulnerabilities, with an overview of common bug classes, fuzzing, debugging, and exhaustion attacks.
Learn how to:
Attacking Network Protocols is a must-have for any penetration tester, bug hunter, or developer looking to understand and discover network vulnerabilities.
Table of Contents
Chapter 1: The Basics of Networking
Chapter 2: Capturing Application Traffic
Chapter 3: Network Protocol Structures
Chapter 4: Advanced Application Traffic Capture
Chapter 5: Analysis from the Wire
Chapter 6: Application Reverse Engineering
Chapter 7: Implementing the Network Protocol
Chapter 8: Network Protocol Security
Chapter 9: The Root Causes of Vulnerabilities
Chapter 10: Finding and Exploiting Security Vulnerabilities
Review
"One of the best, if not the best, reference books on this material."
—Andrew Swoboda, Tripwire
“Very readable and accessible...worth reading even if your only interest in network security is as an applications developer.”
—I Programmer
"Whether you're a pen tester, fuzzer, or a serene developer seeking understanding of what not to do, this book is an excellent beginner's guide."
—Sven Dietrich, IEEE Cipher, Cipher Book Review
"Concise and easy to follow."
—Nicky Lim, Goodreads Reviewer
About the Author
James Forshaw is a renowned computer security researcher at Google Project Zero and the creator of the network protocol analysis tool Canape. His discovery of complex design issues in Microsoft Windows earned him the top bug bounty of $100,000 and placed him as the #1 researcher on the published list from Microsoft Security Response Center (MSRC). He’s been invited to present his novel security research at global security conferences such as BlackHat, CanSecWest, and Chaos Computer Congress.









