0
نام کتاب
The Database Hacker's Handbook

Defending Database Servers

David Litchfield, Chris Anley, John Heasman, and Bill Grindlay

Print Length529 Pages
PublisherWiley
Edition1
LanguageEnglish
Year2005
ISBN9780764578014
1K
A553
انتخاب نوع چاپ:
جلد سخت
1,366,000ت
0
جلد نرم
1,466,000ت(2 جلدی)
0
طلق پاپکو و فنر
1,506,000ت(2 جلدی)
0
مجموع:
0تومان
کیفیت متن:اورجینال انتشارات
قطع:B5
رنگ صفحات:سیاه و سفید
پشتیبانی در روزهای تعطیل!
ارسال به سراسر کشور

#Database

#Defending

#Hacker

#Handbook

#MySQL

#Sybase_ASE

#PostgreSQL

#IBM

#DB2

#SQL

#Shellcoder

#attacker

توضیحات

🧠 پایگاه‌های داده؛ هسته عصبی اقتصاد


🧠 پایگاه‌های داده در واقع مرکز عصبی اقتصاد ما هستند. هر بخش از اطلاعات شخصی شما در آن‌ها ذخیره می‌شود—سوابق پزشکی، حساب‌های بانکی، سابقه شغلی، حقوق بازنشستگی، ثبت خودرو، حتی نمره‌های فرزندان شما و این‌که چه مواد غذایی خرید می‌کنید. حمله به پایگاه‌های داده می‌تواند به‌شدت فلج‌کننده و در عین حال بی‌وقفه باشد.


🔐 هدف این کتاب و اهمیت آن

🔐 این کتاب به‌عنوان یک ادامه ضروری برای The Shellcoder's Handbook، توسط چهار نفر از برترین متخصصان امنیت دنیا نوشته شده و به شما یاد می‌دهد چگونه به هفت مورد از محبوب‌ترین سرورهای پایگاه داده نفوذ کنید و از آن‌ها دفاع کنید. شما یاد می‌گیرید چگونه آسیب‌پذیری‌ها را شناسایی کنید، حملات چگونه اجرا می‌شوند و چطور جلوی این تخریب را بگیرید. مهاجمان این دانش را دارند؛ شما هم باید داشته باشید.


🛡️ آنچه یاد می‌گیرید

🛡️ شناسایی و رفع حفره‌های جدید در Oracle و Microsoft SQL Server

🛡️ یادگیری بهترین روش‌های دفاع برای سرورهای IBM DB2، PostgreSQL، Sybase ASE و MySQL

🛡️ بررسی اینکه چگونه Buffer Overflow، افزایش سطح دسترسی از طریق SQL، سوءاستفاده از Stored Procedure یا Trigger و SQL Injection امکان نفوذ را فراهم می‌کنند

🛡️ شناخت آسیب‌پذیری‌های خاص هر دیتابیس

🛡️ فهمیدن اینکه مهاجمان از قبل چه چیزهایی را می‌دانند


📚 فهرست مطالب

  1. چرا باید به امنیت پایگاه داده اهمیت بدهیم؟
  2. معماری Oracle
  3. حمله به Oracle
  4. Oracle: حرکت عمیق‌تر در شبکه
  5. امن‌سازی Oracle
  6. پایگاه داده IBM DB2 Universal Database
  7. DB2: کشف، حمله و دفاع
  8. حمله به DB2
  9. امن‌سازی DB2
  10. معماری Informix
  11. Informix: کشف، حمله و دفاع
  12. امن‌سازی Informix
  13. معماری Sybase
  14. Sybase: کشف، حمله و دفاع
  15. Sybase: حرکت عمیق‌تر در شبکه
  16. امن‌سازی Sybase
  17. معماری MySQL
  18. MySQL: کشف، حمله و دفاع
  19. MySQL: حرکت عمیق‌تر در شبکه
  20. امن‌سازی MySQL
  21. معماری Microsoft SQL Server
  22. SQL Server: بهره‌برداری، حمله و دفاع
  23. امن‌سازی SQL Server
  24. معماری PostgreSQL
  25. PostgreSQL: کشف و حمله
  26. امن‌سازی PostgreSQL


👨‍💻 درباره نویسنده

👨‍💻 David Litchfield در زمینه جست‌وجوی تهدیدهای جدید برای سیستم‌های پایگاه داده و اپلیکیشن‌های وب تخصص دارد و رکورد غیررسمی جهانی در کشف آسیب‌پذیری‌های مهم را در اختیار دارد. او برای سازمان‌های امنیتی دولتی بریتانیا و آمریکا سخنرانی کرده و از سخنرانان ثابت Black Hat Security Briefings است. او یکی از نویسندگان The Shellcoder’s Handbook، SQL Server Security و Special Ops است و در کنار آن مدیرعامل شرکت Next Generation Security Software Ltd نیز هست.

👨‍💻 Chris Anley یکی از نویسندگان The Shellcoder’s Handbook است که یک کتاب پرفروش در حوزه پژوهش آسیب‌پذیری‌های امنیتی محسوب می‌شود. او مقالات و گزارش‌های امنیتی متعددی درباره سیستم‌هایی مانند SQL Server، Sybase، MySQL، DB2 و Oracle منتشر کرده است.

👨‍💻 John Heasman مشاور ارشد امنیت در شرکت NGS Software است. او پژوهشگر بسیار فعالی در حوزه امنیت است و گزارش‌های متعددی درباره محصولات مهمی مانند Microsoft Windows، RealPlayer، Apple QuickTime و PostgreSQL منتشر کرده است.

👨‍💻 Bill Grindlay مهندس نرم‌افزار و مشاور ارشد امنیت در NGS Software است. او روی ابزارهای اسکن آسیب‌پذیری مانند Typhon III و خانواده NGSSQuirreL کار کرده و یکی از نویسندگان کتاب راهنمای مدیران پایگاه داده یعنی SQL Server Security است.


🏢 درباره Next Generation Security Software Ltd

🏢 شرکت Next Generation Security Software Ltd یک شرکت مستقر در بریتانیاست که مجموعه‌ای از ابزارهای ارزیابی آسیب‌پذیری سرورهای پایگاه داده را تحت خانواده NGSSQuirreL توسعه می‌دهد. این شرکت در سال ۲۰۰۱ تأسیس شده و بخش مشاوره امنیتی آن یکی از بزرگ‌ترین تیم‌های تخصصی امنیت در اروپا محسوب می‌شود. هر چهار نویسنده این کتاب در این شرکت فعالیت دارند.


Databases are the nerve center of our economy. Every piece of your personal information is stored there-medical records, bank accounts, employment history, pensions, car registrations, even your children's grades and what groceries you buy. Database attacks are potentially crippling-and relentless.


In this essential follow-up to The Shellcoder's Handbook, four of the world's top security experts teach you to break into and defend the seven most popular database servers. You'll learn how to identify vulnerabilities, how attacks are carried out, and how to stop the carnage. The bad guys already know all this. You need to know it too.


  • Identify and plug the new holes in Oracle and Microsoft(r) SQL Server
  • Learn the best defenses for IBM's DB2(r), PostgreSQL, Sybase ASE, and MySQL(r) servers
  • Discover how buffer overflow exploitation, privilege escalation through SQL, stored procedure or trigger abuse, and SQL injection enable hacker access
  • Recognize vulnerabilities peculiar to each database
  • Find out what the attackers already know


Table of Contents

Chapter 1: Why Care About Database Security?

Chapter 2: The Oracle Architecture

Chapter 3: Attacking Oracle

Chapter 4: Oracle: Moving Further into the Network

Chapter 5: Securing Oracle

Chapter 6: IBM DB2 Universal Database

Chapter 7: DB2: Discovery, Attack, and Defense

Chapter 8: Attacking DB2

Chapter 9: Securing DB2

Chapter 10: The Informix Architecture

Chapter 11: Informix: Discovery, Attack, and Defense

Chapter 12: Securing Informix

Chapter 13: Sybase Architecture

Chapter 14: Sybase: Discovery, Attack, and Defense

Chapter 15: Sybase: Moving Further into the Network

Chapter 16: Securing Sybase

Chapter 17: MySQL Architecture

Chapter 18: MySQL: Discovery, Attack, and Defense

Chapter 19: MySQL: Moving Further into the Network

Chapter 20: Securing MySQL

Chapter 21: Microsoft SQL Server Architecture

Chapter 22: SQL Server: Exploitation, Attack, and Defense

Chapter 23: Securing SQL Server

Chapter 24: The PostgreSQL Architecture

Chapter 25: PostgreSQL: Discovery and Attack

Chapter 26: Securing PostgreSQL


About the Author

David Litchfield specializes in searching for new threats to database systems and web applications and holds the unofficial world record for finding major security flaws. He has lectured to both British and U.S. government security agencies on database security and is a regular speaker at the Blackhat Security Briefings. He is a co-author of The Shellcoder’s Handbook, SQL Server Security, and Special Ops. In his spare time he is the Managing Director of Next Generation Security Software Ltd.


Chris Anley is a co-author of The Shellcoder’s Handbook, a best-selling book about security vulnerability research. He has published whitepapers and security advisories on a number of database systems, including SQL Server, Sybase, MySQL, DB2, and Oracle.


John Heasman is a principal security consultant at NGS Software. He is a prolific security researcher and has published many security advisories relating to high-profile products such as Microsoft Windows, Real Player, Apple Quick-Time, and PostgreSQL.


Bill Grindlay is a senior security consultant and software engineer at NGS Software. He has worked on both the generalized vulnerability scanner Typhon III and the NGSSQuirreL family of database security scanners. He is a co-author of the database administrator’s guide, SQL Server Security.


Next Generation Security Software Ltd is a UK-based company that develops a suite of database server vulnerability assessment tools, the NGSSQuirreL family. Founded in 2001, NGS Software’s consulting arm is the largest dedicated security team in Europe. All four authors of this book work for NGS Software.

دیدگاه خود را بنویسید
نظرات کاربران (0 دیدگاه)
نظری وجود ندارد.
کتاب های مشابه
هک و امنیت
981
The Art of Intrusion
658,000 تومان
هک و امنیت
1,066
Mastering Windows Security and Hardening
1,706,000 تومان
هک و امنیت
1,181
Application Security Program Handbook
676,000 تومان
هک و امنیت
1,161
Security Engineering
2,572,000 تومان
هک و امنیت
1,245
CISSP All in One Exam Guide
3,050,000 تومان
هک و امنیت
814
PowerShell for Penetration Testing
677,000 تومان
هک و امنیت
1,242
The Pentester BluePrint
535,000 تومان
هک و امنیت
983
Dynamically Enabled Cyber Defense
823,000 تومان
هک و امنیت
606
SSH, the Secure Shell
1,469,000 تومان
هک و امنیت
1,161
Security as Code
394,000 تومان
قیمت
منصفانه
ارسال به
سراسر کشور
تضمین
کیفیت
پشتیبانی در
روزهای تعطیل
خرید امن
و آسان
آرشیو بزرگ
کتاب‌های تخصصی
هـر روز با بهتــرین و جــدیــدتـرین
کتاب های روز دنیا با ما همراه باشید
آدرس
پشتیبانی
مدیریت
ساعات پاسخگویی
درباره اسکای بوک
دسترسی های سریع
  • راهنمای خرید
  • راهنمای ارسال
  • سوالات متداول
  • قوانین و مقررات
  • وبلاگ
  • درباره ما
چاپ دیجیتال اسکای بوک. 2024-2022 ©