Zum Hauptinhalt springen
Dekorationsartikel gehören nicht zum Leistungsumfang.
Database Hacker's Handbook w/WS
Taschenbuch von David Litchfield (u. a.)
Sprache: Englisch

41,20 €*

inkl. MwSt.

Versandkostenfrei per Post / DHL

Lieferzeit 1-2 Wochen

Kategorien:
Beschreibung
Databases are the nerve center of our economy. Every piece of your personal information is stored there-medical records, bank accounts, employment history, pensions, car registrations, even your children's grades and what groceries you buy. Database attacks are potentially crippling-and relentless.

In this essential follow-up to The Shellcoder's Handbook, four of the world's top security experts teach you to break into and defend the seven most popular database servers. You'll learn how to identify vulnerabilities, how attacks are carried out, and how to stop the carnage. The bad guys already know all this. You need to know it too.
* Identify and plug the new holes in Oracle and Microsoft(r) SQL Server
* Learn the best defenses for IBM's DB2(r), PostgreSQL, Sybase ASE, and MySQL(r) servers
* Discover how buffer overflow exploitation, privilege escalation through SQL, stored procedure or trigger abuse, and SQL injection enable hacker access
* Recognize vulnerabilities peculiar to each database
* Find out what the attackers already know

Go to [...] for code samples, security alerts , and programs available for download.
Databases are the nerve center of our economy. Every piece of your personal information is stored there-medical records, bank accounts, employment history, pensions, car registrations, even your children's grades and what groceries you buy. Database attacks are potentially crippling-and relentless.

In this essential follow-up to The Shellcoder's Handbook, four of the world's top security experts teach you to break into and defend the seven most popular database servers. You'll learn how to identify vulnerabilities, how attacks are carried out, and how to stop the carnage. The bad guys already know all this. You need to know it too.
* Identify and plug the new holes in Oracle and Microsoft(r) SQL Server
* Learn the best defenses for IBM's DB2(r), PostgreSQL, Sybase ASE, and MySQL(r) servers
* Discover how buffer overflow exploitation, privilege escalation through SQL, stored procedure or trigger abuse, and SQL injection enable hacker access
* Recognize vulnerabilities peculiar to each database
* Find out what the attackers already know

Go to [...] for code samples, security alerts , and programs available for download.
Über den Autor
David Litchfield specializes in searching for new threats to database systems and web applications and holds the unofficial world record for finding major security flaws. He has lectured to both British and U.S. government security agencies on database security and is a regular speaker at the Blackhat Security Briefings. He is a co-author of The Shellcoder's Handbook, SQL Server Security, and Special Ops. In his spare time he is the Managing Director of Next Generation Security Software Ltd.

Chris Anley is a co-author of The Shellcoder's Handbook, a best-selling book about security vulnerability research. He has published whitepapers and security advisories on a number of database systems, including SQL Server, Sybase, MySQL, DB2, and Oracle.

John Heasman is a principal security consultant at NGS Software. He is a prolific security researcher and has published many security advisories relating to high-profile products such as Microsoft Windows, Real Player, Apple Quick-Time, and PostgreSQL.

Bill Grindlay is a senior security consultant and software engineer at NGS Software. He has worked on both the generalized vulnerability scanner Typhon III and the NGSSQuirreL family of database security scanners. He is a co-author of the database administrator's guide, SQL Server Security.

Next Generation Security Software Ltd is a UK-based company that develops a suite of database server vulnerability assessment tools, the NGSSQuirreL family. Founded in 2001, NGS Software's consulting arm is the largest dedicated security team in Europe. All four authors of this book work for NGS Software.

Inhaltsverzeichnis
About the Authors.

Preface.

Acknowledgments.

Introduction.

Part I: Introduction.

Chapter 1: Why Care About Database Security?

Part II: Oracle.

Chapter 2: The Oracle Architecture.

Chapter 3: Attacking Oracle.

Chapter 4: Oracle: Moving Further into the Network.

Chapter 5: Securing Oracle.

Part III: DB2.

Chapter 6: IBM DB2 Universal Database.

Chapter 7: DB2: Discovery, Attack, and Defense.

Chapter 8: Attacking DB2.

Chapter 9: Securing DB2.

Part IV: Informix.

Chapter 10: The Informix Architecture.

Chapter 11: Informix: Discovery, Attack, and Defense.

Chapter 12: Securing Informix.

Part V: Sybase ASE.

Chapter 13: Sybase Architecture.

Chapter 14: Sybase: Discovery, Attack, and Defense.

Chapter 15: Sybase: Moving Further into the Network.

Chapter 16: Securing Sybase.

Part VI: MySQL.

Chapter 17: MySQL Architecture.

Chapter 18: MySQL: Discovery, Attack, and Defense.

Chapter 19: MySQL: Moving Further into the Network.

Chapter 20: Securing MySQL.

Part VII: SQL Server.

Chapter 21: Microsoft SQL Server Architecture.

Chapter 22: SQL Server: Exploitation, Attack, and Defense.

Chapter 23: Securing SQL Server.

Part VIII: PostgreSQL.

Chapter 24: The PostgreSQL Architecture.

Chapter 25: PostgreSQL: Discovery and Attack.

Chapter 26: Securing PostgreSQL.

Appendix A: Example C Code for a Time-Delay SQL Injection Harness.

Appendix B: Dangerous Extended Stored Procedures.

Appendix C: Oracle Default Usernames and Passwords.

Index.

Details
Erscheinungsjahr: 2005
Fachbereich: EDV
Genre: Informatik
Rubrik: Naturwissenschaften & Technik
Medium: Taschenbuch
Inhalt: About the Authors.Preface.Acknowledgments.Introduction.Part I: Introduction.Chapter 1: Why Care About Database Security?Part II: Oracle.Chapter 2: The Oracle Architecture.Chapter 3: Attacking Oracle.Chapter 4: Oracle: Moving Further into the Network.Chap
ISBN-13: 9780764578014
ISBN-10: 0764578014
Sprache: Englisch
Herstellernummer: 19767801000
Einband: Kartoniert / Broschiert
Autor: Litchfield, David
Anley, Chris
Heasman, John
Grindlay, Bill
Hersteller: Wiley
John Wiley & Sons
Maße: 235 x 191 x 28 mm
Von/Mit: David Litchfield (u. a.)
Erscheinungsdatum: 01.07.2005
Gewicht: 0,982 kg
Artikel-ID: 102444969
Über den Autor
David Litchfield specializes in searching for new threats to database systems and web applications and holds the unofficial world record for finding major security flaws. He has lectured to both British and U.S. government security agencies on database security and is a regular speaker at the Blackhat Security Briefings. He is a co-author of The Shellcoder's Handbook, SQL Server Security, and Special Ops. In his spare time he is the Managing Director of Next Generation Security Software Ltd.

Chris Anley is a co-author of The Shellcoder's Handbook, a best-selling book about security vulnerability research. He has published whitepapers and security advisories on a number of database systems, including SQL Server, Sybase, MySQL, DB2, and Oracle.

John Heasman is a principal security consultant at NGS Software. He is a prolific security researcher and has published many security advisories relating to high-profile products such as Microsoft Windows, Real Player, Apple Quick-Time, and PostgreSQL.

Bill Grindlay is a senior security consultant and software engineer at NGS Software. He has worked on both the generalized vulnerability scanner Typhon III and the NGSSQuirreL family of database security scanners. He is a co-author of the database administrator's guide, SQL Server Security.

Next Generation Security Software Ltd is a UK-based company that develops a suite of database server vulnerability assessment tools, the NGSSQuirreL family. Founded in 2001, NGS Software's consulting arm is the largest dedicated security team in Europe. All four authors of this book work for NGS Software.

Inhaltsverzeichnis
About the Authors.

Preface.

Acknowledgments.

Introduction.

Part I: Introduction.

Chapter 1: Why Care About Database Security?

Part II: Oracle.

Chapter 2: The Oracle Architecture.

Chapter 3: Attacking Oracle.

Chapter 4: Oracle: Moving Further into the Network.

Chapter 5: Securing Oracle.

Part III: DB2.

Chapter 6: IBM DB2 Universal Database.

Chapter 7: DB2: Discovery, Attack, and Defense.

Chapter 8: Attacking DB2.

Chapter 9: Securing DB2.

Part IV: Informix.

Chapter 10: The Informix Architecture.

Chapter 11: Informix: Discovery, Attack, and Defense.

Chapter 12: Securing Informix.

Part V: Sybase ASE.

Chapter 13: Sybase Architecture.

Chapter 14: Sybase: Discovery, Attack, and Defense.

Chapter 15: Sybase: Moving Further into the Network.

Chapter 16: Securing Sybase.

Part VI: MySQL.

Chapter 17: MySQL Architecture.

Chapter 18: MySQL: Discovery, Attack, and Defense.

Chapter 19: MySQL: Moving Further into the Network.

Chapter 20: Securing MySQL.

Part VII: SQL Server.

Chapter 21: Microsoft SQL Server Architecture.

Chapter 22: SQL Server: Exploitation, Attack, and Defense.

Chapter 23: Securing SQL Server.

Part VIII: PostgreSQL.

Chapter 24: The PostgreSQL Architecture.

Chapter 25: PostgreSQL: Discovery and Attack.

Chapter 26: Securing PostgreSQL.

Appendix A: Example C Code for a Time-Delay SQL Injection Harness.

Appendix B: Dangerous Extended Stored Procedures.

Appendix C: Oracle Default Usernames and Passwords.

Index.

Details
Erscheinungsjahr: 2005
Fachbereich: EDV
Genre: Informatik
Rubrik: Naturwissenschaften & Technik
Medium: Taschenbuch
Inhalt: About the Authors.Preface.Acknowledgments.Introduction.Part I: Introduction.Chapter 1: Why Care About Database Security?Part II: Oracle.Chapter 2: The Oracle Architecture.Chapter 3: Attacking Oracle.Chapter 4: Oracle: Moving Further into the Network.Chap
ISBN-13: 9780764578014
ISBN-10: 0764578014
Sprache: Englisch
Herstellernummer: 19767801000
Einband: Kartoniert / Broschiert
Autor: Litchfield, David
Anley, Chris
Heasman, John
Grindlay, Bill
Hersteller: Wiley
John Wiley & Sons
Maße: 235 x 191 x 28 mm
Von/Mit: David Litchfield (u. a.)
Erscheinungsdatum: 01.07.2005
Gewicht: 0,982 kg
Artikel-ID: 102444969
Warnhinweis