Gray Hat Hacking: The Ethical Hacker's Handbook, Fifth Edition Daniel Regalado - eBook PDF download
https://ebooksecure.com/download/gray-hat-hacking-the-ethicalhackers-handbook-fifth-edition-ebook-pdf/ Download
We believe these products will be a great fit for you. Click the link to download now, or visit ebooksecure.com to discover even more!
Gray Hat Hacking: The Ethical Hacker's Handbook Sixth Edition Daniel Regalado - eBook PDF
https://ebooksecure.com/download/gray-hat-hacking-the-ethicalhackers-handbook-sixth-edition-ebook-pdf/
Gray Hat Hacking: The Ethical Hacker's Handbook 5th Edition Allen Harper - eBook PDF https://ebooksecure.com/download/gray-hat-hacking-the-ethicalhackers-handbook-ebook-pdf/
(eBook PDF) The Bedford Handbook 10th Edition by Diana Hacker http://ebooksecure.com/product/ebook-pdf-the-bedfordhandbook-10th-edition-by-diana-hacker/
(eBook PDF) Hands-On Ethical Hacking and Network Defense 3rd Edition
http://ebooksecure.com/product/ebook-pdf-hands-on-ethicalhacking-and-network-defense-3rd-edition/
CEH Certified Ethical Hacker Practice Exams, 5th Edition Matt Walker - eBook PDF
https://ebooksecure.com/download/ceh-certified-ethical-hackerpractice-exams-5th-edition-ebook-pdf/
CEH Certified Ethical Hacker All-in-One Exam Guide 4th Edition (eBook PDF)
http://ebooksecure.com/product/ceh-certified-ethical-hacker-allin-one-exam-guide-4th-edition-ebook-pdf/
Hands-On Ethical Hacking and Network Defense Third Edition Michael T. Simpson - eBook PDF
https://ebooksecure.com/download/hands-on-ethical-hacking-andnetwork-defense-ebook-pdf/
The Audit Process 7th Edition Iain Gray - eBook PDF
https://ebooksecure.com/download/the-audit-process-ebook-pdf/
Hands-On Ethical Hacking and Network Defense (MindTap Course List) [Team-IRA] [True PDF] 4th Edition Rob Wilson - eBook PDF
https://ebooksecure.com/download/hands-on-ethical-hacking-andnetwork-defense-mindtap-course-list-team-ira-true-pdf-ebook-pdf/
Praise forGrayHat Hacking: The EthicalHacker’sHandbook, Fifth Edition “TheGrayHatHackingbookseriescontinuetoprovideanup-to-dateanddetailed view onalargevarietyofoffensiveITsecuritydisciplines.Inthisfifthedition,agroup ofrespectedinfosecprofessionalssparednoefforttosharetheir experienceand expertiseonnovel techniquestobypasssecuritymechanisms.
Theexploitdevelopmentchapters,writtenbyStephenSims,reveal ingreatdetail whatittakestowriteanexploitfor modernapplications.InChapter 14,Stephenusesa recentvulnerabilityinamajor webbrowser todemystifythecomplexityofwriting modernexploitsfor heap-relatedmemorycorruptions,bypassingmemoryprotections alongtheroad.
Thisbookisamustreadfor anyonewhowantstostepupandbroadentheir skillsin infosec.”
PeterVanEeckhoutte CorelanTeam(@corelanc0d3r)
“Oneofthefew bookserieswhereIALWAYSbuytheupdatedversion.Learnupdated exploit-devtechniquesfromthebestinstructorsinthebusiness.Thevolumeofnew informationavailabletotheaverageinformationsecuritypractitioner isstaggering.The authors,whoaresomeofthebestintheir respectivefields,helpusstayuptodatewith currenttrendsandtechniques.GHH’supdatesonRedTeamOps,BugBounties, PowerShell Techniques,andIoT&EmbeddedDevicesareexactlywhatinfosec practitionersneedtoaddtotheir tool kits.”
ChrisGates Sr.SecurityEngineer (Uber)
“Never beforehastherebeensomuchtechnologytoattacknor suchhighlevelsof controlsandpreventionmechanisms.For example,theadvancementsinmodern operatingsystemsandapplicationstoprotectagainstexploitationareveryimpressive, yettimeandtimeagainwiththerightconditionstheyarebypassed.Amongstalitanyof modernandup-to-datetechniques,GrayHatHackingprovidesdetailedandinformative walkthroughsofvulnerabilitiesandhow controlslikeASLRandDEParebypassed. Filledwithreal examplesyoucanfollow ifyouareseekingtoupgradeyour understandingofthelatesthackingtechniques thisisthebookfor you.”
Copyright©2018byMcGraw-Hill Education.All rightsreserved.Exceptaspermitted under theUnitedStatesCopyrightActof1976,nopartofthispublicationmaybe reproducedor distributedinanyformor byanymeans,or storedinadatabaseor retrieval system,withouttheprior writtenpermissionofthepublisher,withthe exceptionthattheprogramlistingsmaybeentered,stored,andexecutedinacomputer system,buttheymaynotbereproducedfor publication.
ISBN: 978-1-26-010842-2
MHID: 1-26-010842-2
Thematerial inthiseBookalsoappearsintheprintversionofthistitle: ISBN: 978-126-010841-5, MHID: 1-26-010841-4.
eBookconversionbycodeMantra Version1.0
All trademarksaretrademarksoftheir respectiveowners.Rather thanputatrademark symbol after everyoccurrenceofatrademarkedname,weusenamesinaneditorial fashiononly,andtothebenefitofthetrademarkowner,withnointentionofinfringement ofthetrademark.Wheresuchdesignationsappear inthisbook,theyhavebeenprinted withinitial caps.
McGraw-Hill Educationebooksareavailableatspecial quantitydiscountstouseas premiumsandsalespromotionsor for useincorporatetrainingprograms.Tocontacta representative,pleasevisittheContactUspageatwww.mhprofessional.com.
All trademarksor copyrightsmentionedhereinarethepossessionoftheir respective ownersandMcGraw-Hill Educationmakesnoclaimofownershipbythementionof productsthatcontainthesemarks.
InformationhasbeenobtainedbyMcGraw-Hill Educationfromsourcesbelievedtobe reliable.However,becauseofthepossibilityofhumanor mechanical error byour sources,McGraw-Hill Education,or others,McGraw-Hill Educationdoesnot guaranteetheaccuracy,adequacy,or completenessofanyinformationandisnot responsiblefor anyerrorsor omissionsor theresultsobtainedfromtheuseofsuch information.
TERMSOFUSE ThisisacopyrightedworkandMcGraw-Hill Educationanditslicensorsreserveall rightsinandtothework.Useofthisworkissubjecttotheseterms.Exceptaspermitted under theCopyrightActof1976andtherighttostoreandretrieveonecopyofthework, youmaynotdecompile,disassemble,reverseengineer,reproduce,modify,create derivativeworksbasedupon,transmit,distribute,disseminate,sell,publishor sublicensetheworkor anypartofitwithoutMcGraw-Hill Education’sprior consent. Youmayusetheworkfor your ownnoncommercial andpersonal use;anyother useof theworkisstrictlyprohibited.Your righttousetheworkmaybeterminatedifyoufail tocomplywiththeseterms.
THEWORKISPROVIDED“ASIS.”McGRAW-HILLEDUCATIONANDITS LICENSORSMAKENOGUARANTEESORWARRANTIESASTOTHE ACCURACY,ADEQUACYORCOMPLETENESSOFORRESULTSTOBE OBTAINEDFROMUSINGTHEWORK,INCLUDINGANYINFORMATIONTHAT CANBEACCESSEDTHROUGHTHEWORKVIAHYPERLINKOROTHERWISE, ANDEXPRESSLYDISCLAIMANYWARRANTY,EXPRESSORIMPLIED, INCLUDINGBUTNOTLIMITEDTOIMPLIEDWARRANTIESOF MERCHANTABILITYORFITNESSFORAPARTICULARPURPOSE.McGraw-Hill Educationanditslicensorsdonotwarrantor guaranteethatthefunctionscontainedin theworkwill meetyour requirementsor thatitsoperationwill beuninterruptedor error free.Neither McGraw-Hill Educationnor itslicensorsshall beliabletoyouor anyone elsefor anyinaccuracy,error or omission,regardlessofcause,intheworkor for any damagesresultingtherefrom.McGraw-Hill Educationhasnoresponsibilityfor the contentofanyinformationaccessedthroughthework.Under nocircumstancesshall McGraw-Hill Educationand/or itslicensorsbeliablefor anyindirect,incidental, special,punitive,consequential or similar damagesthatresultfromtheuseofor inabilitytousethework,evenifanyofthemhasbeenadvisedofthepossibilityofsuch damages.Thislimitationofliabilityshall applytoanyclaimor causewhatsoever whether suchclaimor causearisesincontract,tortor otherwise.
In Memoryof Shon Harris Inthepreviousedition,IspokeinmemoryofShonHarris,myfriend,mentor,anda personIcreditwithjump-startingmycareer after mytimeintheMarineCorps.Simply put,neither thisbooknor mostofmyprofessional accomplishmentswouldhave happenedwithouther.Icontinuetomissher andIknow Ispeakonbehalfoftheother authorsthatwewishshewerestill withus.Ifyoudidnotknow Shonor havenever heardofher,youoweittoyourselftolearnabouther inspiringstoryinthelastedition andelsewhere.For thoseofuswhoknew her andhaveour own“Shon”stories,joinme inkeepingher memoryaliveandshareher storywithanyonewhowill listen.Shewas anamazingpersonandislovedandmisseddearly.Wededicatethisbooktoher memory.
AllenHarper
Leadauthor andfriendofShonHarris
TomybrothersandsistersinChrist,keeprunningtherace.Letyour lightshinefor Him, thatothersmaybedrawntoHimthroughyou.
AllenHarper
Dedicadoati mamitaAdelinaAriasCruz,cuandomepreguntodedondesalemi garra denodejarmedenadieoel sacrificioincansableparaconseguir mismetas,solotengo quevoltear averte,parati nohayimposibles,teadoro!
Daniel Regalado
ToMom,whoreadtomewhenIwaslittle,soIcouldachievethelevel ofliteracyI neededtobecomeanauthor oneday.
RyanLinn
TomylovelywifeLeAnneandmydaughter Audrey,thankyoufor your ongoingsupport!
StephenSims
Tomylovelydaughter Elysia,thankyoufor your unconditional loveandsupport.You inspiremeinsomanyways.Iam,andwill alwaysbe,your biggestfan.
LindaMartinez
Tomyfamilyandfriendsfor their unconditional supportandmakingthislifefunnyand interesting.
Tomydaughter Tiernan,thankyoufor your supportandcontinuousreminderstoenjoy lifeandlearningeachandeveryday.Ilookforwardtoseeingthewonderful womanyou will become.
Michael Baucom
TomysonAaron,thanksfor all your lovewhileIspendtoomuchtimeatthekeyboard, andthanksfor sharingyour joyonall theprojectsweworkontogether.
ChrisEagle
ABOUTTHEAUTHORS Dr.AllenHarper,CISSP.In2007,AllenHarper retiredfromthemilitaryasaMarine CorpsOfficer after atour inIraq.Hehasmorethan30yearsofIT/securityexperience. HeholdsaPhDinITwithafocusinInformationAssuranceandSecurityfromCapella, anMSinComputer SciencefromtheNaval PostgraduateSchool,andaBSinComputer EngineeringfromNorthCarolinaStateUniversity.Allenledthedevelopmentofthe GENIIIhoneywall CD-ROM,calledroo,for theHoneynetProject.Hehasworkedasa securityconsultantfor manyFortune500andgovernmententities.Hisinterestsinclude theInternetofThings,reverseengineering,vulnerabilitydiscovery,andall formsof ethical hacking.Allenwasthefounder ofN2NetSecurity,Inc.,servedastheEVPand chiefhacker atTangibleSecurity,andnow servestheLordatLibertyUniversityin Lynchburg,Virginia.
DanielRegalado,akaDanux,isaMexicansecurityresearcher withmorethan16 yearsinthesecurityfield,dissectingor pen-testingmalware,0-dayexploits,ATMs,IoT devices,IVpumps,andcar infotainmentsystems.Heisaformer employeeofwidely respectedcompanieslikeFireEyeandSymantecandiscurrentlyaprincipal security researcher atZingbox.Daniel isprobablybestknownfor hismultiplediscoveriesand dissectionofATMmalwareattackingbanksworldwide,withthemostnotorious findingsbeingPloutus,Padpin,andRipper.
RyanLinnhasover 20yearsinthesecurityindustry,rangingfromsystems programmer tocorporatesecurity,toleadingaglobal cybersecurityconsultancy.Ryan hascontributedtoanumber ofopensourceprojects,includingMetasploitandthe Browser ExploitationFramework(BeEF).RyanparticipatesinTwitter as@sussurro, andhehaspresentedhisresearchatnumeroussecurityconferences,includingBlackHat andDEFCON,andhasprovidedtraininginattacktechniquesandforensicsworldwide.
StephenSimsisanindustryexpertwithover 15yearsofexperienceininformation technologyandsecurity.HecurrentlyworksoutofSanFranciscoasaconsultant performingreverseengineering,exploitdevelopment,threatmodeling,andpenetration testing.StephenhasanMSininformationassurancefromNorwichUniversityandisa courseauthor,fellow,andcurriculumleadfor theSANSInstitute,authoringcourseson advancedexploitdevelopmentandpenetrationtesting.Hehasspokenatnumerous conferences,includingRSA,BSides,OWASPAppSec,ThaiCERT,AISA,andmany others.Hemaybereachedontwitter: @Steph3nSims
BrankoSpasojevicisasecurityengineer onGoogle’sDetectionandResponseteam. Beforethatheworkedasareverseengineer for Symantecandanalyzedvariousthreats andAPTgroups.
LindaMartinez istheChiefInformationSecurityOfficer (CISO) andVicePresident ofCommercial ServiceDeliveryatTangibleSecurity.Lindaisaproveninformation securityexecutiveandindustryexpertwithover 18yearsofexperienceleading technical teams,developingtechnical businesslines,andprovidinghigh-quality consultingservicestoclients.Sheisresponsiblefor TangibleSecurity’sCommercial Division,wheresheleadsthefollowingbusinesslines: penetrationtesting,including redandpurpleteamoperations;hardwarehacking;productandsupplychainsecurity; governance,riskmanagement,andcompliance;incidentresponseanddigital forensics. Lindaalsoleadsateamofvirtual ChiefInformationSecurityOfficers(CISOs) in providingexpertguidancetomanyorganizations.Prior toher currentposition,Linda wastheVicePresidentofOperationsfor N2NetSecurity.Beforethat,sheco-founded andservedasChiefOperatingOfficer (COO) for ExecutiveInstruments,aninformation securityresearchandconsultingfirm.
MichaelBaucomcurrentlyworksfor TangibleSecurityastheVPofTangibleLabs. WhileatTangiblehehasworkedonawidevarietyofprojects,includingsoftware securityassessments,SDLCconsulting,tool development,andpenetrationtests.Prior to workingatTangibleSecurity,heservedintheMarineCorpsasagroundradio repairman.Additionally,heworkedfor IBM,Motorola,andBroadcominseveral capacities,includingtestengineering,devicedriver development,andsystemsoftware developmentfor embeddedsystems.Inadditiontohisworkactivities,Michael hasbeen atrainer atBlackHat,speaker atseveral conferences,andtechnical editor for GrayHat Hacking: TheEthical Hacker’sHandbook.Hiscurrentinterestsareinautomatingpentestactivities,embeddedsystemsecurity,andmobilephonesecurity.
ChrisEagle isasenior lecturer inthecomputer sciencedepartmentattheNaval PostgraduateSchool inMonterey,California.Acomputer engineer/scientistfor more than30years,hehasauthoredseveral books,servedasthechiefarchitectfor DARPA’s Cyber GrandChallenge,frequentlyspeaksatsecurityconferences,andhascontributed several popular opensourcetoolstothesecuritycommunity.
ThelateShonHarrisisgreatlymissed.ShewasthepresidentofLogical Security,a securityconsultant,aformer engineer intheAir Force’sInformationWarfareunit,an instructor,andanauthor.Sheauthoredthebest-sellingCISSPExamGuide(currentlyin itsseventhedition),alongwithmanyother books.Shonconsultedfor avarietyof companiesinmanydifferentindustries.Shontaughtcomputer andinformationsecurity toawiderangeofclients,includingRSA,DepartmentofDefense,Departmentof Energy,WestPoint,National SecurityAgency(NSA),BankofAmerica,Defense InformationSystemsAgency(DISA),BMC,andmanymore.Shonwasrecognizedas
oneofthetop25womenintheInformationSecurityfieldbyInformationSecurity Magazine.
Disclaimer: The viewsexpressedinthisbookare those of the authorsandnot of the U.S.government oranycompanymentionedherein.
AbouttheTechnicalEditor HeatherLinnhasover 20yearsinthesecurityindustryandhasheldrolesincorporate security,penetrationtesting,andaspartofahuntteam.Shehascontributedtoopen sourceframeworks,includingMetasploit,andhascontributedtocoursematerialson forensics,penetrationtesting,andinformationsecuritytaughtaroundtheglobe.
Heather haspresentedatmanysecurityconferences,includingmultipleBSides conferences,local ISSAchapter conferences,andstudenteventsaimedatproviding realisticexpectationsfor new studentsenteringtheinformationsecurityfield.
CONTENTSATAGLANCE Part I Preparation Chapter1 WhyGrayHatHacking?EthicsandLaw
Chapter2 ProgrammingSurvival Skills
Chapter3 Next-GenerationFuzzing
Chapter4 Next-GenerationReverseEngineering
Chapter5 Software-DefinedRadio
Part II Businessof Hacking Chapter6 SoYouWanttoBeaPenTester?
Chapter7 RedTeamingOperations
Chapter8 PurpleTeaming
Chapter9 BugBountyPrograms
Part III ExploitingSystems Chapter10 GettingShellsWithoutExploits
Chapter11 BasicLinuxExploits
Chapter12 AdvancedLinuxExploits
Chapter13 WindowsExploits
Chapter14 AdvancedWindowsExploitation
Chapter15 PowerShell Exploitation
Chapter16 Next-GenerationWebApplicationExploitation
Chapter17 Next-GenerationPatchExploitation
Part Chapter18 DissectingMobileMalware
Chapter19 DissectingRansomware
Chapter20 ATMMalware
Chapter21 Deception: Next-GenerationHoneypots
Part V Internetof Things
Chapter22 InternetofThingstoBeHacked
Chapter23 DissectingEmbeddedDevices
Chapter24 ExploitingEmbeddedDevices
Chapter25 FightingIoTMalware
Index
Preface
Acknowledgments
Introduction
Part I Preparation
Chapter1 WhyGrayHatHacking?EthicsandLaw
Know Your Enemy
TheCurrentSecurityLandscape
RecognizinganAttack
TheGrayHatWay
EmulatingtheAttack
FrequencyandFocusofTesting
EvolutionofCyberlaw
UnderstandingIndividual Cyberlaws
Summary References
Chapter2 ProgrammingSurvival Skills
CProgrammingLanguage
BasicCLanguageConstructs
SampleProgram
Compilingwithgcc
Computer Memory
RandomAccessMemory
Endian
SegmentationofMemory
ProgramsinMemory
Buffers
StringsinMemory
Pointers
PuttingthePiecesofMemoryTogether
Intel Processors Registers
AssemblyLanguageBasics
Machinevs.Assemblyvs.C
AT&Tvs.NASM
AddressingModes
AssemblyFileStructure
Assembling
Debuggingwithgdb
gdbBasics
Disassemblywithgdb
PythonSurvival Skills
GettingPython
“Hello,World!”inPython
PythonObjects
Strings
Numbers
Lists Dictionaries
FileswithPython
SocketswithPython
Summary For Further Reading References
Chapter3 Next-GenerationFuzzing
IntroductiontoFuzzing
TypesofFuzzers
MutationFuzzers
GenerationFuzzers
GeneticFuzzing
MutationFuzzingwithPeach
Lab3-1: MutationFuzzingwithPeach
GenerationFuzzingwithPeach
CrashAnalysis
Lab3-2: GenerationFuzzingwithPeach Geneticor EvolutionaryFuzzingwithAFL Lab3-3: GeneticFuzzingwithAFL Summary
For Further Reading
Chapter4 Next-GenerationReverseEngineering CodeAnnotation
IDBAnnotationwithIDAscope C++CodeAnalysis CollaborativeAnalysis
LeveragingCollaborativeKnowledgeUsingFIRST CollaborationwithBinNavi DynamicAnalysis
AutomatedDynamicAnalysiswithCuckooSandbox BridgingtheStatic-DynamicTool GapwithLabeless Summary
For Further Reading References
Chapter5 Software-DefinedRadio GettingStartedwithSDR WhattoBuy NotSoQuick: Know theRules LearnbyExample Search Capture Replay Analyze Preview Execute Summary
For Further Reading
Part II Businessof Hacking
Chapter6 SoYouWanttoBeaPenTester?
TheJourneyfromNovicetoExpert
PenTester Ethos
PenTester Taxonomy
TheFutureofHacking
Know theTech
Know WhatGoodLooksLike
PenTester Training
Practice
DegreePrograms
KnowledgeTransfer
PenTester Tradecraft
Personal Liability
BeingtheTrustedAdvisor
ManagingaPenTest
Summary
For Further Reading
Chapter7 RedTeamingOperations
RedTeamOperations
Strategic,Operational,andTactical Focus
AssessmentComparisons
RedTeamingObjectives
WhatCanGoWrong
LimitedScope
LimitedTime
LimitedAudience
OvercomingLimitations
Communications
PlanningMeetings
DefiningMeasurableEvents
UnderstandingThreats
AttackFrameworks
TestingEnvironment
AdaptiveTesting
External Assessment
Physical SecurityAssessment
Social Engineering
Internal Assessment
Summary
References
Chapter8 PurpleTeaming
IntroductiontoPurpleTeaming
BlueTeamOperations
Know Your Enemy
Know Yourself
SecurityProgram
IncidentResponseProgram
CommonBlueTeamingChallenges
PurpleTeamingOperations
DecisionFrameworks
DisruptingtheKill Chain
Kill ChainCountermeasureFramework
Communication
PurpleTeamOptimization
Summary For Further Reading References
Chapter9
BugBountyPrograms
HistoryofVulnerabilityDisclosure
Full Vendor Disclosure
Full PublicDisclosure
ResponsibleDisclosure
NoMoreFreeBugs
BugBountyPrograms
TypesofBugBountyPrograms
Incentives
ControversySurroundingBugBountyPrograms
Popular BugBountyProgramFacilitators
BugcrowdinDepth
ProgramOwner WebInterface
ProgramOwner APIExample
Researcher WebInterface
EarningaLivingFindingBugs
SelectingaTarget
Registering(IfRequired)
UnderstandingtheRulesoftheGame
FindingVulnerabilities
ReportingVulnerabilities
CashingOut
IncidentResponse
Communication
Triage
Remediation
DisclosuretoUsers
PublicRelations
Summary For Further Reading References
Part III ExploitingSystems
Chapter10 GettingShellsWithoutExploits
CapturingPasswordHashes
UnderstandingLLMNRandNBNS UnderstandingWindowsNTLMv1andNTLMv2Authentication UsingResponder
Lab10-1: GettingPasswordswithResponder UsingWinexe
Lab10-2: UsingWinexetoAccessRemoteSystems
Lab10-3: UsingWinexetoGainElevatedPrivileges UsingWMI
Lab10-4: QueryingSystemInformationwithWMI
Lab10-5: ExecutingCommandswithWMI TakingAdvantageofWinRM
Lab10-6: ExecutingCommandswithWinRM
Lab10-7: UsingWinRMtoRunPowerShell Remotely Summary
For Further Reading Reference
Chapter11 BasicLinuxExploits StackOperationsandFunction-CallingProcedures
Buffer Overflows
Lab11-1: Overflowingmeet.c
RamificationsofBuffer Overflows
Local Buffer Overflow Exploits
Lab11-2: ComponentsoftheExploit
Lab11-3: ExploitingStackOverflowsfromtheCommandLine
Lab11-4: ExploitingStackOverflowswithGenericExploit Code
Lab11-5: ExploitingSmall Buffers
ExploitDevelopmentProcess
Lab11-6: BuildingCustomExploits
Summary For Further Reading
Chapter12 AdvancedLinuxExploits
FormatStringExploits
FormatStrings
Lab12-1: ReadingfromArbitraryMemory
Lab12-2: WritingtoArbitraryMemory
Lab12-3: ChangingProgramExecution
MemoryProtectionSchemes
Compiler Improvements
Lab11-4: BypassingStackProtection Kernel PatchesandScripts
Lab12-5: ReturntolibcExploits
Lab12-6: MaintainingPrivilegeswithret2libc BottomLine
Summary For Further Reading References
Chapter13 WindowsExploits
CompilingandDebuggingWindowsPrograms
Lab13-1: CompilingonWindows WindowsCompiler Options
Chapter14
DebuggingonWindowswithImmunityDebugger
Lab13-2: CrashingtheProgram
WritingWindowsExploits
ExploitDevelopmentProcessReview
Lab13-3: ExploitingProSSHDServer
UnderstandingStructuredExceptionHandling(SEH) UnderstandingandBypassingWindowsMemoryProtections
SafeStructuredExceptionHandling(SafeSEH)
BypassingSafeSEH
SEHOverwriteProtection(SEHOP)
BypassingSEHOP
Stack-BasedBuffer OverrunDetection(/GS)
Bypassing/GS
HeapProtections
Summary For Further Reading
References
AdvancedWindowsExploitation
DataExecutionPrevention(DEP)
AddressSpaceLayoutRandomization(ASLR) EnhancedMitigationExperienceToolkit(EMET) andWindows
Defender ExploitGuard
BypassingASLR
BypassingDEPandAvoidingASLR
VirtualProtect
Return-OrientedProgramming Gadgets
BuildingtheROPChain
DefeatingASLRThroughaMemoryLeak
TriggeringtheBug
TracingtheMemoryLeak
WeaponizingtheMemoryLeak
BuildingtheRVAROPChain
Summary
For Further Reading
References
Chapter15 PowerShell Exploitation
WhyPowerShell
LivingOfftheLand
PowerShell Logging
PowerShell Portability
LoadingPowerShell Scripts
Lab15-1: TheFailureCondition
Lab15-2: PassingCommandsontheCommandLine
Lab15-3: EncodedCommands
Lab15-4: BootstrappingviatheWeb ExploitationandPost-ExploitationwithPowerSploit
Lab15-5: SettingUpPowerSploit
Lab15-6: RunningMimikatzThroughPowerShell
Lab15-7: CreatingaPersistentMeterpreter UsingPowerSploit UsingPowerShell Empirefor C2
Lab15-8: SettingUpEmpire
Lab15-9: StaginganEmpireC2
Lab15-10: UsingEmpiretoOwntheSystem Summary
For Further Reading References
Chapter16
Next-GenerationWebApplicationExploitation
TheEvolutionofCross-SiteScripting(XSS)
SettingUptheEnvironment
Lab16-1: XSSRefresher
Lab16-2: XSSEvasionfromInternetWisdom
Lab16-3: ChangingApplicationLogicwithXSS
Lab16-4: UsingtheDOMfor XSS FrameworkVulnerabilities
SettingUptheEnvironment
Lab16-5: ExploitingCVE-2017-5638
Lab16-6: ExploitingCVE-2017-9805 PaddingOracleAttacks
Lab16-7: ChangingDatawiththePaddingOracleAttack Summary For Further Reading
References
Chapter17 Next-GenerationPatchExploitation
IntroductiontoBinaryDiffing
ApplicationDiffing
PatchDiffing
BinaryDiffingTools
BinDiff
turbodiff
Lab17-1: Our FirstDiff
PatchManagementProcess
MicrosoftPatchTuesday
ObtainingandExtractingMicrosoftPatches
Lab17-2: DiffingMS17-010
PatchDiffingfor Exploitation
DLLSide-LoadingBugs
Lab17-3: DiffingMS16-009
Summary
For Further Reading References
Part IV Advanced MalwareAnalysis
Chapter18 DissectingMobileMalware
TheAndroidPlatform
AndroidApplicationPackage ApplicationManifest
AnalyzingDEX
JavaDecompilation
DEXDecompilation
DEXDisassembling
Example18-1: RunningAPKinEmulator
MalwareAnalysis
TheiOSPlatform
iOSSecurity
iOSApplications
Summary
For Further Reading References
Chapter19 DissectingRansomware
TheBeginningsofRansomware
Optionsfor PayingtheRansom
DissectingRansomlock
Example19-1: DynamicAnalysis
Example19-2: StaticAnalysis
Wannacry
Example19-3: AnalyzingWannacryRansomware
Summary For Further Reading
Chapter20 ATMMalware
ATMOverview
XFSOverview
XFSArchitecture
XFSManager
ATMMalwareAnalysis
TypesofATMMalware
Techniquesfor InstallingMalwareonATMs
Techniquesfor DissectingtheMalware ATMMalwareCountermeasures
Summary For Further Reading References
Chapter21 Deception: Next-GenerationHoneypots
BriefHistoryofDeception
HoneypotsasaFormofDeception DeploymentConsiderations
SettingUpaVirtual Machine
OpenSourceHoneypots
Lab21-1: Dionaea
Lab21-2: ConPot
Lab21-3: Cowrie
Lab21-4: T-Pot
Commercial Alternative: TrapX
Summary
For Further Reading References
Part V Internetof Things Chapter22
InternetofThingstoBeHacked
InternetofThings(IoT)
TypesofConnectedThings
WirelessProtocols
CommunicationProtocols
SecurityConcerns
ShodanIoTSearchEngine
WebInterface
ShodanCommand-LineInterface
Lab22-1: UsingtheShodanCommandLine ShodanAPI
Lab22-2: TestingtheShodanAPI
Lab22-3: PlayingwithMQTT
ImplicationsofThisUnauthenticatedAccesstoMQTT
IoTWorms: ItWasaMatter ofTime
Lab22-4: Mirai Lives Prevention
Summary For Further Reading References
Chapter23 DissectingEmbeddedDevices
CPU
Microprocessor
Microcontrollers
SystemonChip(SoC)
CommonProcessor Architectures
Serial Interfaces
UART
SPI
DebugInterfaces
JTAG
SWD(Serial WireDebug)
Software
Bootloader
NoOperatingSystem
Real-TimeOperatingSystem
General OperatingSystem
Summary For Further Reading References
Chapter24 ExploitingEmbeddedDevices
StaticAnalysisofVulnerabilitiesinEmbeddedDevices
Lab24-1: AnalyzingtheUpdatePackage
Lab24-2: PerformingVulnerabilityAnalysis
DynamicAnalysiswithHardware
TheTestEnvironmentSetup Ettercap
DynamicAnalysiswithEmulation FIRMADYNE
Lab24-3: SettingUpFIRMADYNE
Lab24-4: EmulatingFirmware
Lab24-5: ExploitingFirmware
Summary
Further Reading References
Chapter25 FightingIoTMalware
Physical AccesstotheDevice
RS-232Overview
RS-232Pinout
Exercise25-1: TroubleshootingaMedical Device’sRS-232 Port
SettingUptheThreatLab
ARMandMIPSOverview
Lab25-1: SettingUpSystemswithQEMU DynamicAnalysisofIoTMalware
Lab25-2: IoTMalwareDynamicAnalysis Platformfor Architecture-Neutral DynamicAnalysis(PANDA) BeagleBoneBlackBoard
ReverseEngineeringIoTMalware
Crash-CourseARM/MIPSInstructionSet
Lab25-3: IDAProRemoteDebuggingandReversing IoTMalwareReversingExercise
Summary
For Further Reading Index
Thisbookhasbeendevelopedbyandfor securityprofessionalswhoarededicatedto workinginanethical andresponsiblemanner toimprovetheoverall securitypostureof individuals,corporations,andnations.
ACKNOWLEDGMENTS Eachof the authorswouldliketothankthestaffatMcGraw-Hill Education.In particular,wewouldliketothankWendyRinaldi andClaireYee.Youreallywent aboveandbeyond,keepingusontrackandgreatlyhelpingusthroughtheprocess.Your highestlevelsofprofessionalismandtirelessdedicationtothisprojectweretruly noteworthyandbringgreatcredittoyour publisher.Thanks.
AllenHarperwouldliketothankhiswonderful wifeCorannandbeautiful daughters HaleyandMadisonfor their supportandunderstandingasIchasedyetanother dream.
Itiswonderful toseeour familyandeachofusindividuallygrow stronger inChrist eachyear.MadisonandHaley,Iloveyoubothdearlyandamproudoftheyoungladies youhavebecome.Inaddition,Iwouldliketothankthemembersofmyformer and currentemployer.TothefriendsatTangibleSecurity,Iamthankful for your impacton mylife youmademebetter.TomybrothersandsistersinChristatLibertyUniversity, Iamexcitedfor theyearsaheadaswelabor together andaimtotrainChampionsfor Christ!
DanielRegaladolegustaríaagradecer primeroaDiospor labendicióndeestar vivo,asuesposaDianapor aguantarlo,por siempremotivarlo,por festejar cadaunode sustriunfoscomosi fuerandeella,por ser tanbellayatlética,teamo!Asushijos FerchoyAndrickpor ser laluzdelacasaysumotor decadadiayfinalmenteperono menosimportantealaFamiliaRegaladoArias: Fernando,Adelina,SusanaErwiny Belem,sinellos,sustriunfosnosabríanigual,losamo!YasuPapaFernando,hastael ultimodiaquerespire,viviréconlaesperanzadevolver aabrazarte.Cape,Cone, Rober,hermandadparasiempre!
BrankoSpasojevicwouldliketothankhisfamily Sanja,Sandra,AnaMarija, Magdalena,Ilinka,Jevrem,Olga,Dragisa,Marija,andBranislav for all thesupport andknowledgetheypassedon.
Another bigthanksgoestoall myfriendsandcolleagueswhomakeworkandplay fun.Somepeoplewhodeservespecial mentionareAnteGulam,Antonio,Cedric, Clement,Domagoj,Drazen,Goran,Keith,Luka,Leon,Matko,Santiago,Tory,and everyoneinTAG,Zynamics,D&R,andOrca.
RyanLinnwouldliketothankHeather for her support,encouragement,andadviceas well ashisfamilyandfriendsfor their supportandfor puttingupwiththelonghours
andinfrequentcommunicationwhilethebookwascomingtogether.
ThanksalsogoouttoEdSkoudisfor pushingmetodoawesomethings,andtoHD, Egypt,Nate,Shawn,andall theother friendsandfamilywhohaveofferedcode assistance,guidance,andsupportwhenI’veneededitthemost.
StephenSimswouldliketothankhiswifeLeAnneanddaughter Audreyfor their ongoingsupportwiththetimeneededtoresearch,write,work,teach,andtravel.
Hewouldalsoliketothankhisparents,GeorgeandMary,andsister,Lisa,for their supportfromafar.Finally,aspecial thankstoall ofthebrilliantsecurityresearchers whocontributesomuchtothecommunitywithpublications,lectures,andtools.
ChrisEagle wouldliketothankhiswifeKristenfor beingtherockthatallowshimto doall ofthethingshedoes.Noneofitwouldbepossiblewithouther continuedsupport.
LindaMartinez wouldliketothankher momanddadfor beingtrulydelightful peopleandalwayssettingagreatexampletofollow.Lindawouldalsoliketothankher daughter Elysiafor theyearsofencouragementthatallowedher topursueher passions.
Abigthankstomyfriendsandsomeofthebrightestmindsintheindustry Allen, Zack,Rob,Ryan,Bill,andShon,maysherestinpeace.
MichaelBaucomwouldliketothankhiswife,Bridget,anddaughter,Tiernan,for their sacrificesandsupportinallowinghimtopursuehisprofessional goals.
I’dalsoliketothankmyparentsfor your love,support,andinstillinginmethework ethicthathascarriedmetothispoint.Additionally,I’dliketothanktheMarineCorps for givingmethecourageandconfidencetounderstandthatall thingsarepossible. Finally,I’dliketothankmybrother inChrist,long-timefriend,andcolleague,Allen Harper.Nothingcanbeaccomplishedwithoutagreatteam.
We,the authors,wouldalsoliketocollectivelythankHex-Raysfor thegeneroususe oftheir tool,IDAPro.
INTRODUCTION Historyteachesthatwarsbeginwhengovernmentsbelievethepriceofaggression ischeap.
RonaldReagan
Youcan’tsaycivilizationdon’tadvance…ineverywar theykill youinanew way. Will Rogers
Thesupremeartofwar istosubduetheenemywithoutfighting.
Thepurposeofthisbookistoprovideindividualstheinformationonceheldonlyby governmentsandafew blackhathackers.Inthisdayandage,individualsstandinthe breachofcyberwar,notonlyagainstblackhathackers,butsometimesagainst governments.Ifyoufindyourselfinthisposition,either aloneor asadefender ofyour organization,wewantyoutobeequippedwithasmuchknowledgeoftheattacker as possible.Tothatend,wesubmittoyouthemindsetofthegrayhathacker,anethical hacker thatusesoffensivetechniquesfor defensivepurposes.Theethical hacker always respectslawsandtherightsofothers,butbelievestheadversarymaybebeattothe punchbytestingoneselffirst.
Theauthorsofthisbookwanttoprovideyou,thereader,withsomethingwebelieve theindustryandsocietyingeneral needs: aholisticreview ofethical hackingthatis responsibleandtrulyethical initsintentionsandmaterial.Thisiswhywekeep releasingnew editionsofthisbookwithaclear definitionofwhatethical hackingisand isnot somethingour societyisveryconfusedabout.
Wehaveupdatedthematerial fromthefourtheditionandhaveattemptedtodeliver the mostcomprehensiveandup-to-dateassemblyoftechniques,procedures,andmaterial withreal hands-onlabsthatcanbereplicatedbythereaders.Thirteennew chaptersare presented,andtheother chaptershavebeenupdated.
InPartI,weprepareyoufor thebattlewithall thenecessarytoolsandtechniquesto getthebestunderstandingofthemoreadvancedtopics.Thissectionmovesquite quicklybutisnecessaryfor thosejuststartingoutinthefieldandotherslookingtomove tothenextlevel.Thissectioncoversthefollowing:
SunTzu
• White,black,andgrayhatdefinitionsandcharacteristics
• Theslipperyethical issuesthatshouldbeunderstoodbeforecarryingoutanytype ofethical hackingactivities
• Programmingsurvival skills,whichisamust-haveskill for agrayhathacker tobe abletocreateexploitsor review sourcecode
• Fuzzing,whichisawonderful skill for finding0-dayexploits
• Reverseengineering,whichisamandatoryskill whendissectingmalwareor researchingvulnerabilities
• Exploitingwithsoftware-definedradios
InPartII,wediscussthebusinesssideofhacking.Ifyouarelookingtomovebeyond hackingasahobbyandstartpayingthebills,thissectionisfor you.Ifyouarea seasonedhackingprofessional,wehopetooffer youafew tipsaswell.Inthissection, wecover someofthesofter skillsrequiredbyanethical hacker tomakealiving:
• How togetintothepenetrationtestingbusiness
• How toimprovetheenterprisesecurityposturethroughredteaming
• Anovel approachtodevelopingapurpleteam
• Bugbountyprogramsandhow togetpaidfindingvulnerabilities,ethically
InPartIII,wediscusstheskillsrequiredtoexploitsystems.Eachofthesetopicshas beencoveredbefore,buttheoldexploitsdon’tworkanymore;therefore,wehave updatedthediscussionstoworkpastsystemprotections.Wecover thefollowingtopics inthissection:
• How togainshell accesswithoutexploits
• BasicandadvancedLinuxexploits
• BasicandadvancedWindowsexploits
• UsingPowerShell toexploitsystems
• Modernwebexploits
• Usingpatchestodevelopexploits
InPartIV,wecover advancedmalwareanalysis.Inmanyways,thisisthemost advancedtopicinthefieldofcybersecurity.Onthefrontlinesofcyberwar ismalware, andweaimtoequipyouwiththetoolsandtechniquesnecessarytoperformmalware analysis.Inthissection,wecover thefollowing:
• Mobilemalwareanalysis
• Recentransomwareanalysis
• ATMmalwareanalysis
• Usingnext-generationhoneypotstofindadvancedattackersandmalwareinthe network
Finally,inPartV,weareproudtodiscussthetopicofInternetofThings(IoT) hacking.TheInternetofThingsisexplodingand,unfortunately,soarethevulnerabilities therein.Inthissection,wediscusstheselatesttopics:
• InternetofThingstobehacked
• Dissectingembeddeddevices
• Exploitingembeddeddevices
• MalwareanalysisofIoTdevices
Wedohopeyouwill seethevalueofthenew contentthathasbeenprovidedandwill alsoenjoythenewlyupdatedchapters.Ifyouarenew tothefieldor readytotakethe nextsteptoadvanceanddeepenyour understandingofethical hacking,thisisthebook for you.
NOTE Toensureyour systemisproperlyconfiguredtoperformthelabs,wehave providedthefilesyouwill need.Thelabmaterialsanderratamaybedownloadedfrom either theGitHubrepositoryathttps://github.com/GrayHatHacking/GHHv5or the publisher’ssite,atwww.mhprofessional.com.
PARTI Preparation Chapter1 WhyGrayHatHacking?EthicsandLaw
Chapter2 ProgrammingSurvival Skills
Chapter3 Next-GenerationFuzzing
Chapter4 Next-GenerationReverseEngineering
Chapter5 Software-DefinedRadio
WhyGrayHatHacking?Ethicsand Law Thepurposeofthisbookistosupportindividualswhowanttorefinetheir ethical hackingskillstobetter defendagainstmaliciousattackers.Thisbookisnotwrittentobe usedasatool bythosewhowishtoperformillegal andunethical activities. Inthischapter,wediscussthefollowingtopics:
• Know your enemy: understandingyour enemy’stactics
• Thegrayhatwayandtheethical hackingprocess
• Theevolutionofcyberlaw
KnowYourEnemy “Wecannotsolveour problemswiththesamelevel ofthinkingthatcreatedthem.”
AlbertEisenstein
Thesecuritychallengeswefacetodaywill paleincomparisontothosewe’ll faceinthe future.Wealreadyliveinaworldsohighlyintegratedwithtechnologythat cybersecurityhasanimpactonour financial markets,our elections,our families,and our healthcare.Technologyisadvancingandthethreatlandscapeisincreasing.Onthe onehand,vehiclesthatarecapableofautonomousdrivingarebeingmass-producedas smartcitiesarebeingdeveloped.Ontheother hand,hospitalsarebeingheldfor ransom,power gridsarebeingshutdown,intellectual propertyandsecretsarebeing stolen,andcybercrimeisaboomingindustry.Inorder todefendandprotectour assets andour people,wemustunderstandtheenemyandhow theyoperate.Understanding how attacksareperformedisoneofthemostchallengingandimportantaspectsof defendingthetechnologyonwhichwerely.After all,how canwepossiblydefend ourselvesagainsttheunknown?
Thisbookwaswrittentoproviderelevantsecurityinformationtothosewhoare dedicatedtostoppingcyberthreats.Theonlywaytoaddresstodayandtomorrow’s