Linux and Unix Complete Handbook

Author: Nitesh Dhanjani
Publisher:
Publish Date: 2005-04-01
Features: This book will tell you how hackers think so that you can find ways to protect Unix and Linux systems from their attacks. This is the only way to know how to prevent your system from being compromised. To stop experienced hackers, we need to understand their thought process, techniques, and strategies. The powerful nature of Unix and Linux operating systems is a double-edged sword. In most cases, the source code of the operating system kernel is freely available, and administrators can make significant changes to the kernel to meet their needs. However, the powerful and flexible nature of Unix and Linux contains a lot of complexity, increasing the likelihood of dangerous misconfigurations that can easily put the system at risk. We also need to consider the differences among the various Unix and Linux release versions available today. Each version is tied to its own set of security policies and configurations. For example, some release versions disable a set of remote services, while others enable all possible services with weak security policies. Hackers are aware of the complexity of managing Unix and Linux hosts and exactly know how to exploit them. The clever hacker strategies introduced in this book will surprise you, and it will also teach you how to defend against these hacker attacks. Don’t worry about hackers mastering the information provided in this book, because they already know this material. The purpose of this book is to disclose the attack strategies currently used by hackers, so you can learn how to counter them. Once you understand how hackers think and the various methods they use to infiltrate systems, the situation will be in your favor. This book will tell you how hackers think so that you can find ways to protect Unix and Linux systems from their attacks. This is the only way to know how to prevent your system from being compromised. To stop experienced hackers, we need to understand their thought process, techniques, and strategies. The powerful nature of Unix and Linux operating systems is a double-edged sword. In most cases, the source code of the operating system kernel is freely available, and administrators can make significant changes to the kernel to meet their needs. However, the powerful and flexible nature of Unix and Linux contains a lot of complexity, increasing the likelihood of dangerous misconfigurations that can easily put the system at risk. We also need to consider the differences among the various Unix and Linux release versions available today. Each version is tied to its own set of security policies and configurations. For example, some release versions disable a set of remote services, while others enable all possible services with weak security policies. Hackers are aware of the complexity of managing Unix and Linux hosts and exactly know how to exploit them. The clever hacker strategies introduced in this book will surprise you, and it will also teach you how to defend against these hacker attacks. Don’t worry about hackers mastering the information provided in this book, because they already know this material. The purpose of this book is to disclose the attack strategies currently used by hackers, so you can learn how to counter them. Once you understand how hackers think and the various methods they use to infiltrate systems, the situation will be in your favor.
Organization of the Book This book is divided into four main parts: Part I: Hacker Intrusion Techniques and Defenses This part of the book discusses the intrusion techniques currently widely used by hackers and introduces defense techniques against all the intrusion techniques described in these chapters. In Chapter 1, we start with the logical step of tracking: understanding how hackers gather publicly available information through search engines, registration records, DNS records, and more. Once they have gathered all the information from public resources, they begin the actual identification and scanning of networks and hosts. In Chapter 2, this chapter tells you how to determine which hosts are running in a network and the ports they are open on. We will discuss different methods of port scanning, as well as operating system identification techniques and tools. In Chapter 3, learn how hackers identify applications and services running on remote hosts. This chapter will introduce various tools and methods used by potential intruders to enumerate usernames and remote services. In Chapter 4, this chapter discloses the specific tools and strategies hackers use to gain access to vulnerable hosts. Learn the clever techniques used by hackers, such as brute force cracking, sniffing, man-in-the-middle attacks, password cracking, port redirection, and exploiting misconfigurations, buffer overflows, and other software system security vulnerabilities. In Chapter 5, exploiting specific vulnerabilities often allows hackers to gain the privileges of a non-privileged user or system account. In these cases, the next step for hackers is to obtain superuser (root) privileges. This chapter shows the various methods hackers use to attempt to gain higher-level privileges. In Chapter 6, once a host is compromised, hackers want to hide their presence and ensure continuous and privileged access to the host. This chapter tells you how hackers hide their traces by clearing important logs and how they install trojan horses, backdoors, and rootkit attack tools on the compromised target host.
Part II: Host Security Hardening
This second part of the book focuses on the multiple steps system administrators can take to harden default system configurations and policies. In Chapter 7, this chapter discusses important configuration issues related to hardening default application and server configurations. We encourage all system administrators to consider the recommendations in this chapter to prevent intruders from attacking weak system policies and configurations. In Chapter 8, malicious users and hackers often exploit improper user and file system permissions. This chapter will introduce UNIX and LINUX file permissions and describe the exact steps to defend against intrusions caused by poor user and file permissions. In Chapter 9, every system administrator should implement proper system event logging. This chapter teaches you how to enable and configure useful logging services and how to set permissions correctly on log files to prevent them from being tampered with. It is also important to download new security patches in a timely manner, and this chapter provides useful links to official websites where you can obtain this information.
Part III: Special Topics
This third part of the book covers several exciting topics, including writing plugins for the Nessus scanner, wireless intrusion, and intrusion using a Zaurus PDA. In Chapter 10, Nessus is a currently popular vulnerability scanning tool. It is free and designed to be modular. This chapter teaches you how to use NASL (Nessus Attack Script Language) to write custom security vulnerability check plugins for the Nessus scanner. In Chapter 11, learn how hackers infiltrate 802.11 wireless networks. This chapter discusses the weaknesses of the WEP protocol and introduces the tools used by hackers to infiltrate wireless networks. Additionally, this chapter offers some suggestions on how to better protect wireless networks. In Chapter 12, the Sharp Zaurus PDA device runs an embedded Linux operating system. This chapter shows you the various security tools used for the Zaurus PDA and how they are easily exploited by hackers to infiltrate wireless networks.
Reference Center
This part is arranged at the end of the book for easy reference. When you need quick information about common commands, common ports, online resources, IP addresses, and useful Netcat commands, remember to flip to this part of the book. Additionally, this part also provides ASCII values and HTTP response tables.
Words for Readers
The author has put a lot of effort into writing this book. We hope readers can find valuable information in the book. What is important is that readers use the information provided in this book to protect their own systems and networks from experienced hackers.

📌 Related Posts