
۴۴٬۰۰۰تومان
نوع فایل دانلود: EPUB
پس از خرید، یک فایل EPUB دریافت میکنید.
این فایل با Calibre، Apple Books و سایر کتابخوانهای دیجیتال مناسب است.
ویژگیهای کلیدی
* یاد بگیرید چطور با مهارتهای اسکریپتنویسی پایتون، یک سیستم کامپیوتری، شبکه و برنامهٔ وب را تست نفوذ کنید
* در هنر ارزیابی آسیبپذیریها با انجام آزمون نفوذ مؤثر مهارت پیدا کنید
* این راهنمای جامع به شما یاد میدهد چطور با پایتون از سیستمهایتان در برابر حملات سایبری پیچیده محافظت کنید
توضیح کتاب
آزمون نفوذ یعنی بررسی یک سیستم کامپیوتری، شبکه یا برنامهٔ وب برای پیدا کردن نقاط ضعف امنیتی که مهاجم میتواند از آنها سوءاستفاده کند. کتاب «آزمون نفوذ مؤثر با پایتون» به شما کمک میکند با مهارتهای اسکریپتنویسی پایتون، شبکههایتان را در برابر حملات سایبری ایمن نگه دارید.
ابتدا نگاهی کلی به اسکریپتنویسی پایتون و آزمون نفوذ میاندازیم. یاد میگیرید با نوشتن اسکریپتهای Scapy ترافیک شبکه را تحلیل کنید و با کتابخانههایی مثل ProxMon و Spynner، برنامههای وب را انگشتنگاری کنید.
سپس میبینید چطور اسکریپتهای حملهٔ پایه بنویسید و با کتابخانههای پایتون مهارتهای دیباگ و مهندسی معکوس را تقویت کنید. در پایان کتاب هم یاد میگیرید چطور از جعبهابزارهای رمزنگاری در پایتون استفاده کنید و ابزارها و کتابخانههای پایتون را خودکار کنید.
آنچه یاد میگیرید
* نوشتن اسکریپتهای Scapy برای بررسی ترافیک شبکه
* آشنایی با تکنیکهای انگشتنگاری برنامه با پایتون
* درک تکنیکهای اسکریپتنویسی حمله
* نوشتن ابزارهای فازینگ متناسب با نیاز آزمون نفوذ
* یادگیری روشهای پایهٔ اسکریپتنویسی حمله
* استفاده از جعبهابزارهای رمزنگاری در پایتون
* خودکارسازی آزمون نفوذ با ابزارها و کتابخانههای پایتون
دربارهٔ نویسنده
**ریجاه رحیم** در حال حاضر معمار امنیت در FAYA India است و سالهاست حامی نرمافزار متنباز بوده. او از مشارکتکنندگان ثابت بنیاد موزیلاست و نامش روی بنای یادبود سانفرانسیسکو که بنیاد موزیلا ساخته، آمده است.
او عضو هیئت بررسی افزونههای موزیلاست و در توسعهٔ چند ماژول نود هم نقش داشته. هشت افزونهٔ موزیلا ساخته که از جملهٔ آنها Clear Console است؛ افزونهای بسیار موفق که بهعنوان یکی از بهترین افزونههای موزیلا در سال ۲۰۱۳ انتخاب شد. این افزونه بیش از ۴۴ هزار کاربر دارد و تا امروز بیش از ۶۹۰ هزار بار دانلود شده است. او همچنین اولین بستهٔ مرورگر تست امنیت از نوع خود در جهان را ساخته: PenQ؛ یک بستهٔ مرورگر متنباز مبتنی بر لینوکس برای آزمون نفوذ که از قبل با ابزارهایی برای خزیدن وب، جستجوی پیشرفته، انگشتنگاری و موارد مشابه پیکربندی شده است.
ریجاه عضو فعال OWASP و رهبر شعبهٔ OWASP Kerala هم هست. او سخنران فعال FAYA:80 هم هست؛ یکی از نشستهای ماهانهٔ مهم فناوری در تکنوپارک کرالا. علاوه بر فعالیت فعلیاش در بخش امنیت سایبری FAYA و سابقهٔ کار در QBurst، شیفتهٔ خودکارسازی فرایندهاست و آن را در FAYA پیاده کرده. همچنین بهعنوان فرماندهٔ معاون در Cyberdome، ابتکار ادارهٔ پلیس کرالا، داوطلبانه فعالیت میکند.
فهرست مطالب
1. مبانی اسکریپتنویسی پایتون
2. تحلیل ترافیک شبکه با Scapy
3. انگشتنگاری برنامه با پایتون
4. اسکریپتنویسی حمله با پایتون
5. فازینگ و حملهٔ جستجوی فراگیر
6. دیباگ و مهندسی معکوس
7. توابع رمزنگاری، درهمسازی و تبدیل
8. ثبت کلیدها و گرفتن تصویر صفحه
9. خودکارسازی حمله
10. نگاه به آینده
Key Features* Learn to utilize your Python scripting skills to pentest a computer system, network, and web-application* Get proficient at the art of assessing vulnerabilities by conducting effective penetration testing* This is the ultimate guide that teaches you how to use Python to protect your systems against sophisticated cyber attacksBook DescriptionPenetration testing is a practice of testing a computer system, network, or web application to find weaknesses in security that an attacker can exploit. Effective Python Penetration Testing will help you utilize your Python scripting skills to safeguard your networks from cyberattacks.We will begin by providing you with an overview of Python scripting and penetration testing. You will learn to analyze network traffic by writing Scapy scripts and will see how to fingerprint web applications with Python libraries such as ProxMon and Spynner.Moving on, you will find out how to write basic attack scripts, and will develop debugging and reverse engineering skills with Python libraries. Toward the end of the book, you will discover how to utilize cryptography toolkits in Python and how to automate Python tools and libraries.What you will learn* Write Scapy scripts to investigate network traffic* Get to know application fingerprinting techniques with Python* Understand the attack scripting techniques* Write fuzzing tools with pentesting requirements* Learn basic attack scripting methods* Utilize cryptographic toolkits in Python* Automate pentesting with Python tools and librariesAbout the Author**Rejah Rehim** is currently a security architect with FAYA India and is a long-time preacher of open source. He is a steady contributor to the Mozilla Foundation, and his name has been featured on the San Francisco Monument made by the Mozilla Foundation.He is a part of the Mozilla add-on review board and has contributed to the development of several node modules. He has to his credit the creation of eight Mozilla add-ons, including the highly successful Clear Console add-on, which was selected as one of the best Mozilla add-ons of 2013. With a user base of more than 44,000, it has registered more than 6,90,000 downloads to date. He has successfully created the world's first, one-of-a-kind security testing browser bundle, PenQ, an open source Linux-based penetration testing browser bundle preconfigured with tools for spidering, advanced web searching, fingerprinting, and so on.Rejah is also an active member of OWASP and is the chapter leader of OWASP Kerala. He is also an active speaker at FAYA:80, one of the premier monthly tech rendezvous in Technopark, Kerala. Besides being a part of the cyber security division of FAYA currently and QBurst in the past, Rejah is also a fan of process automation and has implemented it in FAYA. In addition to these, Rejah also volunteers with Cyberdome, an initiative of the Kerala police department, as Deputy Commander.Table of Contents1. Python Scripting Essentials2. Analyzing Network Traffic with Scapy3. Application Fingerprinting with Python4. Attack Scripting with Python5. Fuzzing and Brute-Forcing6. Debugging and Reverse Engineering7. Crypto, Hash, and Conversion Functions8. Keylogging and Screen Grabbing9. Attack Automation10. Looking Forward