
۴۴٬۰۰۰تومان
نوع فایل دانلود: EPUB
پس از خرید، یک فایل EPUB دریافت میکنید.
این فایل با Calibre، Apple Books و سایر کتابخوانهای دیجیتال مناسب است.
پیشگفتار
این کتاب برای چه کسانی است
این کتاب چه موضوعاتی را پوشش میدهد
برای بیشترین بهره از این کتاب
تماس با ما
بخش ۱: محیط پایتون و ابزارهای برنامهنویسی سیستم
کار با اسکریپتنویسی پایتون
الزامات فنی
آشنایی با ساختارهای داده و مجموعهها در پایتون
لیستهای پایتون
افزودن عنصر به لیست
برعکس کردن لیست
جستجوی عنصر در لیست
تاپلهای پایتون
دیکشنریهای پایتون
حذف یک آیتم از دیکشنری در پایتون
کار با توابع، کلاسها و اشیاء در پایتون
توابع پایتون
کلاسهای پایتون
وراثت در پایتون
مزایای وراثت در پایتون
کار با فایلها در پایتون
خواندن و نوشتن فایل در پایتون
آشنایی با مدیریت استثناها در پایتون
ماژولها و پکیجهای پایتون
ماژول در پایتون چیست؟
چگونه ماژولها را در پایتون وارد کنیم
گرفتن اطلاعات از ماژولها
تفاوت ماژول و پکیج در پایتون
مدیریت پارامترها در پایتون
مدیریت پارامترها با OptionParser
مدیریت وابستگیها و محیطهای مجازی
مدیریت وابستگیها در یک پروژه پایتون
نصب ماژولهای پایتون
ساخت فایل requirements.txt
کار با محیطهای مجازی
پیکربندی virtualenv
محیطهای توسعه برای اسکریپتنویسی پایتون
راهاندازی محیط توسعه
اشکالزدایی با Python IDLE
PyCharm
اشکالزدایی با PyCharm
خلاصه
پرسشها
مطالعه بیشتر
پکیجهای برنامهنویسی سیستم
الزامات فنی
تعامل با سیستمعامل در پایتون
کار با فایلسیستم در پایتون
کار با فایلها و پوشهها
خواندن فایل ZIP با پایتون
اجرای دستورات با ماژول subprocess
راهاندازی virtualenv با subprocess
مدیریت نخها در پایتون
ساخت یک نخ ساده
کار با ماژول threading
چندپردازشی در پایتون
چندنخی و همزمانی در پایتون
چندنخی در پایتون
همزمانی در پایتون با ThreadPoolExecutor
اجرای ThreadPoolExecutor با context manager
خلاصه
پرسشها
مطالعه بیشتر
بخش ۲: اسکریپتنویسی شبکه و شنود بستهها با پایتون
برنامهنویسی سوکت
الزامات فنی
آشنایی با پکیج socket برای درخواستهای شبکه
سوکتهای شبکه در پایتون
ماژول socket
متدهای سوکت سرور و کلاینت
جمعآوری اطلاعات با سوکتها
مدیریت استثناهای سوکت
کلاینت ساده با ماژول socket
اسکن پورت با سوکتها
پیادهسازی یک پورتاسکنر
پورتاسکنر پیشرفته
پیادهسازی reverse shell با سوکتها
پیادهسازی کلاینت و سرور ساده TCP
پیادهسازی سرور و کلاینت با سوکتها
پیادهسازی سرور TCP
پیادهسازی کلاینت TCP
پیادهسازی کلاینت و سرور ساده UDP
پیادهسازی سرور UDP
پیادهسازی کلاینت UDP
پیادهسازی سرور HTTP در پایتون
تست سرور HTTP
ارسال فایل از طریق سوکتها
پیادهسازی سوکتهای امن با ماژولهای TLS و SSL
خلاصه
پرسشها
مطالعه بیشتر
برنامهنویسی HTTP و احراز هویت وب
الزامات فنی
ساخت کلاینت HTTP با urllib.request
آشنایی با پروتکل HTTP
آشنایی با ماژول urllib
گرفتن هدرهای درخواست و پاسخ
استخراج ایمیل از یک URL با urllib.request
دانلود فایل با urllib.request
مدیریت استثناها با urllib.request
ساخت کلاینت HTTP با requests
گرفتن تصاویر و لینکها از یک URL با requests
ارسال درخواست با REST API
مدیریت پروکسی با requests
مدیریت استثناها با requests
سازوکارهای احراز هویت با پایتون
احراز هویت پایه HTTP با ماژول requests
احراز هویت digest با ماژول requests
پیادهسازی کلاینتهای OAuth در پایتون با ماژول requests-oauthlib
نقشهای OAuth
گردش کار OAuth
پیادهسازی کلاینت با requests_oauthlib
پیادهسازی JSON Web Tokenها (JWT) در پایتون
JSON Web Token چگونه کار میکند؟
کار با PyJWT
خلاصه
پرسشها
مطالعه بیشتر
تحلیل ترافیک شبکه و شنود بستهها
الزامات فنی
گرفتن و تزریق بسته با pcapy-ng
گرفتن بسته با pcapy-ng
خواندن هدرها از بستهها
خواندن فایلهای pcap با pcapy-ng
گرفتن و تزریق بسته با scapy
معرفی scapy
دستورات scapy
ارسال بسته با scapy
کشف شبکه با scapy
اسکن پورت و traceroute با scapy
اسکن پورت با scapy
Traceroute با scapy
خواندن فایلهای pcap با scapy
خواندن درخواستهای DHCP
نوشتن فایل pcap
شنود بسته با scapy
پزشکی قانونی شبکه با scapy
کار با scapy برای تشخیص حملات ARP spoofing
تشخیص حملات جعلی ARP با Scapy
خلاصه
پرسشها
مطالعه بیشتر
بخش ۳: اسکریپتنویسی سرور و اسکن پورت با پایتون
جمعآوری اطلاعات از سرورها با ابزارهای OSINT
الزامات فنی
معرفی هوش منبعباز (OSINT)
Google Dorks و پایگاه داده Google Hacking
Maltego
Photon
The Harvester
Censys
crt.sh
DnsDumpster
WaybackMachine
چارچوب OSINT
Blackbird
موتور جستجوی Shodan
موتور جستجوی BinaryEdge
گرفتن اطلاعات با Google Dorks
Google Dorks
Katana: ابزاری پایتونی برای Google Hacking
Dorks hunter
گرفتن اطلاعات با SpiderFoot
ماژولهای SpiderFoot
گرفتن اطلاعات درباره سرورهای DNS با DNSPython و DNSRecon
پروتکل DNS
ماژول DNSPython
DNSRecon
یافتن آدرسهای آسیبپذیر در سرورها با fuzzing
فرآیند fuzzing
Web fuzzing
آشنایی با پروژه FuzzDB و استفاده از آن
شناسایی صفحات ورود قابل پیشبینی با پروژه FuzzDB
کشف تزریق SQL با پروژه FuzzDB
Wfuzz
خلاصه
پرسشها
مطالعه بیشتر
تعامل با سرورهای FTP، SFTP و SSH
الزامات فنی
اتصال به سرورهای FTP
پروتکل FTP
استفاده از ماژول ftplib پایتون
انتقال فایل با FTP
سایر توابع ftplib
استفاده از ftplib برای حمله brute-force به اطلاعات کاربری FTP
ساخت یک اسکنر FTP ناشناس با پایتون
اتصال به سرورهای SSH با paramiko و pysftp
اجرای سرور SSH روی Debian Linux
معرفی ماژول paramiko
برقراری اتصال SSH با paramiko
استفاده از AutoAddPolicy
اجرای دستورات با paramiko
استفاده از paramiko برای حمله brute-force به اطلاعات کاربری SSH
برقراری اتصال SSH با pysftp
پیادهسازی سرور SSH با paramiko
بررسی امنیت سرورهای SSH
نصب و اجرای ssh-audit
Rebex SSH Check
خلاصه
پرسشها
مطالعه بیشتر
کار با اسکنر Nmap
الزامات فنی
معرفی اسکن پورت با Nmap
انواع اسکن با nmap
اسکن پورت با python-nmap
استخراج اطلاعات با nmap
اسکن همزمان و ناهمزمان با python-nmap
پیادهسازی اسکن همزمان
پیادهسازی اسکن ناهمزمان
کشف سرویسها و آسیبپذیریها با اسکریپتهای Nmap
اجرای اسکریپتهای Nmap برای کشف سرویسها
اجرای اسکریپتهای Nmap برای کشف آسیبپذیریها
تشخیص آسیبپذیریها با اسکریپت Nmap-vulners
تشخیص آسیبپذیریها با اسکریپت Nmap-vulscan
اسکن پورت از طریق سرویسهای آنلاین
اسکنر پورت Scanless
خلاصه
پرسشها
مطالعه بیشتر
بخش ۴: آسیبپذیریهای سرور و امنیت در برنامههای وب
تعامل با اسکنرهای آسیبپذیری
الزامات فنی
معرفی اسکنر آسیبپذیری OpenVAS
نصب اسکنر آسیبپذیری OpenVAS
آشنایی با رابط وب
اسکن یک هدف با OpenVAS
ایجاد هدف
ایجاد وظیفه
تحلیل گزارشها
پایگاههای داده آسیبپذیریها
دسترسی به OpenVAS با پایتون
معرفی OWASP ZAP بهعنوان ابزار تست امنیتی خودکار
استفاده از OWASP ZAP
تعامل با OWASP ZAP با پایتون
WriteHat بهعنوان ابزار گزارشدهی تست نفوذ
خلاصه
پرسشها
مطالعه بیشتر
تعامل با آسیبپذیریهای سرور در برنامههای وب
الزامات فنی
آشنایی با آسیبپذیریها در برنامههای وب با OWASP
تست آسیبپذیریهای Cross-Site Scripting (XSS)
تحلیل و کشف آسیبپذیریها در برنامههای وب مبتنی بر CMS
استفاده از CMSmap
Vulnx بهعنوان اسکنر CMS
کشف آسیبپذیریها در برنامههای سرور Tomcat
نصب سرور Tomcat
تست سرور Tomcat با ApacheTomcatScanner
یافتن سرورهای آسیبپذیر Tomcat در موتور جستجوی Censys
اسکن آسیبپذیریها با اسکنر پورت Nmap
کشف آسیبپذیریهای SQL با ابزارهای پایتون
معرفی تزریق SQL
شناسایی وبسایتهای آسیبپذیر در برابر تزریق SQL
معرفی sqlmap
استفاده از sqlmap برای تست وبسایت از نظر آسیبپذیری تزریق SQL
اسکن آسیبپذیریهای تزریق SQL با sqlifinder
اسکن آسیبپذیریهای تزریق SQL با اسکنر پورت Nmap
خودکارسازی فرآیند تشخیص آسیبپذیریها در برنامههای وب
تشخیص آسیبپذیری open redirect
تشخیص آسیبپذیریها با Fuxploider
خلاصه
پرسشها
مطالعه بیشتر
دریافت اطلاعات از پایگاههای داده آسیبپذیریها
الزامات فنی
شناسایی و درک آسیبپذیریها و اکسپلویتها
اکسپلویت چیست؟
فرمتهای آسیبپذیری
جستجوی آسیبپذیریها در NVD
معرفی NVD متعلق به NIST
جستجوی آسیبپذیریها
جستجوی آسیبپذیریها در پایگاه داده Vulners
جستجوی آسیبپذیریها با Pompem
خلاصه
پرسشها
مطالعه بیشتر
بخش ۵: پزشکی قانونی با پایتون
استخراج موقعیت جغرافیایی و فراداده از اسناد، تصاویر و مرورگرها
الزامات فنی
استخراج اطلاعات موقعیت جغرافیایی
ماژولهای پایتون برای استخراج اطلاعات موقعیت جغرافیایی
استخراج فراداده از تصاویر
معرفی EXIF و ماژول PIL
گرفتن داده EXIF از یک تصویر
استخراج فراداده از اسناد PDF
استخراج فراداده با PyPDF2
استخراج فراداده با PyMuPDF
شناسایی فناوری استفادهشده توسط یک وبسایت
Wappalyzer
WebApp Information Gatherer (WIG)
استخراج فراداده از مرورگرهای وب
پزشکی قانونی فایرفاکس با پایتون
پزشکی قانونی کروم با پایتون
پزشکی قانونی کروم با Hindsight
خلاصه
پرسشها
مطالعه بیشتر
ابزارهای پایتون برای حملات brute-force
الزامات فنی
سازندگان دیکشنری برای حملات brute-force
تولید دیکشنری brute-force با pydictor
تولیدکننده فهرست رمز عبور
ابزارهای حمله brute-force در پایتون
بهدستآوردن زیردامنهها با brute force
حملات brute-force با BruteSpray
حملات brute-force با Cerbrutus
اجرای حملات brute-force برای برنامههای وب
اجرا روی یک سایت WordPress
اجرای حملات brute-force برای فایلهای ZIP
کار با فایلهای ZIP در پایتون
اجرای حملات brute-force برای فایلهای ZIP محافظتشده با رمز عبور
خلاصه
پرسشها
مطالعه بیشتر
رمزنگاری و مبهمسازی کد
الزامات فنی
مقدمهای بر رمزنگاری
رمزگذاری و رمزگشایی اطلاعات با pycryptodome
معرفی pycryptodome
رمزگذاری و رمزگشایی با الگوریتم DES
رمزگذاری و رمزگشایی با الگوریتم AES
تولید امضاهای RSA با pycryptodome
رمزگذاری و رمزگشایی اطلاعات با cryptography
معرفی ماژول cryptography
رمزگذاری متقارن با پکیج fernet
رمزگذاری متقارن با پکیج ciphers
تولید امن کلیدها با ماژولهای secrets و hashlib
تولید امن کلیدها با ماژول secrets
تولید امن کلیدها با ماژول hashlib
بررسی یکپارچگی یک فایل
ابزارهای پایتون برای مبهمسازی کد
مبهمسازی کد با pyarmor
خلاصه
پرسشها
مطالعه بیشتر
ارزیابیها – پاسخ پرسشهای پایان فصل
کتابهای دیگری که ممکن است بپسندید
PrefaceWho this book is forWhat this book coversTo get the most out of this bookGet in touchSection 1: Python Environment and System Programming ToolsWorking with Python ScriptingTechnical requirementsLearn about data structures and collections in PythonPython listsAdding elements to a listReversing a listSearching elements in a listPython tuplesPython dictionariesRemove an item from a dictionary in PythonWorking with functions, classes, and objects in PythonPython functionsPython classesPython inheritanceAdvantages of Python inheritanceWorking with files in PythonReading and writing files in PythonLearn and understand exceptions management in PythonPython modules and packagesWhat is a module in Python?How to import modules in PythonGetting information from modulesDifference between a Python module and a Python packageManaging parameters in PythonManaging parameters with OptionParserManaging dependencies and virtual environmentsManaging dependencies in a Python projectInstall Python modulesGenerating the requirements.txt fileWorking with virtual environmentsConfiguring virtualenvDevelopment environments for Python scriptingSetting up a development environmentDebugging with Python IDLEPyCharmDebugging with PyCharmSummaryQuestionsFurther readingSystem Programming PackagesTechnical requirementsInteract with the operating system in PythonWorking with the filesystem in PythonWorking with files and directoriesReading a ZIP file using PythonExecuting commands with the subprocess moduleSetting up a virtualenv with subprocessManaging threads in PythonCreating a simple threadWorking with the threading moduleMultiprocessing in PythonMultithreading and concurrency in PythonMultithreading in PythonConcurrency in Python with ThreadPoolExecutorExecuting ThreadPoolExecutor with a context managerSummaryQuestionsFurther readingSection 2: Network Scripting and Packet Sniffing with PythonSocket ProgrammingTechnical requirementsUnderstanding the socket package for network requestsNetwork sockets in PythonThe socket moduleServer and client socket methodsGathering information with socketsManaging socket exceptionsBasic client with the socket modulePort scanning with socketsImplementing a port scannerAdvanced port scannerImplementing a reverse shell with socketsImplementing a simple TCP client and TCP serverImplementing a server and client with socketsImplementing the TCP serverImplementing the TCP clientImplementing a simple UDP client and UDP serverImplementing the UDP serverImplementing the UDP clientImplementing an HTTP server in PythonTesting the HTTP serverSending files via socketsImplementing secure sockets with the TLS and SSL modulesSummaryQuestionsFurther readingHTTP Programming and Web AuthenticationTechnical requirementsBuilding an HTTP client with urllib.requestIntroducing the HTTP protocolIntroducing the urllib moduleGet request and response headersExtracting emails from a URL with urllib.requestDownloading files with urllib.requestHandling exceptions with urllib.requestBuilding an HTTP client with requestsGetting images and links from a URL with requestsMaking requests with the REST APIManaging a proxy with requestsManaging exceptions with requestsAuthentication mechanisms with PythonHTTP basic authentication with the requests moduleHTTP digest authentication with the requests moduleImplementing OAuth clients in Python with the requests-oauthlib moduleOAuth rolesOAuth workflowImplementing a client with requests_oauthlibImplementing JSON Web Tokens (JWTs) in PythonHow does a JSON Web Token work?Working with PyJWTSummaryQuestionsFurther readingAnalyzing Network Traffic and Packet SniffingTechnical requirementsCapturing and injecting packets with pcapy-ngCapturing packets with pcapy-ngReading headers from packetsReading pcap files with pcapy-ngCapturing and injecting packets with scapyIntroduction to scapyScapy commandsSending packets with scapyNetwork discovery with scapyPort scanning and traceroute with scapyPort scanning with scapyTraceroute with scapyReading pcap files with scapyRead DHCP requestsWriting a pcap filePacket-sniffing with scapyNetwork forensics with scapyWorking with scapy to detect ARP spoofing attacksDetection of false ARP attacks using ScapySummaryQuestionsFurther readingSection 3: Server Scripting and Port Scanning with PythonGathering Information from Servers with OSINT ToolsTechnical requirementsIntroducing Open Source Intelligence (OSINT)Google Dorks and the Google Hacking DatabaseMaltegoPhotonThe HarvesterCensyscrt.shDnsDumpsterWaybackMachineOSINT frameworkBlackbirdThe Shodan search engineThe BinaryEdge search engineGetting information using Google DorksGoogle DorksKatana: a Python Tool for Google HackingDorks hunterGetting information using SpiderFootSpiderFoot modulesGetting information on DNS servers with DNSPython and DNSReconThe DNS protocolThe DNSPython moduleDNSReconGetting vulnerable addresses in servers with fuzzingThe fuzzing processWeb fuzzingUnderstanding and using the FuzzDB projectIdentifying predictable login pages with the FuzzDB projectDiscovering SQL injection with the FuzzDB projectWfuzzSummaryQuestionsFurther readingInteracting with FTP, SFTP, and SSH ServersTechnical requirementsConnecting to FTP serversFTP protocolUsing the Python ftplib moduleTransferring files with FTPOther ftplib functionsUsing ftplib to brute-force FTP user credentialsBuilding an anonymous FTP scanner with PythonConnecting with SSH servers with paramiko and pysftpExecuting an SSH server on Debian LinuxIntroducing the paramiko moduleEstablishing an SSH connection with paramikoUsing AutoAddPolicyRunning commands with paramikoUsing paramiko to brute-force SSH user credentialsEstablishing an SSH connection with pysftpImplementing an SSH server with paramikoChecking the security of SSH serversInstalling and executing ssh-auditRebex SSH CheckSummaryQuestionsFurther readingWorking with Nmap ScannerTechnical requirementsIntroducing port scanning with NmapScanning types with nmapPort scanning with python-nmapExtracting information with nmapSynchronous and asynchronous scanning with python-nmapImplementing synchronous scanningImplementing asynchronous scanningDiscovering services and vulnerabilities with Nmap scriptsExecuting Nmap scripts to discover servicesExecuting Nmap scripts to discover vulnerabilitiesDetecting vulnerabilities with Nmap-vulners scriptDetecting vulnerabilities with the Nmap-vulscan scriptPort scanning via online servicesScanless port scannerSummaryQuestionsFurther readingSection 4: Server Vulnerabilities and Security in Web ApplicationsInteracting with Vulnerability ScannersTechnical requirementsIntroducing the OpenVAS vulnerability scannerInstalling the OpenVAS vulnerability scannerUnderstanding the web interfaceScanning a target using OpenVASCreating the targetCreating the taskAnalyzing reportsVulnerabilities databasesAccessing OpenVAS with PythonIntroducing OWASP ZAP as an automated security testing toolUsing OWASP ZAPInteracting with OWASP ZAP using PythonWriteHat as a pentesting reports toolSummaryQuestionsFurther readingInteracting with Server Vulnerabilities in Web ApplicationsTechnical requirementsUnderstanding vulnerabilities in web applications with OWASPTesting Cross-Site Scripting (XSS) vulnerabilitiesAnalyzing and discovering vulnerabilities in CMS web applicationsUsing CMSmapVulnx as a CMS scannerDiscovering vulnerabilities in Tomcat server applicationsInstalling the Tomcat serverTesting the Tomcat server with ApacheTomcatScannerFinding vulnerable Tomcat servers in the Censys search engineScanning vulnerabilities with the Nmap port scannerDiscovering SQL vulnerabilities with Python toolsIntroduction to SQL injectionIdentifying websites vulnerable to SQL injectionIntroducing sqlmapUsing sqlmap to test a website for a SQL injection vulnerabilityScanning for SQL injection vulnerabilities with sqlifinderScanning for SQL injection vulnerabilities with the Nmap port scannerAutomating the process of detecting vulnerabilities in web applicationsDetecting an open redirect vulnerabilityDetecting vulnerabilities with FuxploiderSummaryQuestionsFurther readingObtain Information from Vulnerabilities DatabasesTechnical requirementsIdentify and understand vulnerabilities and exploitsWhat is an exploit?Vulnerability formatsSearching for vulnerabilities in the NVDIntroducing NIST’s NVDSearching for vulnerabilitiesSearching for vulnerabilities in the Vulners databaseSearching for vulnerabilities with PompemSummaryQuestionsFurther readingSection 5: Python ForensicsExtracting Geolocation and Metadata from Documents, Images, and BrowsersTechnical requirementsExtracting geolocation informationPython modules for extracting geolocation informationExtracting metadata from imagesIntroduction to EXIF and the PIL moduleGetting the EXIF data from an imageExtracting metadata from PDF documentsExtracting metadata with PyPDF2Extracting metadata with PyMuPDFIdentifying the technology used by a websiteWappalyzerWebApp Information Gatherer (WIG)Extracting metadata from web browsersFirefox forensics with PythonChrome forensics with PythonChrome forensics with HindsightSummaryQuestionsFurther readingPython Tools for Brute-Force AttacksTechnical requirementsDictionary builders for brute-force attacksBrute-force dictionary generation with pydictorPassword list generatorTools for brute-force attacks in PythonObtaining subdomains by brute forceBrute-force attacks with BruteSprayBrute-force attacks with CerbrutusExecuting brute-force attacks for web applicationsExecuting a WordPress siteExecuting brute-force attacks for ZIP filesHandling ZIP files in PythonExecuting brute-force attacks for password-protected ZIP filesSummaryQuestionsFurther readingCryptography and Code ObfuscationTechnical requirementsIntroduction to cryptographyEncrypting and decrypting information with pycryptodomeIntroduction to pycryptodomeEncrypting and decrypting with the DES algorithmEncrypting and decrypting with the AES algorithmGenerating RSA signatures using pycryptodomeEncrypting and decrypting information with cryptographyIntroduction to the cryptography moduleSymmetric encryption with the fernet packageSymmetric encryption with the ciphers packageGenerating keys securely with the secrets and hashlib modulesGenerating keys securely with the secrets moduleGenerating keys securely with the hashlib moduleChecking the integrity of a filePython tools for code obfuscationCode obfuscation with pyarmorSummaryQuestionsFurther readingAssessments – Answers to the End-of-Chapter QuestionsOther Books You May Enjoy