

Buy anything from 5,000+ international stores. One checkout price. No surprise fees. Join 2M+ shoppers on Desertcart.
Desertcart purchases this item on your behalf and handles shipping, customs, and support to Indonesia.
Penetration testers simulate cyber attacks to find security weaknesses in networks, operating systems, and applications. Information security experts worldwide use penetration techniques to evaluate enterprise defenses. In Penetration Testing , security expert, researcher, and trainer Georgia Weidman introduces you to the core skills and techniques that every pentester needs. Using a virtual machine-based lab that includes Kali Linux and vulnerable operating systems, you'll run through a series of practical lessons with tools like Wireshark, Nmap, and Burp Suite. As you follow along with the labs and launch attacks, you'll experience the key stages of an actual assessment - including information gathering, finding exploitable vulnerabilities, gaining access to systems, post exploitation, and more. Learn how to: Crack passwords and wireless network keys with brute-forcing and wordlists Test web applications for vulnerabilities Use the Metasploit Framework to launch exploits and write your own Metasploit modules Automate social-engineering attacks Bypass antivirus software Turn access to one machine into total control of the enterprise in the post exploitation phase You'll even explore writing your own exploits. Then it's on to mobile hacking - Weidman's particular area of research - with her tool, the Smartphone Pentest Framework. With its collection of hands-on lessons that cover key tools and strategies, Penetration Testing is the introduction that every aspiring hacker needs. Review: An eye-opening read showing how easy it can be to get into pentesting - A very informative read which filled in some gaps in my security knowledge, having worked on the "other side" as a firewall engineer. Some of the assets required for the exercises in the book were no longer available in their original locations. However, I saw a tweet from the author in 2018 saying to just email her and she would send a link over. I did this and Georgia responded within 3 hours, which was impressive. I believe she is working on an updated version of the book, which I will buy as soon as it is out. Review: A concise and approachable introduction to pentesting - This is probably the best introduction to pentesting book out there, and in the absence of a guide aligned with Offensive Security's notorious and esteemed OSCP certification, it is also the best option for anyone preparing for that course. Admittedly some of the links no longer work, but workarounds for them are easy to find if you have a search online, which is probably a skill you should be getting comfortable with if you're going down this road anyway. Weidman has mentioned on her Twitter feed that she's currently researching new vulnerabilities and material for the second edition, but I wouldn't expect to see that in the near future. Check out her free videos on Cybrary as well - her Advanced Penetration Testing course closely mirrors the layout of this book.
| Best Sellers Rank | 286,261 in Books ( See Top 100 in Books ) 283 in Computer Information Systems 425 in E-Business 549 in Software Design & Development |
| Customer Reviews | 4.4 out of 5 stars 614 Reviews |
M**N
An eye-opening read showing how easy it can be to get into pentesting
A very informative read which filled in some gaps in my security knowledge, having worked on the "other side" as a firewall engineer. Some of the assets required for the exercises in the book were no longer available in their original locations. However, I saw a tweet from the author in 2018 saying to just email her and she would send a link over. I did this and Georgia responded within 3 hours, which was impressive. I believe she is working on an updated version of the book, which I will buy as soon as it is out.
A**H
A concise and approachable introduction to pentesting
This is probably the best introduction to pentesting book out there, and in the absence of a guide aligned with Offensive Security's notorious and esteemed OSCP certification, it is also the best option for anyone preparing for that course. Admittedly some of the links no longer work, but workarounds for them are easy to find if you have a search online, which is probably a skill you should be getting comfortable with if you're going down this road anyway. Weidman has mentioned on her Twitter feed that she's currently researching new vulnerabilities and material for the second edition, but I wouldn't expect to see that in the near future. Check out her free videos on Cybrary as well - her Advanced Penetration Testing course closely mirrors the layout of this book.
J**B
Great book, very informative, full of hands on learning
Great book, very informative and full of hands on knowledge that is demonstrable and practicable with few requirements (an at least half decent computer/laptop). Some of the information is a little outdated but that is to be expected with Cyber Security being an ever accelerating and developing industry. Another small issue I have is that the spine of the book has peeled away, I wouldn't usually mind but I've only had it for around two weeks so far, other than that I highly recommend!
A**R
Very good book, but...
This is a very good book for beginners who wants to learn it by hands on. I recommend this book to anoyone who is interested in computer security. The only issue you will encounter is trying to install new packages on the old Kali Linux. For example, Nessus, Hyperion, Veil-Evasion, and so on. If you have this problem then I recommend you download the latest Kali Linux and installing the packages there.
A**R
Great Book, I am loving the exercises
Great Book, I am loving the exercises. Even though many people have said it is outdated, the material is still super relavant. It does take a bit of troubleshooting to get it setup exactly as instructed, with Kali2. Cant wait to progress and gain even more skills and knowledge. Book is easy to understand.
R**R
Good intro to the topic
An excellent introduction. I downloaded the sample text and worked with it to give me a feel for the scope of the book and the level of difficulty. I then downloaded the whole text and have started work, using the latest version of Kali and adapting command lines, etc. from the book to reflect this. So far so good, but NOT for the faint hearted! Tip - I have found that the Kali Virtual Machine (in Virtual Box) runs a *lot* faster if you use a static disk size instead of the default dynamic disk. There's a lot of info on the web about this.
A**K
Essential reading to learn Pentesting
I decided to learn Pentesting/Ethical Hacking as a retirement project and this is the only book that actually starts at the begining, and explains in detail how to setup a testing lab on a single machine, so you can actually do some REAL testing. I'm also impressed that the book sticks to it's title and is about Pentesting and doesn't waste hundreds of pages on Coding which is how other Pentesting books fill far too many pages. I have several other Pentesting books but this way ahead of them all.
K**S
Hax0r in the Making?...
Think of this book as a 'Haynes Manual' current edition covers across a broad spectrum of ICT technologies, shows set ups of VM Fusion (Kali) and the additional tricks to get uncooperative OS's neatly in your 'toolbox of doom' for all your PenTest needs, well generally speaking, this book won't make you a $uP3rHax0r, that's completely up to You, but knowing how to 'use' a computer is prerequisite.
A**E
Another amazing nostarch press book on Pen Testing
Very worth the purchase.
B**Z
Excellent Buy for your money!
Excellent book for someone who’s interested in learning penetration testing! This book is written so well that it doesn’t matter if you’re a beginner or even have some experience already it will greatly benefit you!
E**O
M
Se separó la pasta de las hojas el primer día. Sin embargo, el contenido es bueno.
V**T
Very nice product
Good product
R**S
Great intro to hacking (pentesting).
Great intro to hacking (pentesting). I have struggled with other hacking books before, some of them are "too technical " and dive into specific vulnerabilities without explaining why they happen or is not concise. I'm looking at you Hacking Exposed series. But this one is a practical smooth read. After you are done you can start practicing everything you learn pwning boxes on Hack the Box. P.s: I did have difficulty finding the right XP SP3(I think it was) to setup the lab. The one I used didn't have the ms08-067 vulnerability. But that shouldn't stop you from practicing what's being taught. Just do a vulnerability scan of your system with nikto or whatever, as taught in the book, and try to get a meterpreter session attacking another vulnerability.
Trustpilot
2 weeks ago
1 month ago