The Pentester BluePrint: Starting a Career as an Ethical Hacker [Phillip L Wylie] (pdf) читать постранично

Книга в формате pdf! Изображения и текст могут не отображаться!


 [Настройки текста]  [Cбросить фильтры]

The Pentester
Blueprint
Starting a Career
as an Ethical
Hacker
Phillip L. Wylie
Kim Crawley

Copyright © 2021 by John Wiley & Sons, Inc., Indianapolis, Indiana
Published simultaneously in Canada
ISBN: 978-1-119-68430-5
ISBN: 978-1-119-68435-0 (ebk)
ISBN: 978-1-119-68437-4 (ebk)
Manufactured in the United States of America
No part of this publication may be reproduced, stored in a retrieval system or transmitted in any
form or by any means, electronic, mechanical, photocopying, recording, scanning or otherwise,
except as permitted under Sections 107 or 108 of the 1976 United States Copyright Act, without
either the prior written permission of the Publisher, or authorization through payment of the
appropriate per-copy fee to the Copyright Clearance Center, 222 Rosewood Drive, Danvers, MA
01923, (978) 750-8400, fax (978) 646-8600. Requests to the Publisher for permission should be
addressed to the Permissions Department, John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ
07030, (201) 748-6011, fax (201) 748-6008, or online at www.wiley.com/go/permissions.
Limit of Liability/Disclaimer of Warranty: The publisher and the author make no representations
or warranties with respect to the accuracy or completeness of the contents of this work and
specifically disclaim all warranties, including without limitation warranties of fitness for a
particular purpose. No warranty may be created or extended by sales or promotional materials.
The advice and strategies contained herein may not be suitable for every situation. This work is
sold with the understanding that the publisher is not engaged in rendering legal, accounting,
or other professional services. If professional assistance is required, the services of a competent
professional person should be sought. Neither the publisher nor the author shall be liable for
damages arising herefrom. The fact that an organization or Web site is referred to in this work as
a citation and/or a potential source of further information does not mean that the author or the
publisher endorses the information the organization or website may provide or recommendations
it may make. Further, readers should be aware that Internet websites listed in this work may have
changed or disappeared between when this work was written and when it is read.
For general information on our other products and services please contact our Customer Care
Department within the United States at (877) 762-2974, outside the United States at (317) 5723993 or fax (317) 572-4002.
Wiley publishes in a variety of print and electronic formats and by print-on-demand. Some
material included with standard print versions of this book may not be included in e-books or
in print-on-demand. If this book refers to media such as a CD or DVD that is not included in the
version you purchased, you may download this material at booksupport.wiley.com. For
more information about Wiley products, visit www.wiley.com.
Library of Congress Control Number: 2020943760
Trademarks: Wiley and the Wiley logo are trademarks or registered trademarks of John Wiley
& Sons, Inc. and/or its affiliates, in the United States and other countries, and may not be used
without written permission. All other trademarks are the property of their respective owners.
John Wiley & Sons, Inc. is not associated with any product or vendor mentioned in this book.

I dedicate The Pentester Blueprint to my wife Tiffany and daughter Jordan.
Without your love and support, this would not have been possible. As always you
support me in my endeavors, encouraging me every step of the way.

—Phillip L. Wylie

To my loving rock musician boyfriend Jason, my stuffed animal family for
assuring me of the rest that I need in order to work effectively, and my late
father Michael Crawley for encouraging my very early interest in computers and
raising me to write for a living.

— Kim Crawley

About the Authors
Phillip L. Wylie is the Lead Curriculum Developer for Point3 Federal, Adjunct Instructor at
Dallas College, and The Pwn School Project
founder. Phillip has over 23 years of industry
experience in disciplines ranging from system
administrator, network security engineer, and
application security engineer. He has spent
the last eight-plus years as a pentester. During
his pentesting career, Phillip has performed
pentests of networks, wireless networks, and
applications, as well as red team operations and
social engineering.
Phillip started his career in pentesting as a consultant, where he spent his
first five years. These years gave him experience in various environments for
Fortune 500 companies in a broad range of industries. Phillip has a passion
for mentoring, educating, and helping others. His passion for education and
the cybersecurity community motivated him to start teaching and to found
The Pwn School Project, a monthly educational meetup focusing on cybersecurity and ethical hacking. His education efforts, however, expanded beyond
the classroom and The Pwn School Project. He can be found routinely giving
presentations and teaching workshops at cybersecurity conferences.
Phillip teaches Ethical Hacking and Web Application Pentesting at Dallas
College in Dallas, TX. Phillip is a co-host for The Uncommon Journey podcast. Phillip has an associate degree in Computer Networking and holds these
cybersecurity certifications: CISSP, NSA-IAM, OSCP, and GWAPT. During his
system administrator career, Phillip attained these industry certifications;
Microsoft MCSE for Windows NT 4.0 and Windows 2000, Novell CNE, and
Cisco CCNA.

About the Authors

Kim Crawley is dedicated to researching
and writing about a plethora of cybersecurity issues. Some of the companies Kim has
worked for over the years include Sophos,
AT&T Cybersecurity, BlackBerry Cylance,
Tripwire, and Venafi. All matters red team,
blue team, and purple team fascinate her. But
she’s especially fascinated by malware, social
engineering, and advanced persistent threats.
Kim’s extracurricular activities include
running an online cybersecurity event called
DisInfoSec and autistic self-advocacy. When
she’s not working, Kim loves JRPGs (especially the Persona series), trying to
cook Japanese and Korean dishes, goth music and fashion, and falling down
Wikipedia and TV Tropes rabbit holes.

v

Acknowledgments
I thank all of my students and the people I have mentored over the years:
You helped me realize my passion for teaching. I thank my friend and fellow
adjunct instructor Jason Alvarado for hiring me to teach at Dallas College
(formerly Richland College). Teaching Ethical Hacking and Web Application
Pentesting helped me discover my love for teaching, which has opened so many
doors. I thank my friend and Dallas Hackers Association founder Wirefall for
your friendship and for founding the Dallas Hackers Association.
The Dallas Hackers Association was pivotal in getting me involved in the
hacking and cybersecurity community. This led to speaking and teaching
workshops at cybersecurity conferences, where I have connected with so many
amazing people. Thanks to Wirefall, I met Marcus Carey, the author of the
Tribe of Hackers book series (Wiley, 2019). Thanks to Marcus for including
me in the Tribe of Hackers Red Team book, which has been very helpful in
my career and ultimately led to my being offered the opportunity to write
this book. I acknowledge Marcus for his contributions to the cybersecurity
community and for his efforts for the betterment of our world and for inspiring
me to make the world a better place.
Last, but definitively not least, I thank Kim Crawley, my amazing coauthor,
who helped me take my conference talk from conception to a book. Thanks
for helping me take an idea—28 PowerPoint slides—and breathing life into it.
I would like to thank my friend, Rhea Santos for taking time out of her
schedule to create the artwork for the chapters of the book. Rhea is a friend
and someone that I have taught and mentored. It is so fitting to have her art
in The Pentester Blueprint since it was the people that I taught and mentored
that inspired me to write this book.
Thanks also go to Jim Minatel at Wiley for the opportunity to write this
book and to Gary Schwartz and the rest of the Wiley staff for making this
book a reality. Your hard work is much appreciated.
—Phillip L. Wylie
I’m tremendously grateful to Phillip Wylie for inviting me to collaborate
with him on The