Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Arrow up icon
GO TO TOP
Kali Linux 2 ??? Assuring Security by Penetration Testing

You're reading from   Kali Linux 2 ??? Assuring Security by Penetration Testing Achieve the gold standard in penetration testing with Kali using this masterpiece, now in its third edition!

Arrow left icon
Product type Paperback
Published in Sep 2016
Publisher Packt
ISBN-13 9781785888427
Length 572 pages
Edition 3rd Edition
Arrow right icon
Authors (4):
Arrow left icon
Gerard Johansen Gerard Johansen
Author Profile Icon Gerard Johansen
Gerard Johansen
Lee Allen Lee Allen
Author Profile Icon Lee Allen
Lee Allen
 Heriyanto Heriyanto
Author Profile Icon Heriyanto
Heriyanto
 Ali Ali
Author Profile Icon Ali
Ali
Arrow right icon
View More author details
Toc

Table of Contents (24) Chapters Close

Kali Linux 2 – Assuring Security by Penetration Testing Third Edition
Credits
Disclaimer
About the Authors
About the Reviewer
www.PacktPub.com
Preface
1. Beginning with Kali Linux 2. Penetration Testing Methodology FREE CHAPTER 3. Target Scoping 4. Information Gathering 5. Target Discovery 6. Enumerating Target 7. Vulnerability Mapping 8. Social Engineering 9. Target Exploitation 10. Privilege Escalation 11. Maintaining Access 12. Wireless Penetration Testing 13. Kali Nethunter 14. Documentation and Reporting Supplementary Tools Key Resources Index

Vulnerability disclosure and tracking


The following is a list of online resources that may help you track vulnerability information. Many of these websites are best known for their open vulnerability disclosure program, so you are free to contribute your vulnerability research to any of these public/private organizations. Some of them also encourage a full disclosure policy based on the paid incentive program to reward security researchers for the valuable time and effort they put into vulnerability investigation and the development of proof of concept (PoC) code.

The following are some of the vulnerability disclosure and tracking websites that you can use:

URL

Description

https://blog.osvdb.org/

The Open Source Vulnerability Database

http://www.securityfocus.com/

Public vulnerabilities, mailing lists, and security tools

http://www.packetstormsecurity.org/

Exploits, advisories, tools, and whitepapers

http://www.secunia.com/

Advisories, whitepapers, security factsheets, and research papers

http://www.exploit-db.com/

Exploits database, Google Hacking Database (GHDB), and papers

http://web.nvd.nist.gov/view/vuln/search

NVD is a U.S. government repository for a vulnerability database based on CVE

https://access.redhat.com/security/updates/advisory/

RedHat errata notification and security advisories

http://lists.centos.org/pipermail/centos-announce/

CentOS security and general announcement mailing list

http://www.us-cert.gov/ncas/alerts

DHS US-CERT reports security issues, vulnerabilities, and exploits technical alerts

https://exchange.xforce.ibmcloud.com/

IBM X-Force offers security threat alerts, advisories, vulnerability database, and whitepapers

http://www.debian.org/security/

Debian security advisories and mailing lists

https://www.suse.com/support/update/

SUSE Linux Enterprise security advisories

http://technet.microsoft.com/en-us/security/advisory

Microsoft security advisories

http://technet.microsoft.com/en-us/security/bulletin

Microsoft security bulletins

http://www.ubuntu.com/usn

Ubuntu security notices

http://www.first.org/cvss/

First Common Vulnerability Scoring System (CVSS-SIG)

http://tools.cisco.com/security/center/publicationListing.x

Cisco security advisories, responses, and notices.

http://www.security-database.com

Security alerts and dashboard, and CVSS calculator.

http://www.securitytracker.com/

Security vulnerabilities information.

http://www.auscert.org.au/

Australian CERT publishes security bulletins, advisories, alerts, presentations, and papers.

http://en.securitylab.ru/

Advisories, vulnerability database, PoC, and virus reports.

https://www.coresecurity.com/grid/advisories

Vulnerability research, publications, advisories, and tools.

https://www.htbridge.com/

Security advisories and security publications.

http://www.offensivecomputing.net/

Malware sample repository.

http://measurablesecurity.mitre.org/

MITRE offers standardized protocols for the communication of security data related to vulnerability management, intrusion detection, asset security assessment, asset management, configuration guidance, patch management, malware response, incident management, and threat analysis. Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE), Common Attack Pattern Enumeration and Classification (CAPEC), and Common Configuration Enumeration (CCE) are a few of them.

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime
Visually different images