Book review: Security PowerTools by <i>Nicolas Beauchesne et al</i>

Book review: Security PowerTools by Nicolas Beauchesne et al


Security has always been a concern when using a computer. First, we thought physical security was enough. After all, if the computer is in the house, how could anyone else get to it? But in today’s world, many of us live with our computers on-line twenty-four/seven. Security is not just loading up the latest protection software, but being aware of how the “bad guys” attack. Good security also requires vigilant testing and, since no one wants to simply issue a challenge to the “bad guys” and see what happens—they don’t typically fill out trouble tickets—we need to use tools that can simulate these attacks.

It would also be helpful to know what to do after a vulnerability has been identified. O’Reilly Media, Inc. has provided us with an excellent collection of security tools in an appropriately titled book—Security Power Tools. Over twelve authors have collaborated to cover this topic thoroughly. With a peer group such as this, you know they had to defend their choice of tools as the best ones for the job. These authors have a great deal of experience and know their tools. They use them in their daily work and bring their personal experiences to each chapter.

The book’s coverThe book’s cover

The first impression of the book? This book is huge! It is going to take quite awhile to appreciate all the tips and pointers given. But knowing that these tools have been identified and collected into one place, even though it’s a big place, makes the issue of security seem more manageable. Security is a workable topic and not something to be feared. Reading through the first chapter on legal and ethics issues was quite encouraging. Sometimes lawyers, just like us tech folks, speak in a language all of their own. But the writing here is quite clear and actually interesting to read. The chapter will help you identify when it’s time to seek proper council and that was encouraging as well.

Some of the other chapters will not give you this warm and fuzzy level of comfort though. Some of the discussions on system penetration, exploitation, back-doors and root-kits were not comforting to read at all! But when you move on to the section on defense, you will discover topics with words in the titles like: proactive, securing, hardening, and anti-spam. I was quite happy and encouraged once again.

“This is not a simpleton’s instruction manual.”

The contents

The book really does cover an amazing amount of ground. Inside the 856 pages are twenty three chapters grouped into sections covering: legal and ethics, reconnaissance, penetration, control, defense, monitoring and discovery. Each chapter is typically written by one or two authors and will reflect those authors style. There are coding examples, screen captures, command line instructions and a good deal of commentary included. All these things work together to give you a very clear picture of the information being presented. For such a physically large book, it lays open easily and is good to work with on a desk. The length and width of the book are a standard 9.25” x 7” (23.5cm x 17.8cm) respectively, but the thickness is almost 2” (5cm). Don’t drop this book on your toe!

Who’s this book for?

There are a lot of different tools discussed. Different tools for different jobs. But in order to keep the size of the book small enough to still be considered portable, without mechanical assistance, assumptions have to be made. Specifically, the assumption that you know the basics and are looking for more specific details about what needs to be done and how to do it. If you are responsible for the security of your systems, you should have this book. Even if some of the tools are familiar, you will benefit from knowing how other people use them and may find a new use for those same tools. If you are simply concerned about security in general, this book might help you when discussing threats and solutions with your peers. Security may not be your main job, you might work in a small company without clearly identified job descriptions. Using this book could make you the hero if you can not only identify weaknesses but offer solutions as well. Perhaps you outsource your IT help. Using some of these tools to test your current system will help you identify where they need to be strengthening your defenses. Finally, if you’ve never thought about security before and have no interest in learning then this book might make a good gift to give to someone else. Regardless, it is a big enough book to have something in it for everyone.

Relevance to free software

This book covers the major operating systems: Windows, GNU/Linux, Mac OS, Unix, and a few others. There are proprietary tools that are reviewed and recommended. After all, the book is written about security. Free software proponents will be proud at the list of tools covered though. When a “free” tool is the best one, it is given proper credit as such. But don’t gloat if a particular vulnerability is talked about in someone else’s OS. Stick to the high road and realize that security is something everybody needs more of, your systems included. When I think about how many people and how many systems have access to and copies of my personal information, I really want every system to be more secure regardless of the operating system.

Knowing how to protect your self, your computer, and your freedom is essential to keeping those very same things alive. As a user of free software, you will win more friends by offering solutions to problems. After your new friends realize how you helped protect their systems once, they will be more receptive to being “helped” again. This is when you can plant the seeds of freedom and start opening their eyes to a better, more secure, way of doing business.

The “bad guys” stay up late reading too

Pros

This book brings many topics and many tools together. It is a collection of solutions brought together by competent professionals who rely on these tools in their work. Trial and error is a dangerous way to learn about security issues. Here is a book that can identify not only your systems’ weaknesses, but it can help you strengthen the systems as well.

Cons

Once again, ignorance is bliss. I had no idea how simple, nor how clever, some of these security attacks could be. Awareness of the problems will be forcing me to change some habits. My blissful state has slipped a little thanks to this book, but the security of my systems has increased.

Title Security Power Tools
Author Bryan Burns, Jennifer Stisa Granick, Steve Manzuik, Paul Guersch, Dave Killion, Nicolas Beauchesne, Eric Moret, Julien Sobrier, Michael Lynn, Eric Markham, Chris Iezzoni, Philippe Biondi
Publisher O’Reilly
ISBN 0596009631
Year 2007
Pages 856
CD included No
FS Oriented 6
Over all score 9

In short

Category: 
License: 

Comments

tebbatkind's picture
Submitted by tebbatkind on

Once again, ignorance is bliss. I had no idea how simple, nor how clever, some of these security attacks could be.thanks you
______________________
Sohbet Chat

Author information

Brian Turner's picture

Biography

After 18 years supporting communication networks, satellite and microwave, I've discovered some fun on the PC again. GNU/Linux, Mac OS X and MS Windows all have their uses, but GNU/Linux is where the fun is at.

Most forwarded

Interview with Dave Mohyla, of DTIDATA

Dave Mohyla is the president and founder of dtidata.com, a hard drive recovery facility based in Tampa, Florida.

TM: Where are you based? What does your company do?
DTI Data recovery is based in South Pasadena, Florida which is a suburb of Tampa. We have been here for over 10 years. We operate a bio-metrically secured class 100 clean room where we perform hard drive recovery on all types of hard disks, from laptop hard drives to multi drive RAID systems.

Anybody up to writing good directory software?

Since the very beginning, directories (of any kind) have had a very central role in the internet. (I have recently grown fond of Free Web Directory. Even Slashdot can be considered a directory: a collection of great news and invaluable user-generated comments. As far as software is concerned, doing a quick search on Google about software directories will return the free (as in freedom) software directories like Savannah, SourceForge, Freshmeat and so on, followed by shareware and freeware sites such as FileBuzz, PCWin Download Center and All Freeware (great if you're looking for shareware and freeware, but definitely less comprehensive than their free-as-in-freedom counterparts).

Interview with Mark Shuttleworth

Mark Shuttleworth is the founder of Thawte, the first Certification Authority to sell public SSL certificates. After selling Thawte to Verisign, Mark moved on to training as an astronaut in Russia and visiting space. Once he got back he founded Ubuntu, the leading GNU/Linux distribution. He agreed on releasing a quick interview to Free Software Magazine.

Is better education the key to finding better software?

I read David Jonathon's article Anybody Up To Writing Good Directory Software? the other day, which got me thinking about software directories in general. As David mentioned, many of the software directories one finds when doing a quick google search are free as in beer, not as in freedom. But what interests me is the software directories that already exist, providing a combination of both free as in beer software, and open source software. Sites such as Freeware Downloads and Shareware Download don't advertise themselves as providing free as in liberty software, but each of them have a good selection of open source software available... if you know where to look.

Most emailed

Free Open Document label templates

If you’ve ever spent hours at work doing mailings, cursed your printer for printing outside the lines on your labels, or moaned “There has got to be a better way to do this,” here’s the solution you’ve been looking for. Working smarter, not harder! Worldlabel.com, a manufacture of labels offers Open Office / Libre Office labels templates for downloading in ODF format which will save you time, effort, and (if you want) make really cool-looking labels

Creating a user-centric site in Drupal

A little while ago, while talking in the #drupal mailing list, I showed my latest creation to one of the core developers there. His reaction was "Wow, I am always surprised what people use Drupal for". His surprise is somehow justified: I did create a site for a bunch of entertainers in Perth, a company set to use Drupal to take over the world with Entertainers.Biz.

Update: since writing this article, I have updated the system so that the whole booking process happens online. I will update the article accordingly!

So, why, why do people and companies develop free software?

More and more people are discovering free software. Many people only do so after weeks, or even months, of using it. I wonder, for example, how many Firefox users actually know how free Firefox really is—many of them realise that you can get it for free, but find it hard to believe that anybody can modify it and even redistribute it legally.

When the discovery is made, the first instinct is to ask: why do they do it? Programming is hard work. Even though most (if not all) programmers are driven by their higher-than-normal IQs and their amazing passion for solving problems, it’s still hard to understand why so many of them would donate so much of their time to creating something that they can’t really show off to anybody but their colleagues or geek friends.

Sure, anybody can buy laptops, and just program. No need to get a full-on lab or spend thousands of dollars in equipment. But... is that the full story?

Fun articles

Santa Claus - the most successful open source project

It dawned on me the other day, as I was shopping for the dozens of gifts it seems I have to buy every December, that Santa Claus is the most successful open source project in history. (Bridget @ Illiterarty would agree with that). Santa Claus is essentially a marketing development that is embodied by everyone who stuffs a sock, gives a gift, hosts a dinner or wishes Merry Christmas over the holiday season.

Most emailed

Editorial

When I first started thinking about Free Software Magazine, I was feeling enthusiastic about the dream. I had Dave, Gianluca, and Alan willing to help me, I had established members of the free software community willing to help me out, I had writers volunteering their time and energy for free, and I had a generous offer from OpenHosting for servers, all before I'd proved myself. There was a sense of excitement in the air, and I thought maybe, just maybe, I could make this work.

Free Software Magazine uses Apollo project management software and CRM for its everyday activities!