Take your penetration testing and IT security skills to a whole new level with the secrets of Metasploit About This Book Gain the skills to carry out penetration testing in complex and highly-secured environments Become a master using the Metasploit framework, develop exploits, and generate modules for a variety of real-world scenarios Get this completely updated edition with new useful methods and techniques to make your network robust and resilient Who This Book Is For This book is a hands-on guide to penetration testing using Metasploit and covers its complete development. It shows a number of techniques and methodologies that will help you master the Metasploit framework and explore approaches to carrying out advanced penetration testing in highly secured environments. What You Will Learn Develop advanced and sophisticated auxiliary modules Port exploits from PERL, Python, and many more programming languages Test services such as databases, SCADA, and many more Attack the client side with highly advanced techniques Test mobile and tablet devices with Metasploit Perform social engineering with Metasploit Simulate attacks on web servers and systems with Armitage GUI Script attacks in Armitage using CORTANA scripting In Detail Metasploit is a popular penetration testing framework that has one of the largest exploit databases around. This book will show you exactly how to prepare yourself against the attacks you will face every day by simulating real-world possibilities. We start by reminding you about the basic functionalities of Metasploit and its use in the most traditional ways. You'll get to know about the basics of programming Metasploit modules as a refresher, and then dive into carrying out exploitation as well building and porting exploits of various kinds in Metasploit. In the next section, you'll develop the ability to perform testing on various services such as SCADA, databases, IoT, mobile, tablets, and many more services. After this training, we jump into real-world sophisticated scenarios where performing penetration tests are a challenge. With real-life case studies, we take you on a journey through client-side attacks using Metasploit and various scripts built on the Metasploit framework. By the end of the book, you will be trained specifically on time-saving techniques using Metasploit. Style and approach This is a step-by-step guide that provides great Metasploit framework methodologies. All the key concepts are explained details with the help of examples and demonstrations that will help you understand everything you need to know about Metasploit."
Nipun Jaswal is an International Cyber Security Author and an award-winning IT security researcher with a decade of experience in penetration testing, vulnerability assessments, surveillance and monitoring solutions, and RF and wireless hacking.
He has authored Metasploit Bootcamp, Mastering Metasploit, and Mastering Metasploit—Second Edition, and coauthored the Metasploit Revealed set of books. He has authored numerous articles and exploits that can be found on popular security databases, such as packet storm and exploit-db. Please feel free to contact him at @nipunjaswal.
Mastering Metasploit is the best book that all security professionals must read in order to get into the heart of Metasploit framework. The book covers all aspects of the framework including using the exploits, writing exploits and modules, understanding the architecture. It also covers practical examples to help readers achieve the best results. This book is the first book that I have seen to explain under the hood of Metasploit. In order to be a good pentester one must not only focus on the usage of the tools, but also being able to write custom attacks, modules, scripts, etc. The book can be useful for those who want to start with the framework and also security professionals that have used the Metasploit so far. "You can purchase this book from the publishers Website with special discount"
This book takes you on a journey starting from the very begging. On the first couple of pages it covers nmap target analysis, and exploitation of popular Windows systems. It gives you a nice intro into the Ruby programming language - the language Metasploit is written in. Analysis of Metasploit code follows, naturally. But that's not all. Far from it. Explanations on assembly, ports to pearl, web server exploitation, SCADA, SQL, VOIP, you name it. It's all there. Even social engineering. And after all this, there is a chapter on optimizing code it already covered. This is an excellent book, that I found very helpful. I would recommend it to anyone interested in security.
I really enjoyed reading this book, it is very well organized and the chapters follow a logical scheme, clearly stating the objectives at the beginning. After an introductory part, which describes in general how a penetration Testing should be conducted to adhere to the standard and achieve objective results, the book starts introducing you to Metasploit internals and focuses on the framework and what it offers to you to build your own tests and exploits. It is not just a mere description of how Metasploit works, the aim of the author is to help you understand how to work with the software and how you can leverage what it offers in order to get full advantage of what it can do. This objective is achieved explaining every aspect with an example and with some screenshot that help you understand what is going on with a step by step approach : this makes this book ideal also for teaching advanced techniques to a class of students. The central part of the book then focuses on various techniques to test a rich set of systems ranging fom Scada, to Windows, to web and Database servers. Other interesting arguments covered are the advanced client-side attacks and the social engineering toolkit. Finally, the last part of the book gives you many tips to enhance your working environment to speed up the tests and teaches you how you can work even more easily with Armitage, taking advantage of its scripting language Cortana.
To sum up, this is really a must have book if you want to learn a professional approach to penetration testing, to become very proficient using Metasploit and other useful tools used to perform and explain various attack techniques and find useful hints and tips on how to plan and perform penetration testing in various scenarios in a quick and effective manner.
I was thoroughly impressed with the contents of this book. I have read other books on Metasploit and did not find them to go far beyond the basics, whereas Nipun Jaswal's "Mastering Metasploit" goes way beyond the basics. This book was written so even a beginner could understand, however what makes this book stand out is the focus on advanced techniques and clearly written examples. It was written logically and methodically and the objectives were clearly stated from the beginning. I would recommend this book to anybody that uses Metasploit and wants to master it.
The Book is Great in All perspectives. Author has kept each and every thing in detail. the beat part about this book is that it starts where most of the books stop.
Pros: 1. Exploit Development in detail 2. Coverage of Cortana 3. Module Building in detail 4. Voip, Db and scada coverage 5. Too many exploits to deal with
Cons: 1. Didnt found any, Overall extremely happy with the purchase
This is a very good book. Unlike other books about Metasploit, this one even teaches about exploit development in one of its chapters. Highly recommended.
This book is read be come it teach you how much the good to to test your knowledge about. Computer get hack and it test your skills level go Kali Linux