Slashdot Mirror


Hacking Linux Exposed

Reader Bob Johnson wrote this detailed review of Hacking Exposed followup Hacking Linux Exposed -- especially in light of the various color-coded Windows viruses still on the loose, this might be a good present for your your local Windows administrator as well, but both Bob and the authors are clear: GNU/Linux systems may be more resistant, but are not immune to cracking. Hacking Linux Exposed author Brian Hatch, James Lee, George Kurtz pages 566 publisher Osborne/McGraw-hill rating 8.5 reviewer Bob Johnson. ISBN 0072127732 summary The definitive Linux/Unix security and hacking text; follows in the full-disclosure footsteps of Hacking Exposed. What it is

While the recent Code Red worms and their offspring have taken center stage, it is not time for Linux administrators to sit on their behinds and say 'told you so.' Yes, our Unix systems may have been immune, but let us not forget the flurry of worms that came after Ramen made the scene early this year.

Most folks have heard of Hacking Exposed, the ground-breaking security book that is now coming out with a 3rd edition. One of the HE authors, George Kurtz, teamed up with two leading security experts to bring us Hacking Linux Exposed which was released in April of this year.

Hacking Linux Exposed teaches you about security from the cracker's point of view. to give you all you need to know to protect your own systems. It is written by security experts who have seen these attacks in the wild and have been protecting their own systems from them. It gives many examples of attacks, but it also teaches you how attacks of various forms occur in general, giving you a true understanding of vulnerabilities current, future, and theoretical.

The book itself is organized into four parts, each discussing a specific aspect of system security in depth.

Contents Part I begins with Unix permission models, such as passwords, file (user/group/other) modes, capabilities, limits, and other security features built into Linux. Though the authors claim this chapter is 'to get those Windows users up to speed' I found details about things I didn't know about, having been administering Linux systems for several years.

The authors then move onto proactive measures that can be taken to protect your system, under the theory that you shouldn't be reading the entire book before you start securing your systems. This section primes you with security procedures that will be referenced later in the book multiple times, and keeping it all contained seems a very logical organization. Topics include log analysis, system security scanners, hardening tools and patches. The chapter is ended with a step-by-step discussion of what to do should you suffer a break-in. While they strongly suggest a reinstall, and describe all the problems and pitfalls that brings, they acknowledge when business needs may conflict, and how to deal with differing requirements.

Rounding out the first part we move onto a chapter showing how crackers find out information about your machines and network. Naturally it includes the standard port-scanning tools, ping sweepers, and OS detection software, as well as network (in)security scanners such as SAINT, Nessus, and SARA. New administrators will learn a lot from discussions of information leakage through SNMP, DNS, whois, and even newsgroups. I believe this is the only book I have ever read to start a chapter with a piece of email Spam for educational purposes.

Part II talks about how crackers can get into your machine from the outside. We begin with a chapter entitled "Social Engineering, Trojans, and Other Hacker Trickery." This chapter is dedicated to various methods that are not necessarily code-related. The social-engineering angle is broken down into several categories, explaining the human insecurities that are most effective at getting people to give out inappropriate access or information, complete with frighteningly simple examples. The discussion of Trojans reminds us that everything may not be what it seems, such as the trojaned version of tcpd back in 1999, and explains how not to be taken advantage of by using checksums, pgp signatures, and the like. It ends with a discussion of worms. A discussion of the Ramen worm is included (the book was published very soon after this worm was released) as is a prediction that other worms may be on the horizon, which turned out to be all too true.

Next we move onto physical attacks that are used to gain access to systems, or helpful information. You are reminded how lax your office environment is (yes, we all have at least one sticky note with some password, somewhere) perhaps more than necessary. However when discussing console access, the authors return to instantly-implementable countermeasures to keep folks from walking up, rebooting, and dropping into single user mode, including a bit on encrypted filesystems.

Next comes a chapter devoted to attacks launched over the network. True to the overall style of the book, this isn't simply a list of the various POP/IMAP/Sendmail hacks over the years, but rather examples of different classes of attacks, such as wardialing, X servers, buffer overflows, denial of service attacks, sniffers, and automated password guessers. The information provided should help you prevent the known attacks and those that haven't been written yet that operate on similar principles.

The last chapter of Part II discusses attacks based on abuse of the network and network protocols themselves. We learn about abuses of DNS, routing protocols, and advanced sniffing and session hijacking that can be used to funnel your traffic through an attacker's machine without your knowledge, often without any loss in service. Man in the middle attacks against SSH and SSL are also well explained, and critical for anyone to understand before blindly clicking 'ok' to PKI-based warnings. The chapter ends with a discussion of the hazards IP-based trust relationships, and how to properly implement ingress and egress filtering.

All the topics to this point have been geared to keeping the attacker off of your system. In Part III, the authors move on to how an attacker that has already gotten onto your machine in some way will ultimately hack the root account.

We begin with PATH and permissions problems, insecurities with suid/sgid and custom root-run scripts, and common problems with poor sudo configuration (including a script you could use to allow limited editing of /etc/passwd via sudo safely.) It continues with local buffer overflow, format string vulnerabilities, race conditions, and hard/symbolic link problems. A very good chapter for anyone writing code, in addition to security administrators.

Chapter 9 is devoted to password cracking techniques and programs, such as Crack, John the Ripper, and pointers to useful word lists. Shadow passwords, including expiration information, is explained, as well as other systems that use passwords such as Apache .htpasswd files. Lastly, they describe good methods of choosing and enforcing strong passwords via PAM.

Chapter 10 shows you all the evils an attacker can do to your system after having cracked root. This chapter reads like a ringing wake-up call if you think a machine can be properly resecured once it has been compromised. The authors show some simplistic methods a hacker can use to maintain access, such as modifications of .rhosts, read/write nfs exports, and suid root shells, to more advanced methods such as the use of SSH authorized_keys which are suprisingly still not part of most script-kiddies arsenal. It then moves onto several methods of creating a network-accessible root shell (a wacky custom one is written in perl and netcat). The rest of the chapter is devoted to trojaning a system by replacing/recompiling new versions of system programs (netstat/ls/etc) which can be used to hide an attacker's activities. Loadable kernel modules which can do the same, but are potentially undetectable are discussed, complete with code. This chapter could have been titled 'How to build your own rootkit' given the detail they provide.

The last main part of the book discusses firewalls, web, mail, and ftp servers in detail. The server room is still where Linux is most often deployed, and the authors decided to give extensive detail about how to secure these commonly-provided services.

Chapter 11 discusses mail and ftp security, services that are most frequently run by the buggiest of software. However, the authors don't waste their time listing the insecurities that have existed in each product over the years (which would have taken several books) but instead look at current problems in implementations and the protocols themselves. For the mail section, it was refreshing to see that Postfix and Qmail were given equal air time along with Sendmail The authors described attacks that affect Sendmail, Postfix, and Qmail, showing the necessary fix for each mail server. The FTP section began the actual workings of the FTP protocol in both Active and Passive modes to allow you to understand the problems with the protocol itself and how it can be used for FTP bounce attacks, penetrating poorly-designed firewalls, and how data hijacking can occur.

Chapter 12 discusses both webserver configuration issues (Apache being the most prominent) and server-side dynamic content insecurities. The authors show you how to trim overly-permissive configuration options that are enabled by default, protect your HTTP authentication files, tighten proxy settings, decide where symlinks are appropriate, and more. The CGI (mod_perl, etc) section does a good job of showing you common pitfalls you or the programmers you support make every day that can lead to a compromise.

The last chapter of the book discusses how you can enable access controls and firewall rules to keep the bad guys off of your machine. They discuss TCP Wrappers along with inetd, xinetd, and even how to integrate them into your own daemons. They give detailed examples of how you can implement packet filters on your machine. It was nice to see iptables described as prominently as ipchains, especially since the 2.4 kernel was barely out when they released the book.

The last section of the book is the appendices. The first discusses the package management systems of various Linux distributions (RedHat, Debian, Slackware) and how to install/upgrade/verify your packages. The next details how to see what services you are running and how to turn them off, again describing distribution-specific methods where appropriate. The last appendix consists of three actual-hack case studies. If you've read Hacking Exposed then you're familiar with the 1-2 page case study at the beginning of each chapter. Here they included much lengthier case studies, including the code the attackers used. The increased length works much better, and provides a good view into these attacker's methods.

Presentation This book is very well organized, and includes the right combination of discussion and code. They made frequent use of special 'Caution', 'Note' and 'Tip' graphics to emphasis specific issues, and each attack begins with a 'Risk Rating' that lets you understand which attacks should be secured first as you attempt to implement all the countermeasures they make. No issue was brought up without a specific countermeasure you can implement today.

Many security books out there focus on various tools available to attackers, and read like a shopping cart with occasional text interspersed. This book focuses on the attack methods themselves, rather than the tools. As such it contains information about cracking programs where appropriate, and reads more like an educational journey of hacking methods. When many similar tools are available, only a few are described in depth, and eliminating duplication when possible, leaving you with the right information to decide which tool or tools are best for you.

One of the things that I really appreciated about this book is how the authors will start off topics with home-grown examples before discussing advanced security tools. For example, the authors give you a simple shell script that could function as a crude file integrity checker to provide you a clear method of understanding the concept before going onto detailed configuration examples of tripwire, Aide, and others. While they do not take up much space for these primers, usually half a page or so, they are excellent examples of speaking through code, rather than magician wave-of-the-hand explanations.

Conclusion Hacking Linux Exposed is a very good read. It does a great job of staying focused and interesting, without skimping on the actual details you need to secure your systems and understand the threats. The countermeasures are real and specific, allowing administrators to use this book as a tool to secure their own systems.

At many times I wished that the book were more Unix-centric than simply Linux centric. Many of the issues are similar, and the countermeasures would simply be broken down into *BSD vs Linux vs Solaris, etc. However that would have made reading the countermeasures a bit more difficult. As it is, many of the issues have similar or identical countermeasures, regardless of OS, so administrators should be able to extend what is said to their Unix OS of choice without too much trouble.

The Linux focus allows the authors to get much more in depth than they were able to in Hacking Exposed, which was disjointed at times, unable to really probe each issue. However the opposite is also true --- since they wanted to focus on Linux-specific attacks, they do not go into general attacks, such as JavaScript, cross site scripting, and other browser-related problems, for example. For these types of attacks you should look elsewhere. I think keeping the focus clean is very much worth it.

Beginning administrators may find some of the lead-up lacking in places. For example someone who is not very knowledgeable about IP may have trouble understanding some of the sophisticated network abuses and malformed packets described. However this is to be expected. This book is not standalone, nor should it be. If the HLE authors included enough information to adequately describe every nuance of IP packets then that'd be a disservice to those who already have a copy of W. Richard Stevens, and would needlessly add weight to a book that is supposed to stay focused on hacking.

The book has a website that includes all the source code in the book, released under the GPL, as well as some tools they wrote which they didn't feel belonged in the book itself. They also have book corrections on the website, as well as sections they had wished to put in the book that were rejected by the editor, such as their stance on the "Hacking vs Cracking" semantics debate, and why "Linux is Securable" (as opposed to Windows.) Needless to say, these folks won't be employed by Microsoft in the near future.

I highly recommend this book. You'll have ready-to-implement measures that can keep you busy for some time securing your systems. You'll learn a lot on the journey. And I look forward to seeing "Hacking Windows 2000 Exposed" later this year --- I can only assume it'll say "Install Linux."

You can purchase this book at FatBrain.

106 comments

  1. frist poo! by Anonymous Coward · · Score: -1, Offtopic

    first porst!

    frsiky frisky!

    1. Re:frist poo! by cyborg_monkey · · Score: -1

      Looky here! I am the FIRST POST monkey!

    2. Re:frist poo! by j0nkatz · · Score: -1

      werd up!

      --
      Don't mod me, bro'!!!!
    3. Re:frist poo! by cyborg_monkey · · Score: -1

      w00t!

    4. Re:frist poo! by TrollMan+5000 · · Score: -1

      Howz it hangin', CM?

      Propz to all dead penis birds

    5. Re:frist poo! by cyborg_monkey · · Score: -1

      What is happening, d00d?

      You are getting all worked up about GiZ?

    6. Re:frist poo! by TrollMan+5000 · · Score: -1

      I'm GiZzing all over the place, d00d!

  2. first post! by Anonymous Coward · · Score: -1, Offtopic

    firspos!

  3. FP!! by Anonymous Coward · · Score: -1, Offtopic

    first post!

  4. FIRST FROST by Anonymous Coward · · Score: -1, Offtopic

    FRIST PIST

  5. Expose this by ubertroll · · Score: -1


    * g o a t s e x * g o a t s e x * g o a t s e x *
    g g
    o / \ \ / \ o
    a| | \ | | a
    t| `. | | : t
    s` | | \| | s
    e \ | / / \\\ -- \\ : e
    x \ \/ --~~ ~--| \ | x
    * \ \-~ ~-\ | *
    g \ \ .--------.__\| | g
    o \ \_// ((> \ | o
    a \ . C ) _ ((> | / a
    t /\ | C )/ \ (> |/ t
    s / /\| C) | (> / \ s
    e | ( C__)\__/ // / / \ e
    x | \ | \\__// (/ | x
    * | \ \) `---- --' | *
    g | \ \ / / | g
    o | / | | \ | o
    a | | / \ \ | a
    t | / / | | \ |t
    s | / / \/\/ | |s
    e | / / | | | |e
    x | | | | | |x
    * g o a t s e x * g o a t s e x * g o a t s e x *

  6. fatbrain = rip-off by Anonymous Coward · · Score: -1, Offtopic

    don't give them your e-mail either. They will spam it even when you ask to be removed from their list.

  7. That's a lie! by SpanishInquisition · · Score: -1, Offtopic

    You cannot hack Linux, it's impossible, Linux is perfect.
    Burn him! Burn him!

    --
    Je t'aime Stéphanie
    1. Re:That's a lie! by Spootnik · · Score: -1

      Linux? Don't you mean Stallman/GNU/Linux?

  8. Excellent Book by BiggestPOS · · Score: 1
    I bought original Hacking Exposed a while back, and then the second edition came out and I felt shafted... But then I moved in with a new room-mate who had the second edition and all was well again. It will probably be a race to see which of us can get this one first....

    I love the previous books from these guys though, very detailed, and great info. Everyone should pick it up.

    --
    What, me worry?
  9. Linux by ubertroll · · Score: -1

    db d888888b d8b db db db db db
    88 `88' 888o 88 88 88 `8b d8'
    88 88 88V8o 88 88 88 `8bd8'
    88 88 88 V8o88 88 88 .dPYb.
    88booo. .88. 88 V888 88b d88 .8P Y8.
    Y88888P Y888888P VP V8P ~Y8888P' YP YP

    .d8888. db db db db .d88b. d8888b. d88888D
    88' YP 88 88 `8b d8' .8P 88. 88 `8D YP d8'
    `8bo. 88 88 `8bd8' 88 d'88 88oobY' d8'
    `Y8b. 88 88 .dPYb. 88 d' 88 88`8b d8'
    db 8D 88b d88 .8P Y8. `88 d8' 88 `88. d8' db
    `8888Y' ~Y8888P' YP YP `Y88P' 88 YD d88888P

  10. Linux Hackable? by Anonymous Coward · · Score: -1, Offtopic

    RESUME:

    Timothy
    http://www.monkey.org/~timothy/

    SEEKING: Senior ditorial position for high-traffic website

    QUALIFICATIONS: Until recently, I was an editor for a volatile discussion board (http://www.slashdot.org) primarily advocating the prefixing of GNU/ onto everything. Created, maintained, and modified dynamic web pages....

  11. FIRST REPLY! by Anonymous Coward · · Score: -1, Offtopic
    wh00t



    Hacking Linux Exposed


















    faq

    code

    osdn

    awards

    privacy

    journals

    older stuff

    rob's page

    preferences

    submit story

    advertising

    supporters

    past polls

    topics

    about

    bugs

    jobs

    hof




    Sections

    9/18


    apache


    9/20 (8)


    askslashdot


    9/19 (1)


    books


    9/19 (1)


    bsd


    9/20 (2)


    developers


    9/19 (1)


    features


    9/14


    interviews


    6/29


    radio


    9/21 (9)


    science


    9/20 (4)


    yro


    OSDN

    freshmeat

    Linux.com

    SourceForge

    ThinkGeek

    NewsForge

    SlashCode



    Slow Down Cowboy!

    Slashdot requires you to wait 20 seconds between
    hitting 'reply' and submitting a comment.


    It's been 16 seconds since you hit 'reply'!



    If you this error seems to be incorrect, please provide the following in your report to
    Source Forge:

    • Browser type
    • User ID/Nickname or AC
    • What steps caused this error
    • Whether or not you know your ISP to be using a proxy or some sort of service that gives you an IP that others
      are using simultaneously.
    • How many posts to this form you successfully submitted during the day

    * Please choose 'formkeys' for the category!

    Thank you.

    I did this 'cause Linux gives me a woody. It doesn't generate revenue.
    (Dave '-ddt->` Taylor, announcing DOOM for Linux)


    All trademarks and copyrights on this
    page are owned by their respective owners. Comments
    are owned by the Poster.
    The Rest © 1997-2001 OSDN.

    [
    home |
    awards |
    supporters |
    rob's homepage |
    contribute story |
    older articles |
    OSDN |
    advertising |
    past polls |
    about |
    faq ]

  12. Linux is impossible? by ubertroll · · Score: -1
    oo oooo oo oo oo oo oo oo
    oo oo ooo oo oo oo oo oo
    oo oo oooo oo oo oo oooo
    oo oo oo oo oo oo oo oo
    oo oo oo oooo oo oo oooo
    oo oo oo ooo oo oo oo oo
    ooooooo oooo oo oo oooooo oo oo

    ssssss ss ss ssssss ss ss ssssss ss
    ss ss ss ss ss ss ss ss ss ss ss
    ss ss ss ss ss ss ss ss
    ssssss ss ss ss sssss ssssss ss
    ss ss ss ss ss ss ss ss
    ss ss ss ss ss ss ss ss ss ss
    ssssss ssssss ssssss ss ss ssssss ss

    (But burn him anyway)

  13. Oh my god! by Anonymous Coward · · Score: -1, Offtopic

    *** PLEASE READ THIS *** URGENT ***

    Those damned terrorists just took out the Empire State Building and Sears towers! The Empire State Building is still standing but the Sears went down 35 minutes after it was hit. There are also reports of a gas attack on Boston. Another plane was shot down on its way to the capital.

    Yahoo has the terrible details here.

    *** UPDATE ***

    It seems the Empire State building has finally collapsed! Fire and medical officials are afraid to go in after authorities received threats of anthrax bombs in the plane! Over 25,000 dead in Boston!!

    I can't write anymore sorry

    1. Re:Oh my god! by Anonymous Coward · · Score: -1, Offtopic

      As far beneath contempt as you are, you miserable pathetic little piece of offal, and undeserving of any response, nonetheless: The fact that you would try to take advantage of the deaths of thousands, an event that has brought America to the brink of war, and created widespread fear and untold sorrow, as a springboard to attempt to propagate your pathetic little scrap of virtual vandalism, marks you as a coward, an idiot, a vile turd-eating moron, and a disgusting blob of diseased excrement that needs very badly to be flushed. Take a look at yourself in the mirror next time you rush to the bathroom to pull on your pud, and accept the grave reality that everyone who knows you hates you, and that you hate yourself, that women blanch in disgust at the site of you and snicker at you behind your back, and that the world would be an inestimably better place if you never left your room.

  14. Kill all AC fuckheads. Destroy Sporks. Exterminate by Anonymous Coward · · Score: -1, Offtopic

    Our precious slashdot users scream out for vengeance:

    1. Kill all Trolls.
    2. Kill all Sporks.
    3. Kill all Monkeys.
    4. Kill all Trollmans.
    5. Kill all Buttfuckers.
    6. Kill all AC fuckheads.
    7. Kill all Jeff Ks.
    8. Kill all SpanishInquisitions.
    9. Nuke Adequacy to hell.
    10. Nuke Geekizoid again.
    11. Death to Goatsex.

    I piss on First Posts. I wipe my ass with "If I ever meet you..." I spit on "*BSD is dying."

  15. Re:Kill all AC fuckheads. Destroy Sporks. Extermin by Anonymous Coward · · Score: -1, Offtopic

    I regret to inform you that you, sir, are a raging homosexual.

  16. Re:Kill all AC fuckheads. Destroy Sporks. Extermin by Anonymous Coward · · Score: -1, Offtopic

    you got it!

    come over here, boy!

  17. That's great by cyborg_monkey_sucks · · Score: -1, Offtopic

    Sucker.

    1. Re:That's great by cyborg_monkey · · Score: -1

      Hey there you big fag!

      The real cyborg_monkey has UID 666

    2. Re:That's great by cyborg_monkey_sucks · · Score: -1, Offtopic

      The real cyborg_monkey has UID i_suck

    3. Re:That's great by cyborg_monkey · · Score: -1

      Is that all you can do? You went through the effort of creating that account and all you can do is that lame shit?

      what a fucking waste of air, you are. Die, faggot, Die!

  18. Cracking Linux Exposed by Anonymous Coward · · Score: 0

    I thought cracking linux exposed would be a more elegant title, as I was hoping it had a bit more about the ins and outs of coding the linux kernel.

    1. Re:Cracking Linux Exposed by ackthpt · · Score: 1

      Here I was, reading the title of the article and thinking "Hacking Linux while nekkid...hmm" Not that a book on such would be a bad idea (Chap. 1: How to Keep Your Body Bits From Accidently Hitting Keys)

      --

      A feeling of having made the same mistake before: Deja Foobar
  19. Can some one hack lnux's stock by Anonymous Coward · · Score: -1, Troll

    It is in the crapper (sub-$1) suck to be RMS.

  20. Linux security by Anonymous Coward · · Score: -1, Offtopic

    Linux will always be safer because it's main codebase is based on BoumOS which was released in 1988, later took by that dude, Tanembaum which later was ripped off by Linox Torvalds who released Linox.

  21. Bad Title by Anonymous Coward · · Score: 1, Insightful

    This gives all the Hackers in the world a bad name. Just because we right code for a living/hobby doesn't mean we are trying to break into your system.
    It should be Crackering Linux Exposed.

    Hacking Linux Exposed should be a book about how to modify the kernel or maybe how to make drivers in the linux kernel.

    ~Anonymous Coward

  22. Big prediction by almightyjustin · · Score: 1
    as is a prediction that other worms may be on the horizon, which turned out to be all too true.

    Wow, such prescience! I, for one, would never have guessed that! ;)

    --

    Omnes arx vestrum sunt adiuncta nobis.

    1. Re:Big prediction by kilgore_47 · · Score: 2

      Well I for one am certain that the Nimda worm is the last worm we'll ever see. See, the president of my fine country has declared war on evil. As such, all evil will soon be destroyed. So just sit back, relax, and enjoy the ride.

      --
      ___
      The way to see by faith is to shut the eye of reason. --Ben Franklin
  23. Hacking? by Stormie · · Score: 3, Insightful

    So, who'll be the first to complain that it should have been called "Cracking Linux Exposed" ..?

    1. Re:Hacking? by Dexx · · Score: 1

      It's been done - check the lower scored posts..

      --
      Feel the fear and do it anyway.
    2. Re:Hacking? by Stormie · · Score: 1

      It's been done - check the lower scored posts..

      Indeed. Not only did I learn that it had been done, but also that the Empire State Building had been destroyed by a terrorist with a hugely distended rectum.

    3. Re:Hacking? by kubrick · · Score: 1

      So, who'll be the first to complain that it should have been called "Cracking Linux Exposed" ..?

      An Anonymous Coward 8 minutes before you. :)

      --
      deus does not exist but if he does
    4. Re:Hacking? by asv108 · · Score: 1

      Maybe if they were trying to market this book for the slashdot crowd, but the fact is most mainstream IT people don't know about the whole "hacking vs. cracking debate" and I don't see anything changing soon. Hacking was picked up as a way to describe computer crime in the mid-80's by the media. If the book was titled "Cracking Linux Exposed" it would not sell nearly as well as "Hacking Linux Exposed."

    5. Re:Hacking? by Brian+Hatch · · Score: 1
      Who will be the first to complain about the title? That'd be Brian Hatch and James Lee. (George had already fought this battle with HE).

      You can't win against the publisher/editor. We tried. We fought for almost the whole time we were writing. We lost.

      See our take on it at hackers_vs_crackers on our website.

      Trust me, we were not pleased either.

    6. Re:Hacking? by moonboy · · Score: 2



      Or...."Hacking GNU/Linux Exposed"? DOH!

      --

      Co-founder and designer at Music Nearby: http://musicnearby.com
    7. Re:Hacking? by ethereal · · Score: 1

      Oh no! Only federally-mandated key escrow can protect us from clicking on those diabolical links!

      It has been more-or-less a reign of terror, though - I'm terrified that my boss will accidentally see that guy's bum displayed on my screen and get the wrong idea about me :)

      --

      Your right to not believe: Americans United for Separation of Church and

  24. Sucking? by ubertroll · · Score: -1

    So, who'll be the first to complain that it should have been called "Linux Sucking Exposed" ..?

  25. my favorite security book to come out lately by dfelznic · · Score: 1

    My favorite security book to come out lately has been:White-Hat Security Arsenal: Tackling the Threat by Aviel Rubin
    I sawm mcclure and kurtz at usenix. They were doing a talk about network security. Not a whole lot of new info but they are a good team for presentations. The original Hacking Exposed was pretty good too...

  26. Wow... Another "8.5" review. by Anonymous Coward · · Score: 0

    Hey, is the rank of "8.5" hard coded into Slashcode? Why is it that almost every book reviewed here gets an 8.5? Hows about some diversity? Give a book a 5 for a change...

  27. Linus Exposed? by Trollbi-Wan+Kenobi · · Score: 0

    Tell him to put his clothes back on. Perv.

  28. Nimda by kevinank · · Score: 3, Interesting

    So I checked my web server error logs last night, and counted up how many times my box has been attacked. I have over two thousand individual hits from a single IP address (you'd think that the scanner would give up after one try.) About 170 distinct IP's have tried scanning me.

    Mailing abuse seems to be ignored these days; are all of the ISPs scaling back their security staff at the same time as more virulent attacks are released to the net? If anyone has any other suggestions of what to do with these attacks, I'd love to hear it.

    --
    LibBT: BitTorrent for C - small - fast - clean (Now Versio
    1. Re:Nimda by Trollbi-Wan+Kenobi · · Score: 0

      If anyone has any other suggestions of what to do with these attacks, I'd love to hear it.

      Turn off your computer and go out fishing. Take a couple of friends and some beers and enjoy the beauty of nature. Even if you didn't catch anything at least you spent some time outdoors in the sunshine. Or if you don't like fishing you could go to a local park with a book.

      Always look on the bright side of life...

    2. Re:Nimda by kevinank · · Score: 2

      Well, that computer is my mail server and web server among other things, so it never gets turned off. On the other hand I don't exactly sit in front of it all day. It doesn't even have a keyboard or mouse attached to it.

      I do grok the need to spend time away from the keyboard though; my latest project is tearing walls out of an extension that was added to my house in the early 70's, and framing in a new wall for a wine cellar. Just pulled off the last of the old dry wall last night...

      Never the less, when I am online, I'd like to do something to get these viruses to stop propagating. I've tried messaging the operators through smbclient: smblookup -A [...] LOGIN smbclient -U security -I -M LOGIN This machine has been infected with a virus! Please get the latest updates for Microsoft IIS, and install some up to date virus checking software. Until then your machine is spreading that virus through the web, so please shut it off. ^D

      Hasn't had any effect so far. I doubt anyone ever looks at the consoles of these woefully unmaintained machines.

      --
      LibBT: BitTorrent for C - small - fast - clean (Now Versio
    3. Re:Nimda by kevinank · · Score: 2

      ...sorry about the formatting of the previous post. When was <pre> removed from the list of approved HTML tags?

      Well, that computer is my mail server and web server among other things, so it never gets turned off. On the other hand I don't exactly sit in front of it all day. It doesn't even have a keyboard or mouse attached to it.

      I do grok the need to spend time away from the keyboard though; my latest project is tearing walls out of an extension that was added to my house in the early 70's, and framing in a new wall for a wine cellar. Just pulled off the last of the old dry wall last night...

      Never the less, when I am online, I'd like to do something to get these viruses to stop propagating. I've tried messaging the operators through smbclient:

      smblookup -A <ipaddr>
      [...]
      LOGIN <03>
      smbclient -U security -I <ipaddr> -M LOGIN
      This machine has been infected with a virus!
      Please get the latest updates for Microsoft
      IIS, and install some up to date virus checking
      software. Until then your machine is spreading
      that virus through the web, so please shut it
      off.
      ^D

      Hasn't had any effect so far. I doubt anyone ever looks at the consoles of these woefully unmaintained machines.

      --
      LibBT: BitTorrent for C - small - fast - clean (Now Versio
    4. Re:Nimda by belphegore · · Score: 1

      2000 hits from a single IP is probably something like 200 machines, all infected, sitting behind a NAT box or something similar. Possibly a web farm of 200 odd boxen sharing an ip address... Remember that one IP address does not mean one computer.

    5. Re:Nimda by Col.+Panic · · Score: 1
      If anyone has any other suggestions of what to do with these attacks, I'd love to hear it.

      Sure - post the attacker's ip address on alt.2600.hackerz and let the kiddies play around with it.

  29. Cracking and Hacking by BierGuzzl · · Score: 3, Informative

    I just think that people who have been using linux enough to write that book should be able to tell the difference between cracking and hacking. Then again, perhaps it was the publisher that forced this title? I mean, the word "hacking" has been so popularized, it's without a doubt going to generate more sales.

    1. Re:Cracking and Hacking by SCHecklerX · · Score: 4, Insightful
      The accepted meanings and use of words change over time. Hacking is now used both to describe 'hacking on some code' and 'hacking into a computer'


      Deal with it.

    2. Re:Cracking and Hacking by Anonymous Coward · · Score: 0

      Looks like it means lots of things.

      As for me, I'm a "deep dweeb." :-)

      ---
      hack1 (hk)
      v. hacked, hacking, hacks
      v. tr.
      To cut or chop with repeated and irregular blows: hacked down the saplings.
      To break up the surface of (soil).

      Informal. To alter (a computer program): hacked her text editor to read HTML.
      To gain access to (a computer file or network) illegally or without authorization: hacked the firm's personnel database.
      Slang. To cut or mutilate as if by hacking: hacked millions off the budget.
      Slang. To cope with successfully; manage: couldn't hack a second job.

      v. intr.
      To chop or cut something by hacking.
      Informal.
      To write or refine computer programs skillfully.
      To use one's skill in computer programming to gain illegal or unauthorized access to a file or network: hacked into the company's intranet.
      To cough roughly or harshly.

      n.
      A rough, irregular cut made by hacking.
      A tool, such as a hoe, used for hacking.
      A blow made by hacking.
      A rough, dry cough.

  30. Oh my God!! WW3!! by Anonymous Coward · · Score: -1, Troll

    *** PLEASE READ THIS *** URGENT ***

    Those damned terrorists just took out the Empire State Building and Sears towers! The Empire State Building is still standing but the Sears went down 35 minutes after it was hit. There are also reports of a gas attack on Boston. Another plane was shot down on its way to the capital.

    Yahoo has the terrible details here.

    *** UPDATE ***

    It seems the Empire State building has finally collapsed! Fire and medical officials are afraid to go in after authorities received threats of anthrax bombs in the plane! Over 25,000 dead in Boston!!

    I can't write anymore sorry

    1. Re:Oh my God!! WW3!! by Anonymous Coward · · Score: -1, Offtopic

      What's it like to get up every morning and know that everyone despises you and that you'll never have sex with a woman you don't have to pay?

    2. Re:Oh my God!! WW3!! by Anonymous Coward · · Score: -1, Offtopic

      Tell me.

    3. Re:Oh my God!! WW3!! by Anonymous Coward · · Score: -1, Offtopic

      not that bad actually

    4. Re:Oh my God!! WW3!! by Anonymous Coward · · Score: -1, Offtopic

      i fuck my sister every day
      i don't have to pay her
      just suck her feet all the time
      and let her keep me on a leash

    5. Re:Oh my God!! WW3!! by Anonymous Coward · · Score: -1, Offtopic

      my god ur sick
      no wait... that's TURNING ME ON!!!
      *hides his penis*

  31. From the looks of it by wiredog · · Score: 2

    You. ;-)

  32. GPL? by baalzebuth · · Score: 2, Insightful

    "The book has a website that includes all the source code in the book, released under the GPL,"

    Then why do I need a username and password to download the stuff? I think this is not very GPL-like...

    Baal

    1. Re:GPL? by dark_panda · · Score: 2

      i'm not 100% sure on this, but doesn't the GPL basically say that you need to distribute source and such to *your* users, and not necessarily every single computer user out there? if someone didn't buy the book or the accompanying software, then the publishers aren't required to distribute source code to them.

      it might not be GPL-like in spirit, but it's still GPL-like. unless, i'm totally wrong, in which case, i'll just add that IANAL or a GPL expert.

      J

    2. Re: GPL? by Brian+Hatch · · Score: 1
      2 words: External Requirements.

      Divining who made said requirements is left as an exercise to the reader.

    3. Re: GPL? by Chagrin · · Score: 2

      Who made that requirement? The publisher?

      --

      I/O Error G-17: Aborting Installation

  33. Re:Kill all AC fuckheads. Destroy Sporks. Extermin by l33t+j03 · · Score: -1
    I am pleased to see that you approve of my personal crusade to dash the hopes and dreams of all OSS businessmen by showing the world that proprietary software is superior in every way to anything the OSS conspiracy has ever put out. Although you can't really be trusted (you call for own death in #6) I nonethless appreciate the vote of confidence.

    Thank you for your support.

  34. Give it up! (was Re:Bad Title) by statusbar · · Score: 1

    I think it is time to GIVE UP the hacker title. The original meaning is lost forever. Call yourself a 'Computer Programmer' instead and everyone will be happier and will not be confused anymore.

    Everyone knows that Hackers are all terrorists, anyways!

    --jeff

    --
    ipv6 is my vpn
    1. Re:Give it up! (was Re:Bad Title) by Anonymous Coward · · Score: 0

      I'd hope that all "Linux Hackers" were computer programmers though... Otherwise we would be seeing perl scripts in the kernel source... and we can't have that.
      But I know people who will argue that "scripting" is a form of "programming".

      ~Anonymous Coward again

    2. Re:Give it up! (was Re:Bad Title) by jiheison · · Score: 1

      Unless you are compiling the code by hand, I fail to see the difference.

    3. Re:Give it up! (was Re:Bad Title) by Anonymous Coward · · Score: 0
      I think it is time to GIVE UP the hacker title. The original meaning is lost forever. Call yourself a 'Computer Programmer'

      Naw, I call myself a p0rn star. Great for mixing at parties.

      Hi, what do you do?
      Oh, I work with IBM.
      Really, so you're a programmer?
      Naw, I'm a p0rn star.
      More people ask me for my autograph now.
    4. Re:Give it up! (was Re:Bad Title) by PalmKiller · · Score: 1

      The difference is the ones that really worry about the distinction probably watched way to many hacker movies and feel as if the term matters. Real hackers (not the cracker type, though most hackers do reverse engineer and break security measures to figure out things) have more important things to worry about like food, sleep and hacking on their systems.

  35. FUD by Anonymous Coward · · Score: 0

    "I look forward to seeing "Hacking Windows 2000 Exposed" later this year --- I can only assume it'll say "Install Linux."

    no, try learning a little about how to administer Win2K instead.

    asshole.

    1. Re:FUD by Anonymous Coward · · Score: 0

      Maybe they don't write "Hacking Win2K Exposed"
      because it will have more than 10,000 pages!

      :-)

    2. Re:FUD by linuxelf · · Score: 1

      Or perhaps they won't write it because, hey, who can't hack Windows 2000??

      --
      - "That's just the kind of fuzzy-headed liberal thinking that leads to being eaten."
  36. Computer programmers? Bah! by roie_m · · Score: 1

    Well, I don't know whether the "hacker" title is a lost cause, but the "computer programmer" title is just not a good idea. Hackers are not all computer programmers, nor are all computer programmers hackers!

    1. Re:Computer programmers? Bah! by SCHecklerX · · Score: 3, Funny

      I've been a hacker for about a month and a half now.

      Damned allergies. *HACK* *COUGH* *HACK*

  37. ROFLMAO +1 Funny by Anonymous Coward · · Score: -1, Offtopic

    someone mod this up! Jeers to those making light of the tragedy, but your comment was just funny!

  38. If Linux were "all great" by Anonymous Coward · · Score: 0

    it should be unhackable or at least extremely difficult to do so.

  39. Who'll be the first to read the article? by Anonymous Coward · · Score: 1, Informative

    They also have book corrections on the website, as well as sections they had wished to put in the book that were rejected by the editor, such as their stance on the "Hacking vs Cracking" semantics debate, and why "Linux is Securable" (as opposed to Windows.)

  40. Re:Kill all AC fuckheads. Destroy Sporks. Extermin by TrollMan+5000 · · Score: -1

    4. Kill all Trollmans.

    Yeah? Bring it on, motherfucker!!

    Mad propz to cyborg_monkey, mackga and ALL SPORKS!

  41. It is a sign by Anonymous Coward · · Score: 0
    It is a sign how blind the community can be. A book like this comes out, and instead of discussion about ways to prevent security problems from happening, all the discussion burns the guy for saying "hacking" instead of "cracking"


    Give it a rest, the only people who feel that "hacking" and "cracking" are two different things is you. Turn your attention to making things better.

  42. Lucky You! by MadCow42 · · Score: 3, Funny

    Lucky you... I've had over 17000 hits from 800+ unique IP's using Nimda.

    My Apache error log has gone from an average of 80k/week (mostly robot.txt hits) to 2.6MB in 1.5 days!

    Oh well, it could be worse, I could be running IIS.

    MadCow.

    --
    I used to have a sig, but I set it free and it never came back.
  43. Unix code red chicken head by Anonymous Coward · · Score: 0

    unix code red chicken head

    command processing overhead

    Hacking linux oyster bed

    go ahead

  44. Intelligent Banter by huckda · · Score: 1

    Great Review!
    I have read previous versions(In Portugese) and one of the main reasons I bought the book was because it had documentation via examples of issues I was trying to resolve on my own machine.
    So while in Brasil I saw a copy and snagged it...
    Oddly enough, all 'code examples' were in english while the explanations were in Portugese...anyhow, the book is a GREAT resource and your review definately did justice to the time and experience illustrated in the book.

    Kudos!

    --
    "Just Smile and Nod." --Huck
  45. We're loosing this battle by Brian+Hatch · · Score: 1

    In case you haven't noticed, the media doesn't like making distinctions that may confuse them or their readers. Though we may think the subversion of 'hacker' into 'cracker/attacker/script kiddie/etc' is a genuine loss, they don't understand. And I don't know how to fix it, especially since most publishers aren't willing to make the distinction either.

  46. So uncalled for :) by Dog+and+Pony · · Score: 1


    And I look forward to seeing "Hacking Windows 2000 Exposed" later this year --- I can only assume it'll say "Install Linux."

    But of course, an easy way to score cheap points around here. :)

    Seems like a Really sweet book though, it goes straight up to top three on my wish list!

  47. Translations by Brian+Hatch · · Score: 1
    Sorry to hear about the mix of english/portugese. The original authors don't do the translations. If we did then we'd need to rely on Babelfish anyway, and who knows how nasty it'd end up. Hmmn, let's try a random line from chapter 10:

    English:
    Most script kiddies will not have the attention span or coding skills to successfully trojan all the programs that are necessary to hide themselves.

    Portugese via Babelfish:
    A maioria de kiddies do certificado não terão as habilidades da extensão ou do coding da atenção com sucesso a Trojan todos os programas que são necessários para se esconder.

    Back to English:
    The majority of kiddies of the certificate nao terao the abilities of extensao or coding of atencao successfully the Trojan all the necessarios programs that sao to hide itself.

    Yeah, that's bad.

  48. Site? by Anonymous Coward · · Score: 0
    women blanch in disgust at the site of you

    URL, please!

    1. Re:Site? by Anonymous Coward · · Score: 0

      I once saw an mpeg of some girl having a guy cum on her face. At one point, a spurt hit her right in the eye. She totally blanched. She looked like she was about to cry and throw up at the same time.

  49. Hacking is used correctly in this title by iplayfast · · Score: 1
    A Hacker is someone who likes to dive into the guts of either hardware or software. This book does that, (and also looks at Cracker stuff as well).

    I for one am glad to see the word used correctly.

  50. Wait! Don't do that ... by Col.+Panic · · Score: 1
    (appypolylogies for following my own post, but ...)

    *after* I hit "submit" I saw the heading on your message. If these are attacks from Nimba the people on the other end are sure to be clueless about the problem and advertising their IP address will, uh, do no good.

    You might try a phone call the the administrative contact for the host.

  51. ThinkGeek doesn't have it! by kilgore_47 · · Score: 2

    While reading a review for a hacking book on this VA-Linux-owned site, I saw a banner ad for hacking books at another VA-Linux-owned site (thinkgeek).

    While one might think ThinkGeek would be selling the book, they are not.
    Oh well, over to amazon I guess....

    --
    ___
    The way to see by faith is to shut the eye of reason. --Ben Franklin
  52. Nomenclature. by saintlupus · · Score: 1

    Call yourself a 'Computer Programmer' instead and everyone will be happier and will not be confused anymore.

    Katzian as it sounds, I prefer "geek" as a replacement for the tarnished term "hacker." It conveys the same sense of fixity and focus on a subject to the exclusion of other things.

    --saint
    (who can't program too well.)

    1. Re:Nomenclature. by statusbar · · Score: 1

      That works for me!

      --jeff

      --
      ipv6 is my vpn
  53. Password-protected source downloads? by JoshuaDFranklin · · Score: 1
    Anyone else thing the
    From
    password-protected source downloads
    is a bit silly?

    Accessing the pages below requires a username/password.

    Username: The name of the network scanning software shown on page 123.
    Password: The kernel module listed on the first line of page 353. (begins with the lower case letter 'i')

    Sheesh, I just wanted to see what their spam.txt was.
  54. Fatbrain does by macdaddy · · Score: 2

    and if you're an IEEE member you get an additional 5% discount. :) I have edition 1 already. I ordered Hacking Linux Exposed and Hacking Exposed: Network Security Secrets & Solutions edition 2 earlier this week. Excellent books.

  55. Amazon, Barnes and Noble, Fatbrain, etc by Anonymous Coward · · Score: 0

    they've got links to the major online booksellers that sell it here

  56. Maximum Linux Secuity by Anonymous by fetta · · Score: 1

    Another good book in the same vein is "Maximum Linux Security" by Anonymous (ISBN: 0672316706 ). Lots of good, concrete desciptions of potential security holes, guides to using a variety of tools, etc.

    --
    ** The opinions expressed here are my own, and do not reflect those of my employers - past, present, or future**
  57. Fatbrain? by mjg · · Score: 2

    Take a look at Bookpool, this book is going for $24.95 there, rather than the $31.95 from Fatbrain.

    I am not associated with Bookpool. I like to save money. So do others. Bookpool is cheaper. Their service is also excellent.

  58. *BSD is dying by Anonymous Coward · · Score: -1, Offtopic
    *BSDis dying

    Yet another crippling bombshell hit th bleaguered *BSD community when last month IDC confirmed that *BSD accounts for less than a frction of 1 percent of ll servers. Coming on the heels of the latest Netcraft survey which plainly states that *BSD has lost more market share, this news serves to reinforce what we've known all along. *BSD is collapsing in complete disarray, as further exemplified by failing dead last in th recent Sys Admin comprehensive networking test.

    You don't need to be a Kreskin to predict *BSD's future. The hand writing is on the wall: *BSD faces a bleak future. In fact there won't be any future at all for *BSD because *BSD is dying. Things are looking very bad for *BSD. As many of us are already aware, *BSD continues to lose market share. Red ink flows like a river of blood. FreeBSD is the most endangered of them all.

    Let's keep to the facts and look at the numbers.

    OpenBSD leader Theo states that there are 7000 users of OpenBSD. How many users of NetBSD are there? Let's see. The number of OpenBSD versus NetBSD posts on Usenet is roughly in ratio of 5 to 1. Therefore there are about 7000/5 = 1400 NetBSD users. BSD/OS posts on Usenet are about half of the volume of NetBSD posts. Therefore there are about 700 users of BSD/OS. A recent article put FreeBSD at about 80 percent of the *BSD market. Therefore there are (7000+1400+700)*4 = 36400 FreeBSD users. This is consistent with the number of FreeBSD Usenet posts.

    Due to the troubles of Walnut Creek, abysmal sales and so on, FreeBSD went out of business and was taken over by BSDI who sell another troubled OS. Now BSDI is also dead, its corpse turned over to yet another charnel house.

    All major surveys show that *BSD has steadily declined in market share. *BSD is very sick nd its long term survival prospects are very dim. If *BSD is to survive at all it will be among OS hobbyist dabblrs. *BSD continues to decay. Nothing short of a miracle could save it at this point in time. For ll practical purposes, *BSD is dead.

    *BSD is dying

  59. Linux not vulnerable -- you're joking! by dhammabum · · Score: 1
    GNU/Linux systems may be more resistant, but are not immune to cracking

    There is a steady flow of exploits from almost all platforms. It is quite misleading to treat non-Windows systems as monolithic -- or Windows even for that matter, they are composed of many subsystems which from time to time contain exploits.

    Linux, FreeBSD, HPUX, IRIX and the rest have heaps of explits out in the wild. Sure patches are developed, but there are quite a few lame users that just install *nix off the CD, just like they do with Windows.

    Please, please, please be more objective!

    --
    I am not a robot. I am a unicorn.
  60. You are pathetic by Anonymous Coward · · Score: 0

    You geek morons want to tell us all that code is art and speech and should be protected, but god forbid that anyone ever express themself in a manner that offends YOU. Apparently you don't understand what free speech is. You do NOT have the right to tell other people that their chosen form of expression is morally wrong. YOU are the one who is at fault, and it is YOU who needs to examine your attitudes towards others.

    Furthermore, I suspect strongly that your closing insults are a case of you projecting your own feelings of inadequacy onto others as a means of maintaining the state of denial in which you live.

  61. Are you MAD? by Anonymous Coward · · Score: 0

    Your post implies that you actually want to hear what slashdot has to say about fixing security problems. I can't imagine a forum less suited to this task. Slashdot readers mix incompetence with egotism. Reading what they have to say on any matter is non-productive. If you think you are learning anything here, you need to seek medical help. There is no real difference between reading what a slashbot thinks about security and reading what a slashbot thinks about goatsex.

  62. It already exists. by zurmikopa · · Score: 1

    It already exists. At least amazon says it does.

    http://www.amazon.com/exec/obidos/ASIN/007219262 3/ qid=1001196177/sr=1-1/ref=sr_1_3_1/002-2092565-984 9639