Reprints     Printer-Friendly    Email this Article    RSS        Font Size     What's This?

[ED Bookstore]

Hacking: The Art of Exploitation


By Jon Erickson
ISBN: 978-1-59327-144-2


William Wong  |   ED Online ID #18492  |   March 18, 2008

Article Rating: Not Rated

Any book that numbers its chapters in hexadecimal can’t be that bad.

Actually the book is quite good. It should prove invaluable to any except those already well versed in the art of exploitation. It can be especially useful to also any C/C++ programmer that wants to avoid problems or at least make it harder for someone to attack their application.

Erickson presents a variety of methods of attack. Some are common such as buffer overflows. Others are less common or have fallen out of vogue for various reasons but the book does more than just cover the basic what and how. While it is definitely not a tome for script kiddies, it is a more thoughtful presentation of the mechanics that are often overlooked in most programming texts. Programmers and security professionals should get a good bit from this book.

Having a background in C/C++ is pretty much a requirement and any exposure to assembler will help. The examples center on the x86 architecture, but most of the open source tools will work on a range of Linux platforms. These include things like a hex editor, dissassembler, and network manipulation and sniffing tools.

The chapter on buffer overflows is probably the most useful and interesting. The sections on networking and shellcode may be the most useful to non-programmers. The Countermeasures chapter varies depending upon the topic but overall it is very good. The cryptography chapter is just right for someone getting started with encryption but this is a complex topic that has a number of books written about the subject already.

This book will take any programmer well beyond the usual programming techniques covered in conventional programming books. It should be viewed as a good introductory text making it a good prerequisite for most programmers in training.




Reprints     Printer-Friendly    Email this Article    RSS        Font Size     What's This?


  • Network-On-Chip Tools Arrive for The Masses
  • Tackling System Design Challenges Through Early Verification
  • ESL Tools Take Center Stage As Designers Move Up
  • Parasitic Extraction Tool Targets Next-Generation Custom ICs
  • Synopsys Jumps Into ESL-Synthesis Pool
  • Verify Control Systems Before Committing To Hardware
  • You're Using How Many FPGAs?
  • Tool Up For The FPGA Blitz
    1) Build A Smart Battery Charger Using A Single-Transistor Circuit
    (189 views today)
    2) Hot Hands For Some Cool Rock: Motion Sensing Meets Audio Engineering
    (162 views today)
    3) Adjustment-Free Fan Controller For Under $1
    (119 views today)
    4) Science Fiction Meets Science Fact In Today's Robot Research
    (106 views today)
    5) What's All This Transimpedance Amplifier Stuff, Anyhow? (Part 1)
    (97 views today)
    ALL TOP 20







    POST YOUR COMMENTS HERE

    Name:

    Email:
    Rate this article:

     less useful more useful 
    1
    2
    3
    4
    5
    Your Comments:

    Enter the text from the image below




    Please refresh the page if you have trouble reading this text.
    (Acceptable Use Policy)
     
     

    PartFinder

    Find real-time pricing, stock status, same-day/next-day shipping options and more. Brought to you by Digi-Key. Go to PartFinder.    
    GlobalSpec

    PART SEARCH :
    Powered by: GlobalSpec - The Engineering Search Engine
    Sponsored Links

    Electronic Design Europe Electronic Design China EEPN Power Electronics Auto Electronics Microwaves & RF
    Mobile Dev & Design Schematics Find Power Products Military Electronics EE Events Related Resources