or
Sign in to turn on 1-Click ordering.
or
Amazon Prime free trial required. Sign up when you check out. Learn more
More Buying Choices
Have one to sell? Sell yours here
or
Get a £0.70 Amazon.co.uk Gift Card
The Shellcoder's Handbook: Discovering and Exploiting Security Holes
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

The Shellcoder's Handbook: Discovering and Exploiting Security Holes [Paperback]

Jack Koziol , David Litchfield , Dave Aitel , Chris Anley , Sinan "noir" Eren , Neel Mehta , Riley Hassell
5.0 out of 5 stars  See all reviews (1 customer review)
RRP: £33.99
Price: £20.47 & this item Delivered FREE in the UK with Super Saver Delivery. See details and conditions
You Save: £13.52 (40%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In stock.
Dispatched from and sold by Amazon.co.uk. Gift-wrap available.
Only 4 left in stock--order soon (more on the way).
Want guaranteed delivery by Saturday, February 11? Choose Express delivery at checkout. See Details
Trade In this Item for up to £0.70
Trade in The Shellcoder's Handbook: Discovering and Exploiting Security Holes for an Amazon.co.uk gift card of up to £0.70, which you can then spend on millions of items across the site. Trade-in values may vary (terms apply). Find more products eligible for trade-in.
There is a newer edition of this item:
The Shellcoder's Handbook: Discovering and Exploiting Security Holes The Shellcoder's Handbook: Discovering and Exploiting Security Holes 5.0 out of 5 stars (1)
£18.65
In stock.

Customers Who Bought This Item Also Bought


Product details

  • Paperback: 644 pages
  • Publisher: John Wiley & Sons (2 April 2004)
  • Language English
  • ISBN-10: 0764544683
  • ISBN-13: 978-0764544682
  • Product Dimensions: 23.6 x 19 x 3.6 cm
  • Average Customer Review: 5.0 out of 5 stars  See all reviews (1 customer review)
  • Amazon Bestsellers Rank: 442,745 in Books (See Top 100 in Books)
  • See Complete Table of Contents

Product Description

Review

“…80%…anyone developing their own software may be surprised by how easily flaws can be exploited and fixed…” (PC Utilities, July 2004)

“…essential for administrators who want to secure computer systems under their management…” (Computer Weekly, March 2004)

"...has caused some raised eyebrows in the technical community..." (www.infoworld.com, 17 March 2004)

Computer Weekly, March 2004

"...essential for administrators who want to secure computer systems under their management..."

Inside This Book (Learn More)
First Sentence
In order to understand the content of this book, you need a well-developed understanding of computer languages, operating systems, and architectures. Read the first page
Explore More
Concordance
Browse Sample Pages
Front Cover | Copyright | Table of Contents | Excerpt | Index | Back Cover
Search inside this book:

Suggested Tags from Similar Products

 (What's this?)
Be the first one to add a relevant tag (keyword that's strongly related to this product)
 

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more


 

Customer Reviews

1 Review
5 star:
 (1)
4 star:    (0)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
5.0 out of 5 stars (1 customer review)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

5 of 6 people found the following review helpful:
5.0 out of 5 stars Strickly for the serious pen testers!!!, 26 Nov 2004
By A Customer
This review is from: The Shellcoder's Handbook: Discovering and Exploiting Security Holes (Paperback)
The authors of this book are well known in the industry and they really lived up to the expectations. I recommend this book for the serious pen testers who want to sharpen their skills and take it to another level. You discover security holes and close them using some pretty neat techniques. There is good coverage of various platforms but remember this is strickly for the serious pen testers.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
Most Helpful Customer Reviews on Amazon.com (beta)
Amazon.com: 4.5 out of 5 stars (21 customer reviews)

91 of 93 people found the following review helpful:
4.0 out of 5 stars Excellent material, but..., 11 May 2004
By Omar A. Herrera Reyna - Published on Amazon.com
This review is from: The Shellcoder's Handbook: Discovering and Exploiting Security Holes (Paperback)
Not for beginners as others have previously stated, you require deep knowledge of C, assembler and IA32 architecture as well as some knowledge of the Linux and Windows operating systems. If you have this then it will suffice (Even if you have not ever heard of a buffer overflow before).

What amazes me, and the reason of me not giving five stars to the book, is the enormous amount of errors in the book (no one else has talked about this on previous reviews). These go from forgetting to include memory allocation routines in some sample code and putting incorrect labels in some diagrams to talking about certain parts of code while actually showing completely different lines of code or talking about different addresses in the explanations from the ones on the sample code and program output that they talk about.

For example, on page 90 the authors wrote:

" Let's take a look at two assembly instructions that correspond to the free() routine finding the previous chunk

0x42073ff8 <_int_free+136>: mov 0xfffffff8 (%edx),%eax
0x42073ffb <_int_free+139>: sub %eax,%esi

In the first instruction (mov 0x8 (%esi), %edx), %edx is 0x80499b8, the address of..."

The instruction being referred to at the last sentence should be "mov 0xfffffff8 (%edx),%eax". "mov 0x8 (%esi), %edx" appears many lines below this paragraph, in another code sample, and it is completely unrelated to the explanation given there.

Of course, people familiar with these topics who also have a deep knowledge of the required programming languages and architectures will catch these flaws easily. The problem is that there are so many of them that it gets annoying at some point and you end asking yourself why do the editorial reviewers didn't do their job properly.

Also, I bought this book almost as soon as it went out for sale, yet as of this date (may 2004), the only material found in the web page of the book is the source code to most of the examples. Definitely much less compared to all the material that the authors promised in the book to be there (so don't expect to find more than this).

It is an excellent reference book though, and if you take the time to read the book thoroughly and make notes to fix the errors in the book you will find that even this activity is rewarding. Some might even argue that the authors put the errors there on purpose to keep script kiddies away from this knowledge, but I don't think that would be OK with a book like this which has created so much expectation. Hopefully the next edition will have all this fixed.


24 of 24 people found the following review helpful:
4.0 out of 5 stars Amazing, 8 April 2004
By Elijah D "dev1zero" - Published on Amazon.com
This review is from: The Shellcoder's Handbook: Discovering and Exploiting Security Holes (Paperback)
I've always been facinated by the amount of work security researchers put into finding vulnerabilities. This is a very good book on software vulnerabilities. It's also very current as it examines a number of the recently widely publicized vulnerabilities. It also rightly points out the fact that Linux/Unix are not as secure as a lot of people out there would like the public to believe.

The ways to get around stack protection outlined in this book was an eye opener for me.

I thought I had very good knowledge of the material the book covers until I actually read it. It is clear that as software shops continue to plug vulnerabilties, people will continue to find new ways to exploit software.

Clearly, this book is not for the casual reader. This is essentially a book for people who have above average assembly language and c/c++ skills.


25 of 29 people found the following review helpful:
5.0 out of 5 stars Excellent security book although misleading title, 21 May 2004
By AdV - Published on Amazon.com
This review is from: The Shellcoder's Handbook: Discovering and Exploiting Security Holes (Paperback)
The title "Shellcoder's handbook" made me reluctant to even buy this book. I thought it would go about explaining exploiting stack, heap overruns, bypassing memory exploitation methods and so on in order to execute shell code: basically, a book for hacking and I didn't like that. Nonetheless, it took me a glance of the list of authors and the table of contents to realize that this book goes beyond exploitation and into core penetration testing and vulnerability discovery methods. Hopefully, like rational and ethical software security engineers will do, this book will be used more for vulnerability discovery and benign exploitation rather than malicious exploitation.

Parts 1 and 2 are a great introduction of OS internal, system calls, memory management, and in-depth analysis of security bug exploitation; thus making them relevant for part 3: "Vulnerability Discovery". Part 3 goes into great depth on how discover security bugs. No so often do we have the brightest minds in the art of software vulnerability discovery, penetration testing, or "ethical hacking" joining forces. The variety of ways to discover security bugs is what we need to learn in order to ship secure software or to successfully secure existing software applications. Great Job!

 Go to Amazon.com to see all 21 reviews  4.5 out of 5 stars 
Were these reviews helpful?   Let us know
 
 
Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 

Search Customer Discussions
Search all Amazon discussions
   


Listmania!


Look for similar items by category


Look for similar items by subject


Feedback


Amazon.co.uk Privacy Statement Amazon.co.uk Delivery Information Amazon.co.uk Returns & Exchanges