The Mac Hacker'S Handbook 9780470395363 在线 lit 下载 kindle 免费 pdf docx 电子版 txt

The Mac Hacker'S Handbook 9780470395363电子书籍推荐下载地址
- 文件名
- [epub 电子书下载] The Mac Hacker'S Handbook 9780470395363
- [azw3 电子书下载] The Mac Hacker'S Handbook 9780470395363
- [pdf 电子书下载] The Mac Hacker'S Handbook 9780470395363
- [txt 电子书下载] The Mac Hacker'S Handbook 9780470395363
- [mobi 电子书下载] The Mac Hacker'S Handbook 9780470395363
- [word 电子书下载] The Mac Hacker'S Handbook 9780470395363
- [kindle 电子书下载] The Mac Hacker'S Handbook 9780470395363
内容简介:
As more and more vulnerabilities are found in the Mac OS X
(Leopard) operating system, security researchers are realizing the
importance of developing proof-of-concept exploits for those
vulnerabilities. This unique tome is the first book to uncover the
flaws in the Mac OS X operating system—and how to deal with them.
Written by two white hat hackers, this book is aimed at making
vital information known so that you can find ways to secure your
Mac OS X systems, and examines the sorts of attacks that are
prevented by Leopard’s security defenses, what attacks aren’t, and
how to best handle those weaknesses.
书籍目录:
Foreword.
Introduction.
Part I Mac OS X Basics.
Chapter 1 Mac OS X Architecture.
Basics.
XNU.
Mach.
BSD.
I/O Kit.
Darwin and Friends.
Tools of the Trade.
Ktrace/DTrace.
Objective-C.
Universal Binaries and the Mach-O File Format.
Universal Binaries.
Mach-O File Format.
Example.
Bundles.
launchd.
Leopard Security.
Library Randomization.
Executable Heap.
Stack Protection (propolice).
Firewall.
Sandboxing (Seatbelt).
References.
Chapter 2 Mac OS X Parlance.
Bonjour!.
Get an IP Address.
Set Up Name Translation.
Service Discovery.
Bonjour.
mDNSResponder.
Source Code.
QuickTime.
.mov.
RTSP.
Conclusion.
References.
Chapter 3 Attack Surface.
Searching the Server Side.
Nonstandard Listening Processes.
Cutting into the Client Side.
Safari.
All of Safari’s Children.
Safe File Types.
Having Your Cake.
Conclusion .
References.
Part II Discovering Vulnerabilities.
Chapter 4 Tracing and Debugging.
Pathetic ptrace.
Good Ol’ GDB.
DTrace.
D Programming Language.
Describing Probes.
Example: Using Dtrace.
Example: Using ltrace.
Example: Instruction Tracer/Code-Coverage Monitor.
Example: Memory Tracer.
PyDbg.
PyDbg Basics.
Memory Searching.
In-Memory Fuzzing.
Binary Code Coverage with Pai Mei.
iTunes Hates You.
Conclusion.
References.
Chapter 5 Finding Bugs.
Bug-Hunting Strategies.
Old-School Source-Code Analysis.
Getting to the Source.
Code Coverage.
CanSecWest 2008 Bug.
vi + Changelog = Leopard 0-day.
Apple’s Prerelease-Vulnerability Collection.
Fuzz Fun.
Network Fuzzing.
File Fuzzing.
Conclusion.
References.
Chapter 6 Reverse Engineering.
Disassembly Oddities.
EIP-Relative Data Addressing.
Messed-Up Jump Tables.
Identifying Missed Functions.
Reversing Obj-C.
Cleaning Up Obj-C.
Shedding Light on objc_msgSend Calls.
Case Study.
Patching Binaries.
Conclusion.
References.
Part III Exploitation.
Chapter 7 Exploiting Stack Overflows.
Stack Basics.
Stack Usage on PowerPC.
Stack Usage on x86.
Smashing the Stack on PowerPC.
Smashing the Stack on x86.
Exploiting the x86 Nonexecutable Stack.
Return into system().
Executing the Payload from the Heap.
Finding Useful Instruction Sequences.
PowerPC.
x86.
Conclusion.
References.
Chapter 8 Exploiting Heap Overflows.
The Heap.
The Scalable Zone Allocator.
Regions.
Freeing and Allocating Memory.
Overwriting Heap Metadata.
Arbitrary 4-Byte Overwrite.
Large Arbitrary Memory Overwrite.
Obtaining Code Execution.
Taming the Heap with Feng Shui.
Fill ’Er Up.
Feng Shui.
WebKit’s JavaScript.
Case Study.
Feng Shui Example.
Heap Spray.
References.
Chapter 9 Exploit Payloads.
Mac OS X Exploit Payload Development.
Restoring Privileges.
Forking a New Process.
Executing a Shell.
Encoders and Decoders.
Staged Payload Execution.
Payload Components.
PowerPC Exploit Payload.
execve_binsh.
system.
decode_longxor.
tcp_listen 231.
tcp_connect.
tcp_find.
dup2_std_fds.
vfork.
Testing Simple Components.
Putting Together Simple Payloads.
Intel x86 Exploit Payloads.
remote_execution_loop.
inject_bundle.
Testing Complex Components.
Conclusion.
References.
Chapter 10 Real-World Exploits.
QuickTime RTSP Content-Type Header Overflow.
Triggering the Vulnerability.
Exploitation on PowerPC.
Exploitation on x86.
mDNSResponder UPnP Location Header Overflow.
Triggering the Vulnerability.
Exploiting the Vulnerability.
Exploiting on PowerPC.
QuickTime QTJava toQTPointer() Memory Access.
Exploiting toQTPointer().
Obtaining Code Execution.
Conclusion.
References.
Part IV Post-Exploitation.
Chapter 11 Injecting, Hooking, and Swizzling.
Introduction to Mach.
Mach Abstractions.
Mach Security Model Mach Exceptions.
Mach Injection.
Remote Threads.
Remote Process Memory.
Loading a Dynamic Library or Bundle.
Inject-Bundle Usage.
Example: iSight Photo Capture.
Function Hooking.
Example: SSLSpy.
Objective-C Method Swizzling.
Example: iChat Spy.
Conclusion.
References.
Chapter 12 Rootkits.
Kernel Extensions.
Hello Kernel.
System Calls.
Hiding Files.
Hiding the Rootkit.
Maintaining Access across Reboots.
Controlling the Rootkit.
Creating the RPC Server.
Injecting Kernel RPC Servers.
Calling the Kernel RPC Server.
Remote Access.
Hardware-Virtualization Rootkits.
Hyperjacking.
Rootkit Hypervisor.
Conclusion.
References.
Index.
作者介绍:
CharlIe Millerwon the second CanSecWest Pwn2Own contest in
2008 and was named one of the Top 10 Computer Hackers of 2008 by
Popular Mechanics.
Dino Dai Zovi won the first CanSecWest Pwn2Own contest in 2007
and was named one of the 15 Most Influential People in Security by
eWEEK.
出版社信息:
暂无出版社相关信息,正在全力查找中!
书籍摘录:
暂无相关书籍摘录,正在全力查找中!
在线阅读/听书/购买/PDF下载地址:
原文赏析:
暂无原文赏析,正在全力查找中!
其它内容:
书籍介绍
As more and more vulnerabilities are found in the Mac OS X (Leopard) operating system, security researchers are realizing the importance of developing proof-of-concept exploits for those vulnerabilities. This unique tome is the first book to uncover the flaws in the Mac OS X operating system—and how to deal with them. Written by two white hat hackers, this book is aimed at making vital information known so that you can find ways to secure your Mac OS X systems, and examines the sorts of attacks that are prevented by Leopard’s security defenses, what attacks aren’t, and how to best handle those weaknesses.
精彩短评:
深度书评:
网站评分
-
书籍多样性:5分
-
书籍信息完全性:3分
-
网站更新速度:7分
-
使用便利性:9分
-
书籍清晰度:5分
-
书籍格式兼容性:7分
-
是否包含广告:6分
-
加载速度:3分
-
安全性:7分
-
稳定性:8分
-
搜索功能:4分
-
下载便捷性:5分
下载点评
- 差评少(490+)
- 体验还行(188+)
- 收费(497+)
- 内涵好书(392+)
- 情节曲折(632+)
- 无广告(163+)
- 快捷(614+)
- 还行吧(223+)
- 体验差(261+)
- 书籍多(566+)
- 无水印(162+)
下载评价
-
网友 石***烟:
( 2025-02-23 20:01:16 )
还可以吧,毕竟也是要成本的,付费应该的,更何况下载速度还挺快的
-
网友 屠***好:
( 2025-03-01 12:03:34 )
还行吧。
-
网友 融***华:
( 2025-03-13 04:02:45 )
下载速度还可以
-
网友 康***溪:
( 2025-02-24 01:55:41 )
强烈推荐!!!
-
网友 瞿***香:
( 2025-02-27 19:18:34 )
非常好就是加载有点儿慢。
-
网友 居***南:
( 2025-03-13 16:46:13 )
请问,能在线转换格式吗?
-
网友 辛***玮:
( 2025-03-07 04:26:48 )
页面不错 整体风格喜欢
-
网友 蓬***之:
( 2025-03-16 01:40:53 )
好棒good
-
网友 晏***媛:
( 2025-03-22 03:35:27 )
够人性化!
-
网友 濮***彤:
( 2025-02-24 11:29:19 )
好棒啊!图书很全
-
网友 孙***美:
( 2025-03-20 23:37:22 )
加油!支持一下!不错,好用。大家可以去试一下哦
-
网友 詹***萍:
( 2025-02-28 19:39:45 )
好评的,这是自己一直选择的下载书的网站
-
网友 曹***雯:
( 2025-03-08 08:34:06 )
为什么许多书都找不到?
-
网友 菱***兰:
( 2025-02-24 03:01:55 )
特好。有好多书
-
网友 后***之:
( 2025-03-10 14:45:02 )
强烈推荐!无论下载速度还是书籍内容都没话说 真的很良心!
喜欢"The Mac Hacker'S Handbook 9780470395363"的人也看了
-
高校舞蹈教育教学新模式研究 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
-
9787567208391 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
-
9787530469859 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
-
草样青春 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
-
全国美术考级指定专用教材素描考级13级 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
-
妇科内分泌疾病治疗学 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
-
2019全国一级建造师执业资格考试必刷题+历年真题+押题试卷 建设工程经济 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
-
Pro/DETAIL Wildfire3.0工程图设计 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
-
海外直订Never Rush Always Brush: Motivating Your Child to Brush Their Teeth 永远不要急着刷牙:激励孩子刷牙 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
-
心理学导论 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 如何运用Maslow理论使你的企业达到颠峰Peak : How Great Companies Get Their Mojo from Maslow 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 生命与进化 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 畅游加勒比海 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 国际航运职业英语(深圳职业技术学院“十四五”规划教材) 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 中公四川公务员省考2023年行测教材四川省公务员考试用书2022公考行政职业能力测验教材选调生乡镇公务员教材招警法院检察院 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 现代色谱分析 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- CCNA/CCNP模拟试题及详解 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 程序员下午考试指南 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 化工产品手册(第六版).溶剂 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 备考2019 注册消防工程师资格考试辅导用书:消防安全技术实务考点精编 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 意大利语+英语/乐游全球 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 巴巴爸爸建新家 巴巴爸爸经典系列 【正版】 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 家有房产(大字版) 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 本搞定上海特训 英语牛津版五年级第学期/5年级上 沪教版 上海小学教材同步配套课后练习 含参考答案【聚英汇图书】 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 【中商原版】新井洋行360度环绕阅读互动游戏绘本:火车 新井洋行360度環繞閱讀互動遊戲繪本:火車 原版图书 活动与玩具书 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 9787308124218 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 创新一点通星级教案与作业新设计 六年级数学 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 三国演义 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 正版现货 公路工程基本建设项目设计文件编制办法 交公路发(2007)358号中交公路勘察设计研究院 人民交通出版社 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
- 千集大型神话系列动画片《东方神娃2》7 在线 lit 下载 kindle 免费 pdf docx 电子版 txt
书籍真实打分
故事情节:8分
人物塑造:7分
主题深度:9分
文字风格:8分
语言运用:4分
文笔流畅:3分
思想传递:6分
知识深度:4分
知识广度:7分
实用性:8分
章节划分:8分
结构布局:3分
新颖与独特:7分
情感共鸣:8分
引人入胜:6分
现实相关:7分
沉浸感:9分
事实准确性:6分
文化贡献:7分