Rootkits : subverting the Windows kernel /

"It's imperative that everybody working in the field of cyber-security read this book to understand the growing threat of rootkits." --Mark Russinovich, editor, Windows IT Pro / Windows & .NET Magazine "This material is not only up-to-date, it defines up-to-date. It is truly...

Full description

Saved in:
Bibliographic Details
Main Author: Hoglund, Greg
Other Authors: Butler, James
Format: Electronic eBook
Language:English
Published: Upper Saddle River, NJ : Addison-Wesley, 2005.
Subjects:
Online Access:CONNECT

MARC

LEADER 00000cam a2200000Ma 4500
001 in00006039551
006 m o d
007 cr |||||||||||
008 050506s2005 nju ob 001 0 eng d
005 20220718132151.7
035 |a 1WRLDSHRocn316334032 
040 |a SIRPL  |b eng  |e pn  |c SIRPL  |d CEF  |d OCLCQ  |d MBB  |d OCLCQ  |d OCLCF  |d OCLCO  |d YSM  |d VLB  |d XFF  |d C6I  |d OCLCQ  |d COO  |d OCLCQ  |d OCLCA  |d RDF  |d UKBTH  |d OCLCO 
019 |a 70701564  |a 74459550  |a 748094477  |a 1113632587 
020 |a 9780321294319  |q (pbk. ;  |q alk. paper) 
020 |a 0321294319  |q (pbk. ;  |q alk. paper) 
020 |z 0321294319  |q (pbk. ;  |q alk. paper) 
024 8 |a 9780321294319 
024 8 |a 0321294319 
035 |a (OCoLC)316334032  |z (OCoLC)70701564  |z (OCoLC)74459550  |z (OCoLC)748094477  |z (OCoLC)1113632587 
050 4 |a QA76.9.A25  |b H637 2005 
082 0 4 |a 005.8  |2 22 
049 |a TXMM 
100 1 |a Hoglund, Greg. 
245 1 0 |a Rootkits :  |b subverting the Windows kernel /  |c Greg Hoglund, James Butler. 
260 |a Upper Saddle River, NJ :  |b Addison-Wesley,  |c 2005. 
300 |a 1 online resource 
336 |a text  |b txt  |2 rdacontent 
337 |a computer  |b c  |2 rdamedia 
338 |a online resource  |b cr  |2 rdacarrier 
347 |a text file 
504 |a Includes bibliographical references and index. 
588 0 |a Print version record. 
505 0 0 |g 1.  |t Leave no trace --  |g 2.  |t Subverting the kernel --  |g 3.  |t hardware connection --  |g 4.  |t age-old art of hooking --  |g 5.  |t Runtime patching --  |g 6.  |t Layered drivers --  |g 7.  |t Direct kernel object manipulation --  |g 8.  |t Hardware manipulation --  |g 9.  |t Covert channels --  |g 10.  |t Rootkit detection. 
520 |a "It's imperative that everybody working in the field of cyber-security read this book to understand the growing threat of rootkits." --Mark Russinovich, editor, Windows IT Pro / Windows & .NET Magazine "This material is not only up-to-date, it defines up-to-date. It is truly cutting-edge. As the only book on the subject, Rootkits will be of interest to any Windows security researcher or security programmer. It's detailed, well researched and the technical information is excellent. The level of technical detail, research, and time invested in developing relevant examples is impressive. In one word: Outstanding." --Tony Bautts, Security Consultant; CEO, Xtivix, Inc. "This book is an essential read for anyone responsible for Windows security. Security professionals, Windows system administrators, and programmers in general will want to understand the techniques used by rootkit authors. At a time when many IT and security professionals are still worrying about the latest e-mail virus or how to get all of this month's security patches installed, Mr. Hoglund and Mr. Butler open your eyes to some of the most stealthy and significant threats to the Windows operating system. Only by understanding these offensive techniques can you properly defend the networks and systems for which you are responsible." --Jennifer Kolde, Security Consultant, Author, and Instructor "What's worse than being owned? Not knowing it. Find out what it means to be owned by reading Hoglund and Butler's first-of-a-kind book on rootkits. At the apex the malicious hacker toolset--which includes decompilers, disassemblers, fault-injection engines, kernel debuggers, payload collections, coverage tools, and flow analysis tools--is the rootkit. Beginning where Exploiting Software left off, this book shows how attackers hide in plain sight. "Rootkits are extremely powerful and are the next wave of attack technology. Like other types of malicious code, rootkits thrive on stealthiness. They hide away from standard system observers, employing hooks, trampolines, and patches to get their work done. Sophisticated rootkits run in such a way that other programs that usually monitor machine behavior can't easily detect them. A rootkit thus provides insider access only to people who know that it is running and available to accept commands. Kernel rootkits can hide files and running processes to provide a backdoor into the target machine. "Understanding the ultimate attacker's tool provides ... 
542 |f Copyright © 2006 Pearson Education, Inc.  |g 2006 
590 |a O'Reilly Online Learning Platform: Academic Edition (SAML SSO Access) 
630 0 0 |a Microsoft Windows (Computer file) 
630 0 7 |a Microsoft Windows (Computer file)  |2 fast  |0 (OCoLC)fst01367862 
650 0 |a Computer security. 
650 0 |a Computers  |x Access control. 
700 1 |a Butler, James. 
730 0 |a WORLDSHARE SUB RECORDS 
776 0 8 |i Print version:  |a Hoglund, Greg.  |t Rootkits.  |d Upper Saddle River, NJ : Addison-Wesley, 2005  |w (DLC) 2005013061 
856 4 0 |u https://go.oreilly.com/middle-tennessee-state-university/library/view/-/0321294319/?ar  |z CONNECT  |3 O'Reilly  |t 0 
949 |a ho0 
994 |a 92  |b TXM 
998 |a wi  |d z 
999 f f |s 7bd04566-f87a-447b-aa31-e8634f3f89e6  |i b74152cf-0576-4e5a-9cd6-747cecea2389  |t 0 
952 f f |a Middle Tennessee State University  |b Main  |c James E. Walker Library  |d Electronic Resources  |t 0  |e QA76.9.A25 H637 2005  |h Library of Congress classification 
856 4 0 |3 O'Reilly  |t 0  |u https://go.oreilly.com/middle-tennessee-state-university/library/view/-/0321294319/?ar  |z CONNECT