Related tags: Tools [+], Fuzzing [+], Toolkit [+], Testers [+], Pro [+], Penetration [+], Mail [+], Building [+], with, to, Using, The, SarbanesOxley, Locks, Is, IT, How, Future, Compliance
A "fuzzer" is a program that attempts to discover security vulnerabilities by sending random data to an application. If that application crashes, then it has deffects to correct. Security professionals and web developers can use fuzzing for software testing–checking their own programs for problems–before hackers do it!
Open Source Fuzzing Tools is the first book to market that covers the subject of black box testing using fuzzing techniques. Fuzzing has been around fow a while, but is making a transition from hacker home-grown tool to commercial-grade quality assurance product. Using fuzzing, developers can find and eliminate buffer overflows and other software vulnerabilities during the development process and before release.
* Fuzzing is a fast-growing field with increasing commercial interest (7 vendors unveiled fuzzing products last year).
* Vendors today are looking for solutions to the ever increasing threat of vulnerabilities. Fuzzing looks for these vulnerabilities automatically, before they are known, and eliminates them before release.
* Software developers face an incresing demand to produce secure applications—and they are looking for any information to help them do that.

Penetration testing a network requires a delicate balance of art and science. A penetration tester must be creative enough to think outside of the box to determine the best attack vector into his own network, and also be expert in using the literally hundreds of tools required to execute the plan. This second volume adds over 300 new pen testing applications to the pen tester's toolkit. It includes the latest information on Snort, Nessus, Wireshark, Metasploit, Kismet and all of the other major Open Source platforms. It also includes "BackTrack2" on CD, a set of pen testing tools that complements those found on the "Auditor" CD that comes with Volume 1.
The authors of the book are expert penetration testers who have developed many of the leading pen testing tools such as the Metasploit framework. The authors allow the reader inside their heads to unravel the mysteries of things like cross scripting attacks, fuzzing tools, Google hacks, and more.
Covers Metasploit Release 3
Includes BackTrack2 Toolkit
Implements the Snort 2.6, Wireshark, and Nessus
Publisher: Syngress