The world's most business-critical transactions run on Unix machines, which means the machines running those transactions attract evildoers. Furthermore, a lot of those machines have Internet connections, which means it's always possible that some nefarious remote user will find a way in. The third edition of Practical Unix & Internet Security contains--to an even greater extent than its favorably reputed ancestors--an enormous amount of accumulated wisdom about how to protect Internet-connected Unix machines from intrusion and other forms of attack. This book is fat with practical advice on specific defensive measures (to defeat known attacks) and generally wise policies (to head off as-yet-undiscovered ones).

The authors' approach to Unix security is holistic and clever; they devote as much space to security philosophy as to advice about closing TCP ports and disabling unnecessary services. They also recognize that lots of Unix machines are development platforms, and make many recommendations to consider as you design software. It's rare that you read a page in this carefully compiled book that does not impart some obscure nugget of knowledge, or remind you to implement some important policy. Plus, the authors have a style that reminds their readers that computing is supposed to be about intellectual exercise and fun, an attitude that's absent from too much of the information technology industry lately. Read this book if you use any flavor of Unix in any mission-critical situation. --David Wall

Share
Related Documents
  1. [Free] skipfish : web application security reconnaissance tool. (1825)
  2. [PodCast] Security Testing (104M) (762)
  3. [Free] SiteDigger : vulnerabilities, errors, configuration issues, proprietary information, and interesting security testing tool (4284)
  4. [Free] Watcher : testing tool and passive vulnerability scanner (1710)
  5. [Ebook] Internet Security: A Jumpstart for Systems Administrators and IT Managers (2921)
  6. [Ebook] Exploiting Software How to Break Code (2692)
  7. Security Focus : Newsletter Archive (1342)
  8. [Webinar] Are You Ready for DO-178C and Emerging Security-Critical Standards? (1008)
  9. What is a Security stress testing? (1213)
  10. [Video] seNetsparker - A free web app security testing tool (682)
  11. Building web application security into your development process (1373)
  12. [Ebook] Practical Applications for Security Testing (4141)
  13. Creating a Web security testing policy (1639)
  14. Security Testing for Web Application (1841)
  15. Web Security Testing Blog (985)
  16. Security Strategies Alert (765)
  17. [Paid] Web Site Security Audit - WSSA : Website and Web Server Security Auditing (1423)
  18. Secure Software Advisory for security testing (831)
  19. [Ebook] Security Engineering: A Guide to Building Dependable Distributed Systems (4541)
  20. Software Security Assurance (1734)