Practical Unix & Internet Security, 3rd Edition
Binding: Paperback
ASIN: 0596003234
Manufacturer: O’Reilly Media, Inc.
Average Customer Review:
(From 35 total reviews)
List Price: $54.95
Amazon Price: $1.99 (9 new 16 used available)
Availability: Usually ships in 24 hours (Eligible for FREE Super Saver Shipping)
Price is accurate as of the date/time indicated. Prices and product availability are subject to change. Any price displayed on the Amazon web site at the time of purchase will govern the sale of this product.
Editorial Reviews
Amazon.com:
The world’s most business-critical transactions run on Unix machines, which means the machines running those transactions attract evildoers. Furthermore, a lot of those machines have Internet connections, which means it’s always possible that some nefarious remote user will find a way in. The third edition of Practical Unix & Internet Security contains–to an even greater extent than its favorably reputed ancestors–an enormous amount of accumulated wisdom about how to protect Internet-connected Unix machines from intrusion and other forms of attack. This book is fat with practical advice on specific defensive measures (to defeat known attacks) and generally wise policies (to head off as-yet-undiscovered ones).
The authors’ approach to Unix security is holistic and clever; they devote as much space to security philosophy as to advice about closing TCP ports and disabling unnecessary services. They also recognize that lots of Unix machines are development platforms, and make many recommendations to consider as you design software. It’s rare that you read a page in this carefully compiled book that does not impart some obscure nugget of knowledge, or remind you to implement some important policy. Plus, the authors have a style that reminds their readers that computing is supposed to be about intellectual exercise and fun, an attitude that’s absent from too much of the information technology industry lately. Read this book if you use any flavor of Unix in any mission-critical situation. –David Wall
Topics covered: Security risks (and ways to limit them) under Linux, Solaris, Mac OS X, and FreeBSD. Coverage ranges from responsible system administration (including selection of usernames and logins) to intrusion detection, break-in forensics, and log analysis.
Product Description:
When “Practical Unix Security” was first published more than a decade ago, it became an instant classic. Crammed with information about host security, it saved many a Unix system administrator from disaster. The second edition added much-needed Internet security coverage and doubled the size of the original volume. The third edition is a comprehensive update of this very popular book - a companion for the Unix/Linux system administrator who needs to secure his or her organization’s system, networks, and web presence in an increasingly hostile world.
Focusing on the four most popular Unix variants today–Solaris, Mac OS X, Linux, and FreeBSD–this book contains new information on PAM (Pluggable Authentication Modules), LDAP, SMB/Samba, anti-theft technologies, embedded systems, wireless and laptop issues, forensics, intrusion detection, chroot jails, telephone scanners and firewalls, virtual and cryptographic filesystems, WebNFS, kernel security levels, outsourcing, legal issues, new Internet protocols and cryptographic algorithms, and much more.
“Practical Unix & Internet Security” consists of six parts:
Computer security basics: introduction to security problems and solutions, Unix history and lineage, and the importance of security policies as a basic element of system security.
Security building blocks: fundamentals of Unix passwords, users, groups, the Unix filesystem, cryptography, physical security, and personnel security.
Network security: a detailed look at modem and dialup security, TCP/IP, securing individual network services, Sun’s RPC, various host and network authentication systems (e.g., NIS, NIS+, and Kerberos), NFS and other filesystems, and theimportance of secure programming.
Secure operations: keeping up to date in today’s changing security world, backups, defending against attacks, performing integrity management, and auditing.
Handling security incidents: discovering a break-in, dealing with programmed threats and denial of service attacks, and legal aspects of computer security.
Appendixes: a comprehensive security checklist and a detailed bibliography of paper and electronic references for further reading and research.
Packed with 1000 pages of helpful text, scripts, checklists, tips, and warnings, this third edition remains the definitive reference for Unix administrators and anyone who cares about protecting their systems and data from today’s threats.
Customer Reviews
Excellent Guide by Francisco Segura
This book is just what I was looking for. Excellent Security Guide to day to day security issues at my workplace. Information about TPC and UDP ports and their security risks have been very useful.
This book must be part of every UNIX System Security Profesional.
Order a wrong edition by zoomn
I saw that there is a bargain of another paperback edition on the page of 3rd edition, so I didn’t recheck whether it is 3rd edition. So I end up in buying 2 books, 2nd and 3rd editions, because I need the 3rd edition for my class. It would be better to put edition number up in the page, not only paperback or library binding!
A mile wide, several inches deep, great for filling in gaps by Keith Tokash
I hate to repeat the cliche, but if you can only buy one security book this year and you are a *nix geek, this should be it, hands down. As some point out, you can probably find everything in this book online, but then again you can find anything online, so why buy any books at all? I don’t like giving 5 stars; this book left me no choice.
The strength of this book lies in several areas. First, the authors probably have 50+ years experience between them and it shows. You really get the impression that they’ve “been there, done that”. But they don’t try and “wow” you with their intelligence and they aren’t condescending, in fact they write quite clearly.
The “mile wide” crack I made in the title refers to the fact that this book covers everything from physical security and social engineering, to how to setup up integrity checking with tripwire and use PAM. Basically I found this book to be invaluable because while I could breeze through certain sections, there was a ton of material that I needed more knowledge about, but either never got around to it, or didn’t even know I was lacking. An example is NFS. I knew I needed more background about NFS because I work in infosec, but every place I’ve ever worked has banned NFS outright, which makes it a little more difficult to learn…. Another 2 technologies pop into my mind: LDAP and PAM. I knew what they were, but now I know how to set up the basics and can branch out on my own.
In our infosec world it’s simply not possible to know everything. This book gives the reader a solid grounding in a ton of stuff, which enables him to go out and Google around intelligently for more advanced information. In a pinch it can also be used as an anti-theft device since it weighs in at 900+ pages and is quite heavy.
Awesome security book! by Eric Kent
Practical Unix & Internet Security, the 3rd Edition has a ton of new useful information.
If you have but one security reference, this should be it!
Similar Products
Tags: computer security, intro, introduction, network security, simson garfinkel, unix security


Leave a Reply