Third Edition
Senior Acquisitions Editor: Kenyon Brown
Development Editor: Gary Schwartz
Technical Editors: Russ Christy and Brent Hamilton
Senior Production Editor: Christine O'Connor
Copy Editor: Judy Flynn
Editorial Manager: Pete Gaughan
Production Manager: Kathleen Wisor
Executive Editor: Jim Minatel
Book Designers: Judy Fung and Bill Gibson
Proofreader: Nancy Carrasco
Indexer: Johnna VanHoose Dinse
Project Coordinator, Cover: Brent Savage
Cover Designer: Wiley
Cover Image: Getty Images Inc./Jeremy Woodhouse
Copyright © 2019 by John Wiley & Sons, Inc., Indianapolis, Indiana
Published simultaneously in Canada
ISBN: 978-1-119-47764-8
ISBN: 978-1-119-47771-6 (ebk.)
ISBN: 978-1-119-47767-9 (ebk.)
Manufactured in the United States of America
No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning or otherwise, except as permitted under Sections 107 or 108 of the 1976 United States Copyright Act, without either the prior written permission of the Publisher, or authorization through payment of the appropriate per-copy fee to the Copyright Clearance Center, 222 Rosewood Drive, Danvers, MA 01923, (978) 750-8400, fax (978) 646-8600. Requests to the Publisher for permission should be addressed to the Permissions Department, John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ 07030, (201) 748-6011, fax (201) 748-6008, or online at http://www.wiley.com/go/permissions.
Limit of Liability/Disclaimer of Warranty: The publisher and the author make no representations or warranties with respect to the accuracy or completeness of the contents of this work and specifically disclaim all warranties, including without limitation warranties of fitness for a particular purpose. No warranty may be created or extended by sales or promotional materials. The advice and strategies contained herein may not be suitable for every situation. This work is sold with the understanding that the publisher is not engaged in rendering legal, accounting, or other professional services. If professional assistance is required, the services of a competent professional person should be sought. Neither the publisher nor the author shall be liable for damages arising herefrom. The fact that an organization or Web site is referred to in this work as a citation and/or a potential source of further information does not mean that the author or the publisher endorses the information the organization or Web site may provide or recommendations it may make. Further, readers should be aware that Internet Web sites listed in this work may have changed or disappeared between when this work was written and when it is read.
For general information on our other products and services or to obtain technical support, please contact our Customer Care Department within the U.S. at (877) 762-2974, outside the U.S. at (317) 572-3993 or fax (317) 572-4002.
Wiley publishes in a variety of print and electronic formats and by print-on-demand. Some material included with standard print versions of this book may not be included in e-books or in print-on-demand. If this book refers to media such as a CD or DVD that is not included in the version you purchased, you may download this material at http://booksupport.wiley.com. For more information about Wiley products, visit www.wiley.com.
Library of Congress Control Number: 2018967329
TRADEMARKS: Wiley, the Wiley logo, and the Sybex logo are trademarks or registered trademarks of John Wiley & Sons, Inc. and/or its affiliates, in the United States and other countries, and may not be used without written permission. CompTIA and CASP are registered trademarks of CompTIA Properties, LLC. All other trademarks are the property of their respective owners. John Wiley & Sons, Inc. is not associated with any product or vendor mentioned in this book.
To my wife, Maylia:
Thank you for your encouragement, patience, and support.
CC&W, Jeff
Kudos to the Sybex/Wiley team, but particularly Pete Gaughan and Kenyon Brown for granting me the opportunity to bring this edition to the reader. Thank you as well to Gary Schwartz for his early support and patience to the end. Finally, much thanks to Russ Christy and Brent Hamilton for their vigilance as the technical editors.
Jeff Parker resides on the Canadian east coast, but he works for an IT consultancy firm in Virginia where he specializes in IT risk management and compliance. Jeff started in information security while working as a software engineer for HP in Boston, Massachusetts. Jeff then took the role of a global IT risk manager for Deutsche Post to enjoy Prague in the Czech Republic with his family for several years. There he developed and oversaw implementation of a new IT risk management strategy. Today, Jeff most enjoys time with his two children in Nova Scotia.
Jeff maintains several certifications, including CISSP, CompTIA CASP+, CySA+, and ITT+. He also co-authored the book Wireshark for Security Professionals: Using Wireshark and the Metasploit Framework (Wiley, 2017) with Jessey Bullock. Jeff also wrote practice exam books for the CompTIA certifications CySA+ and the A+, out in 2018 and 2019, respectively.
Michael Gregg is the founder and CEO of Superior Solutions, Inc., a security consulting firm based in Houston, Texas. Superior Solutions performs security assessments and penetration testing for Fortune 1000 firms. The company has performed security assessments for private, public, and governmental agencies. Its Houston-based team travels the United States to assess, audit, and provide training services.
Michael is responsible for working with organizations to develop cost-effective and innovative technology solutions to security issues and for evaluating emerging technologies. He has more than 20 years of experience in the IT field and holds two associate's degrees, a bachelor's degree, and a master's degree. In addition to co-writing the first, second, and third editions of Security Administrator Street Smarts, Michael has written or co-written 14 other books, including Build Your Own Security Lab: A Field Guide for Network Testing (Wiley, 2008), Hack the Stack: Using Snort and Ethereal to Master the 8 Layers of an Insecure Network (Syngress, 2007), Certified Ethical Hacker Exam Prep 2 (Pearson, 2006), and Inside Network Security Assessment: Guarding Your IT Infrastructure (Sams Publishing, 2005).
Michael has been featured on Fox News, CBS News, CNN, and other TV outlets as well as in the New York Times and other print publications, and he has testified before US Congress as an industry/cybersecurity expert. Michael has created over a dozen training security classes and training manuals and has created and performed video instruction on many security topics such as cybersecurity, CISSP, CISA, Security+, and others.
When not consulting, teaching, or writing, Michael enjoys 1960s muscle cars and giving back to the community. He is a member of the board of Habitat for Humanity.