
Amazon Prime Free Trial
FREE Delivery is available to Prime members. To join, select "Try Amazon Prime and start saving today with FREE Delivery" below the Add to Cart button and confirm your Prime free trial.
Amazon Prime members enjoy:- Cardmembers earn 5% Back at Amazon.com with a Prime Credit Card.
- Unlimited FREE Prime delivery
- Streaming of thousands of movies and TV shows with limited ads on Prime Video.
- A Kindle book to borrow for free each month - with no due dates
- Listen to over 2 million songs and hundreds of playlists
Important: Your credit card will NOT be charged when you start your free trial or if you cancel during the trial period. If you're happy with Amazon Prime, do nothing. At the end of the free trial, your membership will automatically upgrade to a monthly membership.
Buy new:
-31% $35.73$35.73
Ships from: Amazon.com Sold by: Amazon.com
Save with Used - Acceptable
$21.09$21.09
Ships from: Amazon Sold by: Tome Dealers

Download the free Kindle app and start reading Kindle books instantly on your smartphone, tablet, or computer - no Kindle device required.
Read instantly on your browser with Kindle for Web.
Using your mobile phone camera - scan the code below and download the Kindle app.
Follow the authors
OK
The Shellcoder's Handbook: Discovering and Exploiting Security Holes 2nd Edition
Purchase options and add-ons
- This much-anticipated revision, written by the ultimate group of top security experts in the world, features 40 percent new content on how to find security holes in any operating system or application
- New material addresses the many new exploitation techniques that have been discovered since the first edition, including attacking "unbreakable" software packages such as McAfee's Entercept, Mac OS X, XP, Office 2003, and Vista
- Also features the first-ever published information on exploiting Cisco's IOS, with content that has never before been explored
- The companion Web site features downloadable code files
- ISBN-109780470080238
- ISBN-13978-0470080238
- Edition2nd
- PublisherWiley
- Publication dateAugust 20, 2007
- LanguageEnglish
- Dimensions7.4 x 1.6 x 9.2 inches
- Print length752 pages
Frequently bought together

Frequently purchased items with fast delivery
Editorial Reviews
From the Inside Flap
In the technological arena, three years is a lifetime. Since the first edition of this book was published in 2004, built-in security measures on compilers and operating systems have become commonplace, but are still far from perfect. Arbitrary-code execution vulnerabilities still allow attackers to run code of their choice on your system—with disastrous results.
In a nutshell, this book is about code and data and what happens when the two become confused. You'll work with the basic building blocks of security bugs—assembler, source code, the stack, the heap, and so on. You'll experiment, explore, and understand the systems you're running—and how to better protect them.
- Become familiar with security holes in Windows, Linux, Solaris, Mac OS X, and Cisco's IOS
Learn how to write customized tools to protect your systems, not just how to use ready-made ones
Use a working exploit to verify your assessment when auditing a network
Use proof-of-concept exploits to rate the significance of bugs in software you're developing
Assess the quality of purchased security products by performing penetration tests based on the information in this book
Understand how bugs are found and how exploits work at the lowest level
From the Back Cover
In the technological arena, three years is a lifetime. Since the first edition of this book was published in 2004, built-in security measures on compilers and operating systems have become commonplace, but are still far from perfect. Arbitrary-code execution vulnerabilities still allow attackers to run code of their choice on your system―with disastrous results.
In a nutshell, this book is about code and data and what happens when the two become confused. You'll work with the basic building blocks of security bugs―assembler, source code, the stack, the heap, and so on. You'll experiment, explore, and understand the systems you're running―and how to better protect them.
- Become familiar with security holes in Windows, Linux, Solaris, Mac OS X, and Cisco's IOS
Learn how to write customized tools to protect your systems, not just how to use ready-made ones
Use a working exploit to verify your assessment when auditing a network
Use proof-of-concept exploits to rate the significance of bugs in software you're developing
Assess the quality of purchased security products by performing penetration tests based on the information in this book
Understand how bugs are found and how exploits work at the lowest level
About the Author
John Heasman is the Director of Research at NGSSoftware. He is a prolific security researcher and has published many security advisories in enterprise level software. He has a particular interest in rootkits and has authored papers on malware persistence via device firmware and the BIOS. He is also a co-author of The Database Hacker’s Handbook: Defending Database Servers (Wiley 2005).
Felix “FX” Linder leads SABRE Labs GmbH, a Berlin-based professional consulting company specializing in security analysis, system design creation, and verification work. Felix looks back at 18 years of programming and over a decade of computer security consulting for enterprise, carrier, and software vendor clients. This experience allows him to rapidly dive into complex systems and evaluate them from a security and robustness point of view, even in atypical scenarios and on arcane platforms. In his spare time, FX works with his friends from the Phenoelit hacking group on different topics, which have included Cisco IOS, SAP, HP printers, and RIM BlackBerry in the past.
Gerardo Richarte has been doing reverse engineering and exploit development for more than 15 years non-stop. In the past 10 years he helped build the technical arm of Core Security Technologies, where he works today. His current duties include developing exploits for Core IMPACT, researching new exploitation techniques and other low-level subjects, helping other exploit writers when things get hairy, and teaching internal and external classes on assembly and exploit writing. As result of his research and as a humble thank you to the community, he has published some technical papers and open source projects, presented in a few conferences, and released part of his training material. He really enjoys solving tough problems and reverse engineering any piece of code that falls in his reach just for the fun of doing it.
Product details
- ASIN : 047008023X
- Publisher : Wiley; 2nd edition (August 20, 2007)
- Language : English
- Paperback : 752 pages
- ISBN-10 : 9780470080238
- ISBN-13 : 978-0470080238
- Item Weight : 2.31 pounds
- Dimensions : 7.4 x 1.6 x 9.2 inches
- Best Sellers Rank: #102,296 in Books (See Top 100 in Books)
- #3 in Software Programming Compilers
- #171 in Computer Security & Encryption (Books)
- #184 in Networking & Cloud Computing
- Customer Reviews:
About the authors
Discover more of the author’s books, see similar authors, read book recommendations and more.
Discover more of the author’s books, see similar authors, read book recommendations and more.
Customer reviews
Customer Reviews, including Product Star Ratings help customers to learn more about the product and decide whether it is the right product for them.
To calculate the overall star rating and percentage breakdown by star, we don’t use a simple average. Instead, our system considers things like how recent a review is and if the reviewer bought the item on Amazon. It also analyzed reviews to verify trustworthiness.
Learn more how customers reviews work on AmazonCustomers say
Customers find the book informative and in-depth, particularly suitable for intermediate shell coders looking to expand their knowledge. They appreciate its coverage of buffer overflows and heap overflows, and one customer notes its focus on real-world exploits.
AI-generated from the text of customer reviews
Select to learn more
Customers find the book informative and in-depth, particularly suitable for beginners learning about shell coding and intermediate shell coders looking to expand their knowledge.
"...This book being reviewed. This book is much more in depth and focuses on real-world exploits...." Read more
"...You're not going to get fluff, opinion, editorials, introductions or appendixes for review, NOTHING...." Read more
"...It encourages writing your own tools rather than relying on 3rd party tools...." Read more
"...favorite social media influencer, this book is for intelligent coders and security experts. It is dated, but the concepts are still in use today...." Read more
Customers appreciate the book's coverage of buffer overflows and heap overflows.
"...It focuses on exploiting and mentions buffer overflows as well as heap overflows and goes into detail about stack protection and evading stack..." Read more
"...exploits work and various types of exploit like stack overflow, heap overflow, format string vulnerability...." Read more
"...like Return Oriented Programming, Fuzzing, ASLR/DEP handling, heap overflows and how to go about doing vulnerability analysis from scratch." Read more
Customers appreciate the book's focus on real-world exploits and how they work.
"...It focuses on exploiting and mentions buffer overflows as well as heap overflows and goes into detail about stack protection and evading stack..." Read more
"...This book is much more in depth and focuses on real-world exploits. These exploits actually work and are practical in more modern systems...." Read more
"The book is really one of the classics and explains how exploits work and various types of exploit like stack overflow, heap overflow, format string..." Read more
Top reviews from the United States
There was a problem filtering reviews. Please reload the page.
- Reviewed in the United States on October 8, 2015The book is a difficult topic and takes close to eternity to read it all the way through its many pages with perfect comprehension, but that's not because it's poorly written. The book is expertly written but covers some very advanced concepts and has a lot of hex bytes, code, and memory addresses. Understanding of C/C++ coding and assembly and ideally one or more interpreted languages will help you understand it. Otherwise, you'll probably end up learning some coding as a side effect of reading this book (which hopefully isn't a terrible thing). It focuses on exploiting and mentions buffer overflows as well as heap overflows and goes into detail about stack protection and evading stack protection. As someone who almost always prefers free text books, this is one of few paid text books I say is worth twice what I paid for it if not more. A word of caution: this is not a beginner book and you may need to research certain concept independently. By the end of this book you will be thinking like a pro.
- Reviewed in the United States on May 7, 2016Make no mistake: this book is pretty hard core and, IMHO, not for the beginner.
In short I recommend people interested in learning about malware in depth use the following materials:
1."Smashing The Stack For Fun And Profit" by Aleph One (aka Elias Levy).
This is a masterpiece of some basic vulnerabilities and their exploitation. A good intro to the topic and many folks may wish to stop here.
2. "Hacking: The Art of Exploitation", 2nd Ed by Jon Erickson
This moves into some excellent examples that apply the techniques of exploitation. A good way to get some "hands on" experience and put into practice the core ideas of exploitation. Just don't expect this to be geared toward modern exploits and real-world applications in 2016.
3. "The Shellcoder's Handbook: Discovering and Exploiting Security Holes" 2nd Ed. This book being reviewed.
This book is much more in depth and focuses on real-world exploits. These exploits actually work and are practical in more modern systems. If your goal is to move beyond concepts and simple examples to practical techniques that are useful, this is the book you'll need.
I hope this helps.
.
- Reviewed in the United States on February 27, 2017This book is no joke. The introduction underplays the prerequisites. SIMPLE PROGRAMMING/ IT CONCEPTS IS NOT ENOUGH!!! You shouldn't buy this book unless you have a background in CS and some practice with the concepts - data structures and algorithms, computer organization/architecture, x86, C language/pointer arithmetic, Compilers/converting C code to assembly.
IF YOU DON'T KNOW COMPUTER SCIENCE TURN BACK NOW
This book is a nonstop stream of information relating all of those concepts. And certainly the best one I've ever read.
You're not going to get fluff, opinion, editorials, introductions or appendixes for review, NOTHING. Many of the other books in this category, such as "Hacking: The Art of Exploitation" have a lot of reviews clearly by people with no a background in Computer Science claiming those books are too technical. Those books are IT and networking books that have a -- nothing compared to this. The meat of what is in "Hacking: The Art of Exploitation" is covered in the first 5 chapters in this book.
- Reviewed in the United States on August 28, 2014I recommend this book for everyone looking to begin their journey into advanced penetration testing via writing their own exploits. It is a little dated, though still provides a solid foundation. This is a classic in its own time and a must-read for every info sec professional, or those simply curious about getting into the field. It encourages writing your own tools rather than relying on 3rd party tools. Nothing wrong with the latter, though it is good to know how to code your own exploits. This is a great first step to becoming a Metasploit contributor or creating your own collection of 0days.
- Reviewed in the United States on February 12, 2022Know C, ASM, and x86 architecture before you even open this book or you're not going to understand it. Your favorite blog writer isn't going to understand it, nor is your favorite social media influencer, this book is for intelligent coders and security experts. It is dated, but the concepts are still in use today. Do not be misled by the size, it is packed with verbose code examples and explanations you get you up to speed on shellcode.
- Reviewed in the United States on March 7, 2016This book is really cool. I am interesting in learning more about how to compromise a computer program so I can improve my programming. This book takes a really deep dive into programming and breaking programs. That being said I would suggest you have a fairly decently knowledge of Assembly language. This book uses linux programs to write and dissaemble the various programs. It is important to take your time and work through each exercise and example. There is a world of knowledge for any programmer looking to understand how people man abuse or break your programs and exploit them for self gain.
Personal Note: This book will show you how to hack a computer system. I ask that you use this knowledge to help people and to make the world a bit safer than to abuse it for self gain.
- Reviewed in the United States on October 11, 2011This book serves as a good introduction to shell coding. The first 6 chapters on linux are reasonably complete; if you read the material and take the time to learn the concepts you will be happy with your progress. However, as the book dives into other operating systems I feel that some of this completeness and solidarity are vanishing. As I get deeper and deeper into the text, there are more and more words and concepts which are prerequisite yet the authors never explained. It feels like they were very comprehensive and diligent in the first chapters, but got lazy and impatient as it progressed.
- Reviewed in the United States on February 7, 2022High-Level Book. you must know C language. And a basic grasp of gdb debugger and computer architecture. Does set you up with 130pages of trying to catch u up on those topics. However.. if you can master this book and it’s concepts… you’ll be on your way to a computer God.
Top reviews from other countries
- Cliente AmazonReviewed in Spain on July 5, 2017
5.0 out of 5 stars Awesome book
How other people say here, this book is not for beginners, from the begining it teach very advanced concepts about exploitation and how a computer work.
How explains the writer at the begining, this book its for the people who understants hacking like a way of life, learn and enjoy, not of only earn money ;)
-
Adrian González PardoReviewed in Mexico on December 4, 2019
3.0 out of 5 stars Siendo un regalo que dare
El libro se ve muy interesante y fue una buena elección para dar como regalo, el unico problema es que llego maltratado de una de las portadas por ello doy una calificación baja, de eso en fuera se ve muy interesante y con buen contenido..
- francois veilleuxReviewed in Canada on February 28, 2017
5.0 out of 5 stars Five Stars
excellent
-
GiorgioReviewed in Italy on July 5, 2019
5.0 out of 5 stars Ottimo libro!
Ottima libro per cementarsi nelle tecniche di baking binario. Il libro è completo ed esaustivo, ricco di esempi e spiegazioni.
- GylesReviewed in the United Kingdom on December 4, 2023
5.0 out of 5 stars Classic must read
This book sells itself frankly. If you work in offensive security and want to up your game in writing your own exploits this book covers the needed fundamentals. Is it a little dated? Sure. But the basics that you need are there.