· 3 min read

Top 100 Hacking Books

A hundred books on offensive security, reverse engineering, network defence and forensics — assembled in 2018 from the titles that came up most often when practitioners were asked what they actually learned from.

This is a reading list, nothing more. There are no downloads here. Every one of these is in print or sold as an ebook by its publisher, and that is where they should come from — the people who wrote them are largely the same community the list is aimed at. The earlier version of this page linked to scanned copies on third-party hosts; those links are gone and will not be coming back.

Titles are listed as originally recorded, so a few are now several editions out of date. Check for a current edition before buying — in this field a 2016 book on tooling ages faster than one on fundamentals. For what I am reading now, see the library.

1. Advanced Penetration Testing Hacking 2017

2. CEH v9 Certified Ethical Hacker Version 9

3. Begin Ethical Hacking with Python

4. Certified Ethical Hacker 2016

5. Essential Skills for Hackers

6. Hacking 2016

7. Hacking the Hacker 2017

8. The Art of Invisibility 2017

9. Penetration Testing Basics

10. Penetration Testing Essentials 2017

11. Security

12. Hackers Beware

13. Network Performance and Security

14. Advanced_Persistent_Threat_Hacking

15. Modern Web Penetration Testing 2016

16. From Hacking to Report Writing

17. Python Web Penetration Testing Cookbook

18. CompTIA Cybersecurit 2017

18.IT final

19. Wireshark for Security Professionals 2016

20. Cyber-Physical Attack Recover

21. Honeypots and Routers_ Collecting Internet Attacks

22. Practical Information Security Management 2016

23. Phishing Dark Waters

24. Network Attacks and Exploitation

25. A Hacker

26. Hacker School

27. Automated Credit Card Fraud

28. A Beginners Guide To Hacking Computer Systems

29. 501 Website Hacking Secrets

30. Cracking Passwords Guide

31. Eldad Eilam – Reversing: Secrets of Reverse Engineering – Wiley 2005

32. Metasploit Toolkit – Presentation

33. Metasploit Toolkit – Syngress

34. Oracle Rootkits 2.0

35. Pest Control – Taming the RATS

36. Practical Malware Analysis

37. Return Oriented Programming

38. Web App Hacking (Hackers Handbook)

39. The Basics of Web Hacking – Tools and Techniques to Attack the Web(2013)

40. Syngress – Sockets, Shellcode, Porting & Coding – Reverse Engineering Exploits And Tool Coding For Security Professionals

41. Stack Smashing

42. SQL Injection Attacks and Defense

43. Reverse Engineering for Beginners

44. Black Book of Viruses and Hacking

45. Bluepilling the Xen Hypervisor

46. Computer Viruses, Hacking and Malware attacks for Dummies

47. Cracking Passwords Guide

48. Hackers_Secrets

49. Buffer Overflow Attacks

50. Exploiting Software – How To Break Code

51. Grumpy Old Fart’s Big Book of Hacking

53. Comptia Security+

54. Hack Attacks Revealed

55. Hacking Exposed (Laxxuss)

56. Hacking For Dummies (2004) Wiley

57. Hacking For Dummies – Access To Other Peoples Systems Made Simple

58. Hacking Into Computer Systems – A Beginners Guide

59. How To Hack Windows Xp Admin Passwords

60. Bluetooth Hacking

61. ETH – Attacks on P2P Networks (Freenet) (2005)

62. Francisco Amato – evilgrade – ENG

63. Fun With EtterCap Filters

64. Man_In_The_Middle

65. arp MITM

66. ethereal-tcpdump

67. KALI-LINUX-COMMANDS

68. DEFCON-24-Anto-Joseph-Fuzzing-Android-Devices

69. DEFCON-24-Bigezy-Saci-Pinworm-MITM-for-Metadata

70. DEFCON-24-Brad-Dixon-Pin2Pwn-How-to-Root-An-Embedded-Linux-Box-With-A-Sewing-Needle

71. DEFCON-24-Brad-Woodberg-Malware-Command-And-Control-Channels-A-Journey-Into-Darkness

72. DEFCON-24-Bryant-Zadegan-Ryan-Lester-Abusing-Bleeding-Edge-Web-Standards-For-Appsec-Glory

73. DEFCON-24-Chapman-Stone-Toxic-Proxies-Bypassing-HTTPS-and-VPNs

74. DEFCON-24-Demay-Auditing-6LoWPAN-Networks-Using-Standard-Penetration-Testing-Tools-WP

75. DEFCON-24-Demay-Auditing-6LoWPAN-Networks-Using-Standard-Penetration-Testing-Tools

76. DEFCON-24-Fitzpatrick-and-Grand-101-Ways-To-Brick-Your-Hardware

77. DEFCON-24-Seymour-Tully-Weaponizing-Data-Science-For-Social-Engineering

78. DEFCON-24-Thomas-Wilhelm-Hacking-Network-Protocols-Using-Kali

79. DEFCON-24-Thomas-Wilhelm-Intrusion-Prevention-System-Evasion-Techniques

80. DEFCON-24-Ulf-Frisk-Direct-Memory-Attack-the-Kernel

81. EN-Hacking Web Applications Using Cookie Poisoning

82. EN – NoSQL, No injection – Ron, Shulman-Peleg, Bronshtein

83. Ethical Hacking and Penetration Testing Guide – Baloch, Rafay

84. Faille-CSRF

85. Metasploit, Penetration Testers Guide

86. Next Generation Web Attacks – HTML 5, DOM(L3) and XHR(L2)

87. Ninja Hacking

88. OWASP_Stammtisch_Frankfurt_WAF_Profiling_and_Evasion

89. Pentesting With Burp Suite

90. Phishing Dark Waters The Offensive and Defensive Sides of Malicious Emails

91. Seven Deadliest Network Attacks

92. Seven Deadliest USB Attacks

93. Seven Deadliest USB Attacks

94. Seven Deadliest Web Application Attacks

95. Seven Deadliest Wireless Technologies Attacks

96. The 60 Minute Network Security Guide, National Security Agency

97. The Basics of Hacking and Penetration

98. WAF Bypassing

99. Windows_Services_-_All_roads_lead_to_SYSTEM

100. Web Penetration Testing with Kali Linux

← All writing