2006 was my most productive reading and reviewing year yet. I read and reviewed 17 in 2000, 42 in 2001, 24 in 2002, 33 in 2003, 33 in 2004, 26 in 2005. This year I read and reviewed 52 books. I was determined to make as big a dent as possible in the huge stack of books sent to me by publishers and blog readers, and I made a lot of progress.
My ratings yielded the following:
- 1 star: 0 books
- 2 stars: 1 book
- 3 stars: 9 books
- 4 stars: 29 books
- 5 stars: 13 books
Because I don't try to read every book, I'm glad my ratings are skewed towards the higher end. I don't intentionally read books I expect to be bad.
I thought I would list the 13 books that I gave five stars, starting with my favorite and working down.
- 802.11 Wireless Networks: The Definitive Guide, 2nd Ed by Matthew S Gast: A first-rate technical book that dispels myths by speaking authoritatively and comprehensively.
- Running IPv6 by Iljitsch-van-Beijnum: A close second, this book nicely describes IPv6 in a practical manner.
- Protect Your Windows Network by Jesper M. Johansson and Steve Riley: Yes, really -- a "Windows" book! This book is amazing because the security principles within apply to any platform.
- The Debian System by Martin F. Krafft: I would love to see a book like this written for FreeBSD.
- PGP-GPG by Michael Lucas: This book should be given to anyone who needs to use PGP or GPG, before they create their first key!
- IPv6 Essentials, 2nd Ed by Sylvia Hagen: This book is the perfect companion for the previous IPv6 book, because this title is mostly IPv6 formats and theory.
- Software Security by Gary McGraw: Of the six books I read this year on building secure software, this was my favorite and the only five-star recipient.
- Hacking Exposed: Web Applications, 2nd Ed by Mike Shema, Joel Scambray, and Caleb Sima: I liked this book because it is a thorough update of the 1st Ed, and it covers the subject very well. It still won't win over all you HE-bashers out there. (You know who you are.)
- Apache Security by Ivan Ristic: This is the best book on Apache security, and a good introduction to Web attacks as well.
- Phishing Exposed by Lance James: I liked this book because it seemed to extend the boundaries of knowledge regarding phishing, and not just rehash old attacks.
- File System Forensic Analysis by Brian Carrier: If you do any sort of host-centric forensics, this book is a must-have.
- Pro Nagios 2.0 by James Turnbull: The best Nagios book, thus far.
- Skype Me! by Michael Gough: Wow, I gave a Skype book five stars? It was very well-written.
So, congratulations to Matthew Gast for being my favorite author of 2006!
I have more than 30 books sitting on my shelf waiting to be read now, and another 40 plus books on my Amazon.com Wish List. I've assigned priority values to the Wish List based on projected publication date. In other words, books that are already on shelves or due soon are rated "Highest." Books arriving next year, for example, are rated "lowest."
If you find my reviews helpful, please rate them as such at Amazon.com. I look forward to hitting the 4000 mark for "Helpful Votes" in 2007. I hit 1500 three years ago and 3000 at the beginning of 2006. Since I am not paid for my reviews I appreciate any indication that they are helpful. Thank you.
Copyright 2006 Richard Bejtlich
Thank you to Patricia at
It would be nice if the Tag in this situation were a watch, but it turns out 
As a security person I try to take notice of security measures in non-digital settings. These are a few I noticed this week.
In my 2005 

I wanted to quickly highlight two FreeBSD developments.
I came across this 

This is a follow-up to
First things first. Inside threat is not new. Check out the lead line from a security story:
Here's my point: why are security managers so worried about Eva the Engineer or Stan the Secretary when Renfro the Romanian is stealing data right now. I read somewhere (I can't cite it now) that something like 70 million hosts on the Internet may be under illegitimate control. It may make sense to speak more of the number of hosts not compromised instead of those that are compromised. In 2004 the authors of the great book
During some holiday downtime I managed to catch up on some reading. Recently I
Thanks to those of you who responded to my post
The
Today I received an email which said in part:
I noticed this
I found the following quote by Microsoft's Ray Ozzie, in 


Web site defacement mirror
My post on the
One of my clients wants to know if it's possible to implement something like the
I'm not an auditor or CPA, thank goodness. The first time I heard of
For my 1700th post (as reported by the new Blogging infrastructure) I thought I would report on an issue I'm looking at in
The 
I have a feeling these 
Two publishers were kind enough to send new books last week. I plan to read and review both early next year. The first is McGraw-Hill/Osborne's
The second is Syngress'
In June and July this year I devoted several posts to covering the 
I will attend a book signing event at
I'd like to address a few issues that arose during class Sunday and Monday.
I still have a few open seats left for part 2 of the course on Saturday 9 Dec 06 and Sunday 10 Dec 06, which covers the topics addressed in this
Two publishers were kind enough to send new books last week. I plan to read and review both early next year. The first is Apress'
Second is Syngress'
This note is intended for students in days 
