Web Hacking
(häftad)Attacks and Defense
av Stuart McClure
- Format:
- Häftad (paperback)
- Utgiven:
- 2002-08-01
- Språk:
- Engelska
--From the Foreword by William C. Boni, Chief Information Security Officer, Motorola"Just because you have a firewall and IDS sensor does not mean you aresecure; this book shows you why."
--Lance Spitzner, Founder, The Honeynet ProjectWhether it's petty defacing or full-scale cyber robbery, hackers are moving to the Web along with everyone else. Organizations using Web-based business applications are increasingly at risk. Web Hacking: Attacks and Defense is a powerful guide to the latest information on Web attacks and defense. Security experts Stuart McClure (lead author of Hacking Exposed), Saumil Shah, and Shreeraj Shah present a broad range of Web attacks and defense.
Features include:
- Overview of the Web and what hackers go after
- Complete Web application security methodologies
- Detailed analysis of hack techniques
- Countermeasures
- What to do at development time to eliminate vulnerabilities
- New case studies and eye-opening attack scenarios
- Advanced Web hacking concepts, methodologies, and tools
"How Do They Do It?" sections show how and why different attacks succeed, including:
- Cyber graffiti and Web site defacements
- e-Shoplifting
- Database access and Web applications
- Java application servers; how to harden your Java Web Server
- Impersonation and session hijacking
- Buffer overflows, the most wicked of attacks
- Automated attack tools and worms
Appendices include a listing of Web and database ports, cheat sheets for remote command execution, and source code disclosure techniques.
Web Hacking informs from the trenches. Experts show you how to connect the dots--how to put the stages of a Web hack together so you can best defend against them. Written for maximum brain absorption with unparalleled technical content and battle-tested analysis, Web Hacking will help you combat potentially costly security threats and attacks.
0201761769B07192002
(Pearson)
Fler böcker av Stuart McClure
Hacking Exposed: Network Security Secrets & Solution...Stuart McClure, Joel Scambray, George Kurtz (häftad) |
Hacking Exposed 5th EditionStuart McClure, Joel Scambray, George Kurtz (e-bok) |
Hacking Exposed, Sixth EditionStuart McClure, Joel Scambray, George Kurtz (e-bok) |
Hacking For DummiesKevin Beaver, Stuart McClure (e-bok) | |||
|
264:- Köp
|
529:- Visa
|
529:- Visa
|
185:- Visa
|
Kundrecensioner
Bloggat om Web Hacking
Övrig information
Stuart McClure, President/CTO, Foundstone, Inc., brings over 12 years of IT and security experience to Foundstone. Stuart is a successful security author, speaker, and teacher whose writings have been translated into dozens of languages around the world. Stuart is the lead author of the best-selling security book Hacking Exposed: Network Security Secrets and Solutions, which has been translated into 19 languages, and has received critical acclaim around the world. In addition, it was ranked the #4 computer book sold on Amazon in 2001, positioning it as the best selling security book ever sold. Prior to co-founding Foundstone, Stuart was a Senior Manager with Ernst & Young's National Security Profiling Team responsible for project management, attack and penetration reviews, and security technology evaluations. Prior to Ernst & Young, Stuart was a Security Analyst for the InfoWorld Test Center where he covered the security industry and evaluated over 100 network and security products specializing in firewalls, security auditing, intrusion detection, and public key infrastructure (PKI). Prior to InfoWorld, Stuart was the IT manager for State and Local Governments, supporting Novell, NT, Solaris, AIX, and AS/400 platforms. Stuart holds a B.A. degree from the University of Colorado, Boulder and numerous certifications including ISC2's CISSP, Novell's CNE, and Check Point's CCSE. Saumil continues to lead the efforts in e-commerce security research at Net-Square. His focus is on researching vulnerabilities with various e-commerce and Web-based application systems. Saumil also provides information security consulting services to Net-Square clients, specializing in ethical hacking and security architecture. He holds a designation of Certified Information Systems Security Professional. Saumil has had more than eight years experience with system administration, network architecture, integrating heterogenous platforms and information security, and has perfomed numerous ethical hacking exercises for many significant companies in the IT area. Saumil is a regular speaker at security conferences such as BlackHat, RSA, etc. Previously, Saumil was the Director of Indian Operations for Foundstone Inc, where he was instrumental in developing their Web application security assessment methodology, the Web assessment component of FoundScan--Foundstone's Managed Security Services software and was instrumental in pioneering Foundstone's Ultimate Web Hacking training class. Prior to joining Foundstone, Saumil was a senior consultant with Ernst & Young, where he was responsible for the company's ethical hacking and security architecture solutions. Saumil has also worked at the Indian Institute of Management, Ahmedabad, as a research assistant and is currently a visiting faculty member there. Saumil graduated from Purdue University with a master's degree in computer science and a strong research background in operating systems, networking, information security, and cryptography. At Purdue, he was a research assistant in the COAST (Computer Operations, Audit and Security Technology) laboratory. He got his undergraduate degree in computer engineering from Gujarat University, India. Saumil is also the author of The Anti-Virus Book (Tata McGraw-Hill, 1996). Shreeraj leads the software development and research arm of Net-Square. His role is to develop new methodologies for Web application security assessment and defense. In the past, he has been involved in several Web application assessment projects, protocol analysis, code reviews, ethical Web hacking, etc. He has also been a speaker at RSA and BlackHat. Shreeraj has vast experience in the fields of security, application development, and network administration in addition to his strong technical background, client management skills, project management, and research methodologies. He was a member of the core development t
(Pearson)
Innehållsförteckning
(NOTE: Each chapter begins with an Introduction and concludes with a Summary.)
Foreword.
Introduction.
I. THE E-COMMERCE PLAYGROUND.
Case Study: Acme Art, Inc. Hacked!1. Web Languages: The Babylon of the 21st Century.Languages of the Web.HTML.Dynamic HTML (DHTML).XML.XHTML.Perl.PHP.ColdFusion.Active Server Pages.CGI.Java.2. Web and Database Servers.Web Servers.Apache.Microsoft's Internet Information Server (IIS).Database Servers.Microsoft SQL Server.Oracle.3. Shopping Carts and Payment Gateways.Evolution of the Storefront.Electronic Shopping.Shopping Cart Systems.Scope and Lifetime of an Electronic Shopping Cart.Collecting, Analyzing, and Comparing Selected Components.Keeping Track of the Total Cost.Change of Mind.Processing the Purchase.Implementation of a Shopping Cart Application.Product Catalog.Session Management.Database Interfacing.Integration with the Payment Gateway.Examples of Poorly Implemented Shopping Carts.Carello Shopping Cart.DCShop Shopping Cart.Hassan Consulting's Shopping Cart.Cart32 and Several Other Shopping Carts.Processing Payments.Finalizing the Order.Method of Payment.Verification and Fraud Protection.Order Fulfillment and Receipt Generation.Overview of the Payment Processing System.Innovative Ways to Combat Credit Card Fraud.Order Confirmation Page.Payment Gateway Interface.Transaction Database Interface.Interfacing with a Payment GatewayAn Example.Payment System Implementation Issues.Integration.Temporary Information.SSL.Storing User Profiles.Vulnerabilities Caused by Poor Integration of Shopping Cart and Payment Gateway.PayPalEnabling Individuals to Accept Electronic Payments.4. HTTP and HTTPS: The Hacking Protocols.Protocols of the Web.HTTP.HTTPS (HTTP over SSL).5. URL: The Web Hacker's Sword.URL Structure.Web Hacker Psychology.URLs and Parameter Passing.URL Encoding.
(Pearson)