• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% studentrabatt med kod TERM26

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare

    Mina sidor

      Hjälp

      • Kundservice
      • Vanliga frågor och svar
      • Frakt och leverans
      • Retur vid ångerrätt
      • Reklamera vara
      • Betalning
      • Köpvillkor
      • Allmänna villkor
      • Information om webbplatsens tillgänglighet

      Om Bokus

      • Om oss
      • Pressrum
      • För studenter
      • För företag
      • För bibliotek och offentlig verksamhet
      • För leverantörer
      • Hållbarhet

      Populärt

      • Aktuella erbjudanden
      • Presentkort
      • Studentlitteratur
      • Nya böcker
      • Topplistor
      • Signerade böcker
      • Engelska böcker

      Inspiration

      • Boktips
      • BookTok
      • Populära bokserier
      • Barnbokskaraktärer
      • Populära författare
      Logotyp för Bokus
      Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
      bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
      Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
      1. Data och IT
      2. Nätverk och kommunikation

      Web Application Hacker's Handbook

      Finding and Exploiting Security Flaws

      AvDafydd Stuttard,Marcus Pinto

      Häftad, Engelska, 2011

      457 kr

      Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

      Beskrivning

      The highly successful security book returns with a new edition, completely updated Web applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of ever-evolving web applications. You'll explore the various new technologies employed in web applications that have appeared since the first edition and review the new attack techniques that have been developed, particularly in relation to the client side. Reveals how to overcome the new technologies and techniques aimed at defending web applications against attacks that have appeared since the previous editionDiscusses new remoting frameworks, HTML5, cross-domain integration techniques, UI redress, framebusting, HTTP parameter pollution, hybrid file attacks, and moreFeatures a companion web site hosted by the authors that allows readers to try out the attacks described, gives answers to the questions that are posed at the end of each chapter, and provides a summarized methodology and checklist of tasksFocusing on the areas of web application security where things have changed in recent years, this book is the most current resource on the critical topic of discovering, exploiting, and preventing web application security flaws.

      Produktinformation

      • Utgivningsdatum:2011-10-07
      • Mått:188 x 234 x 50 mm
      • Vikt:1 330 g
      • Format:Häftad
      • Språk:Engelska
      • Antal sidor:912
      • Upplaga:2
      • Förlag:John Wiley & Sons Inc
      • ISBN:9781118026472

      Utforska kategorier

      • Nätverk och kommunikation inom Data och IT

      Mer om författaren

      DAFYDD STUTTARD is an independent security consultant, author, and software developer specializing in penetration testing of web applications and compiled software. Under the alias PortSwigger, Dafydd created the popular Burp Suite of hacking tools. MARCUS PINTO delivers security consultancy and training on web application attack and defense to leading global organizations in the financial, government, telecom, gaming, and retail sectors.The authors cofounded MDSec, a consulting company that provides training in attack and defense-based security.

      Innehållsförteckning

      • Introduction xxiiiChapter 1 Web Application (In)security 1The Evolution of Web Applications 2Web Application Security 6Summary 15Chapter 2 Core Defense Mechanisms 17Handling User Access 18Handling User Input 21Handling Attackers 30Managing the Application 35Summary 36Questions 36Chapter 3 Web Application Technologies 39The HTTP Protocol 39Web Functionality 51Encoding Schemes 66Next Steps 70Questions 71Chapter 4 Mapping the Application 73Enumerating Content and Functionality 74Analyzing the Application 97Summary 114Questions 114Chapter 5 Bypassing Client-Side Controls 117Transmitting Data Via the Client 118Capturing User Data: HTML Forms 127Capturing User Data: Browser Extensions 133Handling Client-Side Data Securely 154Summary 156Questions 157Chapter 6 Attacking Authentication 159Authentication Technologies 160Design Flaws in Authentication Mechanisms 161Implementation Flaws in Authentication 185Securing Authentication 191Summary 201Questions 202Chapter 7 Attacking Session Management 205The Need for State 206Weaknesses in Token Generation 210Weaknesses in Session Token Handling 233Securing Session Management 248Summary 254Questions 255Chapter 8 Attacking Access Controls 257Common Vulnerabilities 258Attacking Access Controls 266Securing Access Controls 278Summary 284Questions 284Chapter 9 Attacking Data Stores 287Injecting into Interpreted Contexts 288Injecting into SQL 291Injecting into NoSQL 342Injecting into XPath 344Injecting into LDAP 349Summary 354Questions 354Chapter 10 Attacking Back-End Components 357Injecting OS Commands 358Manipulating File Paths 368Injecting into XML Interpreters 383Injecting into Back-end HTTP Requests 390Injecting into Mail Services 397Summary 402Questions 403Chapter 11 Attacking Application Logic 405The Nature of Logic Flaws 406Real-World Logic Flaws 406Avoiding Logic Flaws 428Summary 429Questions 430Chapter 12 Attacking Users: Cross-Site Scripting 431Varieties of XSS 433XSS Attacks in Action 442Finding and Exploiting XSS Vulnerabilities 451Preventing XSS Attacks 492Summary 498Questions 498Chapter 13 Attacking Users: Other Techniques 501Inducing User Actions 501Capturing Data Cross-Domain 515The Same-Origin Policy Revisited 524Other Client-Side Injection Attacks 531Local Privacy Attacks 550Attacking ActiveX Controls 555Attacking the Browser 559Summary 568Questions 568Chapter 14 Automating Customized Attacks 571Uses for Customized Automation 572Enumerating Valid Identifiers 573Harvesting Useful Data 583Fuzzing for Common Vulnerabilities 586Putting It All Together: Burp Intruder 590Barriers to Automation 602Summary 613Questions 613Chapter 15 Exploiting Information Disclosure 615Exploiting Error Messages 615Gathering Published Information 625Using Inference 626Preventing Information Leakage 627Summary 629Questions 630Chapter 16 Attacking Native Compiled Applications 633Buffer Overflow Vulnerabilities 634         Integer Vulnerabilities 640Format String Vulnerabilities 643Summary 645Questions 645Chapter 17 Attacking Application Architecture 647Tiered Architectures 647Shared Hosting and Application Service Providers 656Summary 667Questions 667Chapter 18 Attacking the Application Server 669Vulnerable Server Configuration 670Vulnerable Server Software 684Web Application Firewalls 697Summary 699Questions 699Chapter 19 Finding Vulnerabilities in Source Code 701Approaches to Code Review 702Signatures of Common Vulnerabilities 704The Java Platform 711ASP.NET 718PHP 724Perl 735JavaScript 740Database Code Components 741Tools for Code Browsing 743Summary 744Questions 744Chapter 20 A Web Application Hacker’s Toolkit 747Web Browsers 748Integrated Testing Suites 751Standalone Vulnerability Scanners 773Other Tools 785Summary 789Chapter 21 A Web Application Hacker’s Methodology 791General Guidelines 7931 Map the Application’s Content 7952 Analyze the Application 7983 Test Client-Side Controls 8004 Test the Authentication Mechanism 8055 Test the Session Management Mechanism 8146 Test Access Controls 8217 Test for Input-Based Vulnerabilities 8248 Test for Function-Specific Input Vulnerabilities 8369 Test for Logic Flaws 84210 Test for Shared Hosting Vulnerabilities 84511 Test for Application Server Vulnerabilities 84612 Miscellaneous Checks 84913 Follow Up Any Information Leakage 852Index 853
      Hoppa över listan

      Mer från samma författare

      Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard - Attack and Defend Computer Security Set, E-bok

      Attack and Defend Computer Security Set

      Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard

      E-bok
      2014

      854 kr

      Marcus Pinto, Dafydd Stuttard - Web Application Hacker's Handbook, E-bok

      Web Application Hacker's Handbook

      Marcus Pinto, Dafydd Stuttard

      E-bok
      2011

      561 kr

      Marcus Pinto, Dafydd Stuttard - Web Application Hacker's Handbook, E-bok

      Web Application Hacker's Handbook

      Marcus Pinto, Dafydd Stuttard

      E-bok
      2011

      561 kr

      Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard - Attack and Defend Computer Security Set, E-bok

      Attack and Defend Computer Security Set

      Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard

      E-bok
      2014

      854 kr

      Dafydd Stuttard, Marcus Pinto, Michael Hale Ligh, Steven Adair, Blake Hartstein, Ozh Richard - Attack and Defend Computer Security Set, Häftad

      Attack and Defend Computer Security Set

      Dafydd Stuttard, Marcus Pinto, Michael Hale Ligh, Steven Adair, Blake Hartstein, Ozh Richard

      Häftad, 2014

      658 kr

      Hoppa över listan

      Du kanske också är intresserad av

      Marcus Pinto, Dafydd Stuttard - Web Application Hacker's Handbook, E-bok

      Web Application Hacker's Handbook

      Marcus Pinto, Dafydd Stuttard

      E-bok
      2011

      561 kr

      Dafydd Stuttard, Marcus Pinto, Michael Hale Ligh, Steven Adair, Blake Hartstein, Ozh Richard - Attack and Defend Computer Security Set, Häftad

      Attack and Defend Computer Security Set

      Dafydd Stuttard, Marcus Pinto, Michael Hale Ligh, Steven Adair, Blake Hartstein, Ozh Richard

      Häftad, 2014

      658 kr

      Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard - Attack and Defend Computer Security Set, E-bok

      Attack and Defend Computer Security Set

      Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard

      E-bok
      2014

      854 kr

      Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard - Attack and Defend Computer Security Set, E-bok

      Attack and Defend Computer Security Set

      Ozh Richard, Blake Hartstein, Steven Adair, Michael Hale Ligh, Marcus Pinto, Dafydd Stuttard

      E-bok
      2014

      854 kr

      Marcus Pinto, Dafydd Stuttard - Web Application Hacker's Handbook, E-bok

      Web Application Hacker's Handbook

      Marcus Pinto, Dafydd Stuttard

      E-bok
      2011

      561 kr

      Måns Petter Zelmerlöw - När allt faller, Inbunden
      • -12%

      När allt faller

      Måns Petter Zelmerlöw

      Inbunden, 2026

      229 kr259 kr

      Carola Häggkvist - SIGNERAD - Jag är Carola, Inbunden
      • Signerad!

      SIGNERAD - Jag är Carola

      Carola Häggkvist

      Inbunden, 2026

      269 kr

      Klara Peters Bastin - SIGNERAD - Om julens wälgång, Inbunden
      • Signerad!

      SIGNERAD - Om julens wälgång

      Klara Peters Bastin

      Inbunden, 2026

      249 kr

      Syou Ishida - Katt på recept, Pocket
      • -30%

      Katt på recept

      Syou Ishida

      Pocket, 2026

      69 kr99 kr

      Roland Paulsen - Avbegåvad : en essäberättelse om arv och miljö, Inbunden
      • -15%

      Avbegåvad : en essäberättelse om arv och miljö

      Roland Paulsen

      Inbunden, 2026

      225 kr265 kr