• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod: NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    Beginner's Guide To Web Application Penetration Testing

    AvAli Abdollahi

    Häftad, Engelska, 2025

    Del i serien Tech Today

    557 kr

    Beställningsvara. Skickas inom 5-8 vardagar. Fri frakt över 249 kr.

    Fler format och utgåvor

    E-bok

    691 kr

    E-bok

    634 kr

    Beskrivning

    A hands-on, beginner-friendly intro to web application pentesting In A Beginner's Guide to Web Application Penetration Testing, seasoned cybersecurity veteran Ali Abdollahi delivers a startlingly insightful and up-to-date exploration of web app pentesting. In the book, Ali takes a dual approach—emphasizing both theory and practical skills—equipping you to jumpstart a new career in web application security. You'll learn about common vulnerabilities and how to perform a variety of effective attacks on web applications. Consistent with the approach publicized by the Open Web Application Security Project (OWASP), the book explains how to find, exploit and combat the ten most common security vulnerability categories, including broken access controls, cryptographic failures, code injection, security misconfigurations, and more. A Beginner's Guide to Web Application Penetration Testing walks you through the five main stages of a comprehensive penetration test: scoping and reconnaissance, scanning, gaining and maintaining access, analysis, and reporting. You'll also discover how to use several popular security tools and techniques—like as well as: Demonstrations of the performance of various penetration testing techniques, including subdomain enumeration with Sublist3r and Subfinder, and port scanning with NmapStrategies for analyzing and improving the security of web applications against common attacks, includingExplanations of the increasing importance of web application security, and how to use techniques like input validation, disabling external entities to maintain securityPerfect for software engineers new to cybersecurity, security analysts, web developers, and other IT professionals, A Beginner's Guide to Web Application Penetration Testing will also earn a prominent place in the libraries of cybersecurity students and anyone else with an interest in web application security.

    Produktinformation

    • Utgivningsdatum:2025-02-11
    • Mått:185 x 234 x 23 mm
    • Vikt:499 g
    • Format:Häftad
    • Språk:Engelska
    • Serie:Tech Today
    • Antal sidor:352
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781394295593

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT
    • IT-säkerhet inom Data och IT

    Mer om författaren

    ALI ABDOLLAHI is a cybersecurity researcher with over 12 years of experience. Currently, he is the application and offensive security manager at Canon EMEA. He studied computer engineering, published articles, and holds several professional certificates. Ali is a Microsoft MVP and regular speaker or trainer at industry conferences and events.

    Innehållsförteckning

    • Foreword xviiIntroduction xixChapter 1 Introduction to Web Application Penetration Testing 1The Importance of Web Application Security 3Overview of Web Application Penetration Testing 6The Penetration Testing Process 8Methodologies 12Tools and Techniques 14Reporting 16Types of Web Application Vulnerabilities 17Key Takeaways 25Chapter 2 Setting Up Your Penetration Testing Environment 27Setting Up Virtual Machines 28Container Option 29Kali Linux Installation 30PentestBox 34Installing DVWA 35OWASP Juice Shop 40Burp Suite 41OWASP ZED Attack Proxy 46WILEY Preconfigured Environment 49Key Takeaways 49Chapter 3 Reconnaissance and Information Gathering 51Passive Information Gathering 52Automating Subdomain Enumeration 61Active Information Gathering 64Open-Source Intelligence Gathering 77Key Takeaways 88Chapter 4 Cross-Site Scripting 89XSS Categories 90Reflected XSS 91Stored XSS 93Automatic User Session Hijacking 94Website Defacement Using XSS 96DOM-Based XSS 97Self-XSS 98Browser Exploitation Framework 100XSS Payloads and Bypasses 102XSS Mitigation Techniques 105Reflected XSS Bypass Techniques 107Stored XSS Bypass Technique 110Key Takeaways 112Chapter 5 SQL Injection 113What Is SQL Injection? 113Types of SQL Injection 114Error-Based SQL Injection 117Union-Based SQL Injection 117Blind SQL Injection 123SQLMap 126SQL Injection Payloads with ChatGPT 140SQL Injection Prevention 142Key Takeaways 145Chapter 6 Cross-Site Request Forgery 147Hunting CSRF Vulnerability 149CSRF Exploitation 149XSS and CSRF 151Clickjacking 152Generating an Effective Proof of Concept Using ChatGPT 154Tips for Developers 157Key Takeaways 158Chapter 7 Server-Side Attacks and Open Redirects 159Server-Side Request Forgery 159SSRF in Action 160SSRF Vulnerability 162Blind SSRF 164Local File Inclusion 166Remote File Inclusion 170Open Redirect 173Server-Side Attacks Differences 177Security Mitigations 178Key Takeaways 181Chapter 8 XML-Based Attacks 183XML Fundamentals 183XXE Exploitation 185Hunting XML Entry Points 187SSRF Using XXE 192DoS Using XXE 193XXE Payload and Exploitation with ChatGPT 195XML-Based Attacks Countermeasures 196Key Takeaways 198Chapter 9 Authentication and Authorization 201Password Cracking and Brute-Force Attacks 205Credential Stuffing Attack 211Password Spraying 213Password Spraying Using Burp Suite Intruder 214Other Automated Tools for Password Attacks 215JSON Web Token 223Key Takeaways 225Chapter 10 API Attacks 227OWASP API Top 10 228API Enumeration and Discovery 230API Discovery Using ChatGPT 231API Broken Object-Level Authorization Exploitation 235Rate Limiting 240API Penetration Testing Tools 242API Security Tips 244Key Takeaways 245Appendix A Best Practices and Standards 247Information Gathering 248Configuration and Deployment Management Testing 251Identity Management Testing 254Authentication Testing 256Authorization Testing 261Session Management Testing 265Input Validation Testing 273Testing for Error Handling 285Testing for Weak Cryptography 286Business Logic Testing 290Client-Side Testing 297Appendix B CWE and CVSS Score 307Base Score 308Temporal Score 308Environmental Score 309Appendix c Writing Effective and Comprehensive Penetration Testing Reports 311Table of Contents (ToC) 311Project History and Timeline 311Scope 312Testing Approach 312Executive Summary 312Industry Standard 312Findings Table 312Findings Details 313Key Takeaways 315Index 317