TITLE : The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws (Paperback)
AUTHOR : by Dafydd Stuttard (Author), Marcus Pinto (Author)
PUBLISHER : Wiley publisher
ISBN : 0470170778
EDITION : 1st
PUB DATE : October 22, 2007
LANGUAGE : English
RLS DATE : 12/02/2007
MAKER : BBL
SUPPLIER : BBL
PACKAGER : BBL
FORMAT : PDF
SIZE : 02 x 2.88 MB
[ R e l e a s e N o t e s ]
This book is a practical guide to discovering and exploiting security
flaws in web applications. The authors explain each category of
vulnerability using real-world examples, screen shots and code extracts.
The book is extremely practical in focus, and describes in detail the
steps involved in detecting and exploiting each kind of security
weakness found within a variety of applications such as online banking,
e-commerce and other web applications. The topics covered include
bypassing login mechanisms, injecting code, exploiting logic flaws and
compromising other users. Because every web application is different,
attacking them entails bringing to bear various general principles,
techniques and experience in an imaginative way. The most successful
hackers go beyond this, and find ways to automate their bespoke attacks.
This handbook describes a proven methodology that combines the virtues
of human intelligence and computerized brute force, often with
devastating results. The authors are professional penetration testers
who have been involved in web application security for nearly a decade.
They have presented training courses at the Black Hat security
conferences throughout the world. Under the alias "PortSwigger", Dafydd
developed the popular Burp Suite of web application hack tools.
URL: http://www.amazon.com/exec/obidos/tg/detail/-/0470170778/
Download:
http://depositfiles.com/files/2576173
Mirror Download:
http://rapidshare.com/files/73917043/0470170778.zip
The Web Application Hacker's Handbook: Discovering and Exploiting, Security Flaws (Paperback) Oct.2007.eBook-BBL
本书为一本实战指南,详细介绍了发现并利用Web应用程序安全漏洞的方法。作者通过真实的案例、截图及代码片段讲解了各种类型的漏洞,如绕过登录机制、代码注入等。适合对在线银行、电子商务和其他Web应用进行渗透测试的专业人士。

被折叠的 条评论
为什么被折叠?



