出版社: Wiley
副标题: Finding and Exploiting Security Flaws
出版年: 2011-9-27
页数: 912
定价: USD 50.00
装帧: Paperback
ISBN: 9781118026472
内容简介 · · · · · ·
The highly successful security book returns with a new edition, completely updated Web applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for...
The highly successful security book returns with a new edition, completely updated Web applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of ever-evolving web applications. You'll explore the various new technologies employed in web applications that have appeared since the first edition and review the new attack techniques that have been developed, particularly in relation to the client side. Reveals how to overcome the new technologies and techniques aimed at defending web applications against attacks that have appeared since the previous edition Discusses new remoting frameworks, HTML5, cross-domain integration techniques, UI redress, framebusting, HTTP parameter pollution, hybrid file attacks, and more Features a companion web site hosted by the authors that allows readers to try out the attacks described, gives answers to the questions that are posed at the end of each chapter, and provides a summarized methodology and checklist of tasks Focusing on the areas of web application security where things have changed in recent years, this book is the most current resource on the critical topic of discovering, exploiting, and preventing web application security flaws.
作者简介 · · · · · ·
作者简介:
Dafydd Stuttard 世界知名安全顾问、作家、软件开发人士。牛津大学博士,MDSec公司联合创始人,尤其擅长Web应用程序和编译软件的渗透测试。Dafydd以网名PortSwigger蜚声安全界,是众所周知的Web应用程序集成攻击平台Burp Suite的开发者。
Marcus Pinto 资深渗透测试专家,剑桥大学硕士,MDSec公司联合创始人。Marcus为全球金融、政府、电信、博彩、零售等行业顶尖组织和机构提供Web应用程序渗透测试和安全防御的咨询与培训。
喜欢读"The Web Application Hacker's Handbook"的人也喜欢 · · · · · ·
-
- Metasploit 8.8
-
- Violent Python 6.7
-
- Hacking 9.0
-
- Web前端黑客技术揭秘 7.5
-
- Web Operations 9.4
-
- HBase 8.6
-
- 计算机病毒防范艺术 8.8
The Web Application Hacker's Handbook的书评 · · · · · · ( 全部 9 条 )

经典啊经典,WEB安全审计人员必看

Burp Suite从入门到精通

黑客攻防技术宝典·WEB实战篇
这篇书评可能有关键情节透露
作者绝对是实力派,很久没看过这么经典的书了。 评论的人少不是因为书不好 而是因为讲解的太深入,很多人没毅力或者没基础读下去 如果你做渗透测试,或者做风险评估,那么,选择它吧! (展开)


跟安全技术大师学习黑客攻防技术
这篇书评可能有关键情节透露
这两位作者都是资深的渗透测试专家。Dafydd原来就是蜚声安全界的PortSwigger!著名Web应用攻击测试工具Burp Suite的开发者!由这样的人主刀这本书,肯定不会让人失望。 本书极其注重实用性,全面而翔实地讨论了如何攻击 Web 应用程序、窃取敏感数据、执行未授权操作,重在介绍... (展开)> 更多书评 9篇
论坛 · · · · · ·
在这本书的论坛里发言这本书的其他版本 · · · · · · ( 全部4 )
-
人民邮电出版社 (2012)8.6分 170人读过
-
人民邮电出版社 (2009)8.4分 88人读过
-
Wiley (2007)9.3分 22人读过
在哪儿借这本书 · · · · · ·
以下书单推荐 · · · · · · ( 全部 )
- 安全待读 (lastmayday)
- 近三年信安渗测技术流非屎类目前仅五本 (豆友2869147)
- T (dhcn)
- 渗透测试 (888)
- HACK (mario)
谁读这本书? · · · · · ·
二手市场
· · · · · ·
订阅关于The Web Application Hacker's Handbook的评论:
feed: rss 2.0
0 有用 非洲小白脸 2014-12-18 17:16:04
指南
3 有用 黄健宁 2016-04-19 20:44:40
没看中文版,据说翻译不好,直接上英文版,开始有点困难,后来就习惯了,还是得push yourself,现在大二,希望在毕业能去知道创宇,为了梦想努力!