书目

The Web Application Hacker's Handbook 黑客攻防技术宝典:Web实战篇

  • 作者 DafyddMarcus Pinto
  • 出版社 Wiley
  • 出版时间 2011年9月 第2版
  • ISBN 9781118026472
  • 定价 504.50

内容简介

Thehighlysuccessfulsecuritybookreturnswithanewedition,completelyupdatedWebapplicationsarethefrontdoortomostorganizations,exposingthemtoattacksthatmaydisclosepersonalinformation,executefraudulenttransactions,orcompromiseordinaryusers.Thispracticalbookhasbeencompletelyupdatedandrevisedtodiscussthelateststep-by-steptechniquesforattackinganddefendingtherangeofever-evolvingwebapplications.You'llexplorethevariousnewtechnologiesemployedinwebapplicationsthathaveappearedsincethefirsteditionandreviewthenewattacktechniquesthathavebeendeveloped,particularlyinrelationtotheclientside.RevealshowtoovercomethenewtechnologiesandtechniquesaimedatdefendingwebapplicationsagainstattacksthathaveappearedsincethepreviouseditionDiscussesnewremotingframeworks,HTML5,cross-domainintegrationtechniques,UIredress,framebusting,HTTPparameterpollution,hybridfileattacks,andmoreFeaturesacompanionwebsitehostedbytheauthorsthatallowsreaderstotryouttheattacksdescribed,givesanswerstothequestionsthatareposedattheendofeachchapter,andprovidesasummarizedmethodologyandchecklistoftasksFocusingontheareasofwebapplicationsecuritywherethingshavechangedinrecentyears,thisbookisthemostcurrentresourceonthecriticaltopicofdiscovering,exploiting,andpreventingwebapplicationsecurityflaws.

作者简介

DAFYDDSTUTTARDisanindependentsecurityconsultant,author,andsoftwaredeveloperspecializinginpenetrationtestingofwebapplicationsandcompiledsoftware.UnderthealiasPortSwigger,DafyddcreatedthepopularBurpSuiteofhackingtools.MARCUSPINTOdeliverssecurityconsultancyandtrainingonwebapplicationattackanddefensetoleadingglobalorganizationsinthefinancial,government,telecom,gaming,andretailsectors.TheauthorscofoundedMDSec,aconsultingcompanythatprovidestraininginattackanddefense-basedsecurity.

—  END  —