Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

HACKING EXPOSED WEB APPLICATIONS, 3rd Edition Review

HACKING EXPOSED WEB APPLICATIONS, 3rd Edition
Average Reviews:

(More customer reviews)
Are you looking to buy HACKING EXPOSED WEB APPLICATIONS, 3rd Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on HACKING EXPOSED WEB APPLICATIONS, 3rd Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

HACKING EXPOSED WEB APPLICATIONS, 3rd Edition ReviewThis is the third Hacking Exposed: Web Applications (HE:WA) book I've reviewed, having reviewed the second edition in 2006 and the first edition in 2002. While I gave the earlier editions each five stars, I don't think HE:WA3E quite meets my expectations of a five star web application security book -- at least not one bearing the Hacking Exposed (HE) series name.
In my opinion, the winning formula for a good HE book was set by the first in the series, back in 1999: 1) explain a technology of interest; 2) show exactly how to exploit it; 3) recommend countermeasures. For me, these three steps MUST be followed, and any book with HE in the title that fails to follow this recipe is likely to fall flat. The reason I like this approach is simple; in many cases, defenders first encounter a new technology only after a researcher or intruder has broken it! In other words, the offensive side is usually far ahead of the defensive side, because offenders often specialize in a promising new area and pursue it relentlessly until they break it. Good HE books help redress this imbalance by getting the defender up to speed on a new technology, showing how to break it, and then suggesting defensive measures.
I believe that while HE:WA3E adopts some of this approach, it seems to not be consistently applied. In fact, I'm wondering if the absence of Mike Shema from the author team could be the reason for this change. Mike's handiwork still appears as a legacy of using older material, but elsewhere I found myself missing the HE formula.
For example, ch 9 seems to diverge from the HE recipe. It also seemed "light" to me compared to the prevalence of client-side exploitation. When HE:WA2E arrived in 2006, client-side attacks had been popular for about three years. I would have expected HE:WA3E (even though it's a "Web apps" book) to spend much more time on exploiting Web clients given the events of the past five years.
If you're wondering how the contents of HE:WA3E compare to HE:WA2E, it appears that concepts from the old ch 7 "Attacking Web Datastores" now appears in ch 6 ("Input Injection Attacks"), and ch 11 "Denial of Service (DoS) Attacks" is gone. I could tell when some material was repeated, but in other areas I could see updates (mention of the SHODAN search engine -- though not the "full details" listed on the back cover! -- for example).
Content-wise, the authors appeared to know a lot about their subject. Since I know all three from their conference appearances, I was confident in their expertise. One small note: I was disappointed by the screen shots in ch 10. The authors should keep in mind that screen captures from high resolution monitors do not translate well in print, especially when the images are fuzzy or very small.
Overall, I like HE:WA3E, but I hope to see a fourth edition return to the winning HE formula. I'd also like to see the authors take a look at some of the competing Web security books to see where they could differentiate to add even more value.HACKING EXPOSED WEB APPLICATIONS, 3rd Edition Overview
The latest Web app attacks and countermeasures from world-renowned practitioners
Protect your Web applications from malicious attacks by mastering the weapons and thought processes of today's hacker. Written by recognized security practitioners and thought leaders, Hacking Exposed Web Applications, Third Edition is fully updated to cover new infiltration methods and countermeasures. Find out how to reinforce authentication and authorization, plug holes in Firefox and IE, reinforce against injection attacks, and secure Web 2.0 features. Integrating security into the Web development lifecycle (SDL) and into the broader enterprise information security program is also covered in this comprehensive resource.

Get full details on the hacker's footprinting, scanning, and profiling tools, including SHODAN, Maltego, and OWASP DirBuster
See new exploits of popular platforms like Sun Java System Web Server and Oracle WebLogic in operation
Understand how attackers defeat commonly used Web authentication technologies
See how real-world session attacks leak sensitive data and how to fortify your applications
Learn the most devastating methods used in today's hacks, including SQL injection, XSS, XSRF, phishing, and XML injection techniques
Find and fix vulnerabilities in ASP.NET, PHP, and J2EE execution environments
Safety deploy XML, social networking, cloud computing, and Web 2.0 services
Defend against RIA, Ajax, UGC, and browser-based, client-side exploits
Implement scalable threat modeling, code review, application scanning, fuzzing, and security testing procedures


Want to learn more information about HACKING EXPOSED WEB APPLICATIONS, 3rd Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws Review

The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws
Average Reviews:

(More customer reviews)
Are you looking to buy The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws ReviewThis is the most important IT security title written in the past year or more. Why? Custom web applications offer more opportunities for exploitation than all of the publicized vulnerabilities your hear about combined. This book gives expert treatment to the subject. I found the writing to be very clear and concise in this 727 page volume. There is minimal fluff. While everything is clearly explained, this is not a beginners book. The authors assume that you can read html, JavaScript, etc... Usually with a book like this there are a few really good chapters and some so-so chapters, but that's not the case here. Chapters 3-18 in this book rock all the way through. Another huge plus is the tools in this book are free.
The first few chapters provide context and background information. Chapter 3 on Web Application Technologies provides particularly useful background info. The next 666 pages of the book are all about attacking the applications.
There next five chapters cover mapping application functionality, client side controls, authentication, sessions, and access controls. The coverage is comprehensive. I'm not new to these topics, but I learned so much in every chapter. The depth of coverage is amazing.
The next six chapters are the heart of this book. They cover injection, path traversal, application logic, XSS and related attacks, automating attacks, and information disclosure. You'll find full treatment of attacks we're all familiar with like SQL injection and cross site scripting as well as many that most of us haven't heard of before. The danger is real and these chapters need to be read.
The final next four chapters cover attacks against compiled applications, application architecture, web servers, and source code. The final two chapters are more useful as a quick reference. They provide an overview of the tools covered throughout the book and describe attack methodology discussed throughout the book for exploiting each technology.
This book scores five easily based on the relevance and value of the information.The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws OverviewThis book is a practical guide to discovering and exploiting security flaws in web applications. The authors explain each category of vulnerability using real-world examples, screen shots and code extracts. The book is extremely practical in focus, and describes in detail the steps involved in detecting and exploiting each kind of security weakness found within a variety of applications such as online banking, e-commerce and other web applications.
The topics covered include bypassing login mechanisms, injecting code, exploiting logic flaws and compromising other users. Because every web application is different, attacking them entails bringing to bear various general principles, techniques and experience in an imaginative way. The most successful hackers go beyond this, and find ways to automate their bespoke attacks. This handbook describes a proven methodology that combines the virtues of human intelligence and computerized brute force, often with devastating results.
The authors are professional penetration testers who have been involved in web application security for nearly a decade. They have presented training courses at the Black Hat security conferences throughout the world. Under the alias "PortSwigger", Dafydd developed the popular Burp Suite of web application hack tools.

Want to learn more information about The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...