Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Professional ASP.NET 3.5 Security, Membership, and Role Management with C# and VB (Wrox Programmer to Programmer) Review

Professional ASP.NET 3.5 Security, Membership, and Role Management with C# and VB (Wrox Programmer to Programmer)
Average Reviews:

(More customer reviews)
Are you looking to buy Professional ASP.NET 3.5 Security, Membership, and Role Management with C# and VB (Wrox Programmer to Programmer)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Professional ASP.NET 3.5 Security, Membership, and Role Management with C# and VB (Wrox Programmer to Programmer). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Professional ASP.NET 3.5 Security, Membership, and Role Management with C# and VB (Wrox Programmer to Programmer) ReviewThe author clearly understands this technology space, I have no complaints with his expertise. And I gained some useful information here and there.
However I found that book to be very dense and overall the book did not feel well edited. Each chapter does a deep dive into the technology, but the information is hard to parse through. The author embeds a lot of reference assembly names and configuration references within the written paragraphs, making it harder to absorb the information.
Perhaps my expectations were wrong. I was hoping for a book that made me feel like a practical expert who could jump straight into a project after reading the book. Instead I felt that the book was more academic treatise than practical manual. I felt like I had been imparted a lot of deep technical information. But I was left with little practical to show for it.
I am giving this book 3 starts because of the author's clear and obvious expertise with the subject matter, and the fact that I did get some useful information here that I could not find elsewhere. But I felt I had to work very hard to get to it.Professional ASP.NET 3.5 Security, Membership, and Role Management with C# and VB (Wrox Programmer to Programmer) OverviewAs the only book to address ASP.NET 3.5, AJAX, and IIS 7 security from the developer's point of view, this book begins with a look at the new features of IIS 7.0 and then goes on to focus on IIS 7.0 and ASP.NET 3.5 integration. You'll walk through a detailed explanation of the request life cycle for an ASP.NET application running on IIS 7.0 under the classic mode, from the moment it enters IIS 7.0 until ASP.NET generates a corresponding response.

Want to learn more information about Professional ASP.NET 3.5 Security, Membership, and Role Management with C# and VB (Wrox Programmer to Programmer)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

The Shellcoder's Handbook: Discovering and Exploiting Security Holes Review

The Shellcoder's Handbook: Discovering and Exploiting Security Holes
Average Reviews:

(More customer reviews)
Are you looking to buy The Shellcoder's Handbook: Discovering and Exploiting Security Holes? Here is the right place to find the great deals. we can offer discounts of up to 90% on The Shellcoder's Handbook: Discovering and Exploiting Security Holes. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

The Shellcoder's Handbook: Discovering and Exploiting Security Holes ReviewBasically this book is very good. It goes through the basic to some advanced techniques. The author tried to cover a lot of Operating Systems, from x86 (Windows and Linux) to Mac, Sparks and Cisco, so you should be aware whether this is your focus or not, if not you will take advantage of a few chapters of the book. In my case, I was interested just in x86 shellcode programming, so I should paid half of the price (just kidding). But essentially this book is very good, you should have it.The Shellcoder's Handbook: Discovering and Exploiting Security Holes Overview
This much-anticipated revision, written by the ultimate group of top security experts in the world, features 40 percent new content on how to find security holes in any operating system or application
New material addresses the many new exploitation techniques that have been discovered since the first edition, including attacking "unbreakable" software packages such as McAfee's Entercept, Mac OS X, XP, Office 2003, and Vista
Also features the first-ever published information on exploiting Cisco's IOS, with content that has never before been explored
The companion Web site features downloadable code files


Want to learn more information about The Shellcoder's Handbook: Discovering and Exploiting Security Holes?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code Review

Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code
Average Reviews:

(More customer reviews)
Are you looking to buy Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code? Here is the right place to find the great deals. we can offer discounts of up to 90% on Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code ReviewI have just received this book and have not yet worked my way through all the chapters, but I have reviewed the contents and tool DVD. I teach college classes on Network and Computer forensics from a survey level through a hard-core programming level. I have likely purchased or been sent most of the books in this area, and this book does stand out for the following reasons.
1. The material is up-to-date. Tools and malware resources change on an almost daily basis and you need to get books that reflect current resources and best practices. This book does a very good job covering the current tools and resources. It provides the web addresses for the various tools and resources discussed in each chapter. It also refers to current research, articles, and conference material in the areas covered in the chapters.
2. The topics covered are comprehensive. The book includes topics on anonymizing (the first chapter), classifying malware, shellcode, DLL code injection, debugging, how to safely run malware in a virtual environment, dumping memory and memory forensics, debugging kernel code, etc. The topics are collected into 18 chapters and are very complete.
3. The focus of this book is performing analysis of malware (which includes a wide variety of exploit types) and creating/using the tools to perform this analysis. Numerous examples are given showing how the analysis can be done, and some background information is presented as needed.
4. The book assumes the reader has brains. Too many "Computer Forensics" books are a waste of time for someone that already has a background in programming, networking, etc. They (the other Forensics books) often start their discussion of Network Forensics with a definition of what a network is ("A network sends packets between computers..."). Give me a break. This book assumes the reader already has a level of knowledge that is appropriate to anyone really working in this field. However, the authors do a good job explaining what needs to be explained in the course of presenting the topics. They don't talk down to the reader.
5. The book has a wealth of examples. Each chapter presents the topics by showing examples as well as showing how to get and install the necessary tools.
6. The book balances using pre-written tools with create-your-own tools. The latter include scripts in Python and programs in C/C++. The authors indicate where to get various relevant libraries which can be used to create or customize tools. This book is not just a collection of tools, but shows how to use the tools, analysis techniques, etc.
7. The book is very reasonably priced for the quality of content and the extra DVD. The price from Amazon is under $40 and the retail price is about $60. However, even at $60 this book is a bargain. Even if you just used the web addresses for the lists of tools presented in each chapter, the amount of time would take to locate and document the huge number of forensics/hacking tools presented in this book, is worth more than the book's price.
8. The book presents a huge amount of material. Almost every page is crammed with information and examples. Frankly, this book presents more information in one chapter than most other books do in their entirety, and this book has 18 chapters. The chapters are written so they are independent of each other and you can select the chapter you want to work through without reading previous chapters.
9. The tool focus is open-source and platform independent. The authors stay with open-source tools and try to reference tools that can run on both Linux and Windows. However, they also use the best tools available for a specific task, even if the tool only runs under Linux or only under Windows.
Reader Background:
There are enough varied topics in this book that readers with different levels of knowledge can benefit. The authors assume the reader has a background in basic networking, understands operating systems (both Windows and Unix), understands programming (Python, C/C++, Assembly), and understand processor basics (registers, the stack, etc). However, these assumptions are not barriers to getting something out of this book. Beginners will find the book too difficult, but would profit by just downloading the various tools referenced in the chapters.
Bottom line:
* If you are doing forensic analysis on Malware you should purchase this book (for the chapters on debugging, memory forensics, and malware forensics)
* If you are working in the network/computer security area you should purchase this book (for the chapters on setting up a malware lab, classifying malware, and setting up a malware sandbox)
* If you are interested in the programming aspects of malware you should purchase this book (for the chapters on DLLs and debugging malware code and on code injection)
* If (and I hesitate to include this) you want to be a hacker you should purchase this book and read the entire thing.
Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code OverviewA computer forensics "how-to" for fighting malicious code and analyzing incidents
With our ever-increasing reliance on computers comes an ever-growing risk of malware. Security professionals will find plenty of solutions in this book to the problems posed by viruses, Trojan horses, worms, spyware, rootkits, adware, and other invasive software. Written by well-known malware experts, this guide reveals solutions to numerous problems and includes a DVD of custom programs and tools that illustrate the concepts, enhancing your skills.
Security professionals face a constant battle against malicious software; this practical manual will improve your analytical capabilities and provide dozens of valuable and innovative solutions
Covers classifying malware, packing and unpacking, dynamic malware analysis, decoding and decrypting, rootkit detection, memory forensics, open source malware research, and much more
Includes generous amounts of source code in C, Python, and Perl to extend your favorite tools or build new ones, and custom programs on the DVD to demonstrate the solutions

Malware Analyst's Cookbook is indispensible to IT security administrators, incident responders, forensic analysts, and malware researchers.

Want to learn more information about Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Database Systems: Design, Implementation, and Management Review

Database Systems: Design, Implementation, and Management
Average Reviews:

(More customer reviews)
Are you looking to buy Database Systems: Design, Implementation, and Management? Here is the right place to find the great deals. we can offer discounts of up to 90% on Database Systems: Design, Implementation, and Management. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Database Systems: Design, Implementation, and Management ReviewI'm a technical person but have very little DB experience and purchased the book because I had to for a college class. I feel the book was simply OK. Some points were made well others I had to read several times. Over all the explanations were not as concise as I would like but in all fairness DB concepts are hard to explain. The overall layout was good however I think there should have been more attention during the intro to familiarize the reader with DB's and the related concepts before delving in to the details of each phase of DB creation.
My only real gripe is that a new revision is published every year and the previous version of the $100 + dollar book becomes worthless. To save money I bought the previous version and found all the material I needed. However for the final exam the instructor of the online class gave us page numbers to use as reference so I was forced to buy the latest version which was the same book with a few new references...
If you are buying this book for reference or if you are buying this because you are taking a face to face class I recommend that you buy the previous version required by the instructor at a greatly reduced cost. You may be able to do this w/ an online class if the professor (or classmates) are flexible and willing to help reconcile the different page numbers.
Database Systems: Design, Implementation, and Management OverviewDatabase Systems: Design, Implementation, and Management, Eighth Edition, a market-leader for database texts, gives readers a solid foundation in practical database design and implementation. The book provides in-depth coverage of database design, demonstrating that the key to successful database implementation is in proper design of databases to fit within a larger strategic view of the data environment. Updates for the eighth edition include additional Unified Modeling Language coverage, expanded coverage of SQL Server functions, all-new business intelligence coverage, and added coverage of data security. With a strong hands-on component that includes real-world examples and exercises, this book will help students develop database design skills that have valuable and meaningful application in the real world.

Want to learn more information about Database Systems: Design, Implementation, and Management?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Essential PHP Security Review

Essential PHP Security
Average Reviews:

(More customer reviews)
Are you looking to buy Essential PHP Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on Essential PHP Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Essential PHP Security Review
You would think that with all of the books being published recently about PHP that everyone and his mother is writing PHP code. This may be true, but even if it is not, it is certain that many people and businesses are using PHP code, in concert with other applications like MySQL, to produce dynamic web sites. This is all well and good because PHP is a high-quality coding language especially well-suited to web applications. It is also open-source, meaning well-supported by a community of coders and developers and cost-free. The one problem is that, like all coding languages, poorly designed or written PHP applications can be security risks potentially allowing Internet miscreants to cause damage to web servers, hosts, and users. It appears to be the case that there are many, many instances of insecure PHP code in use, hence, the value in a targeted book on PHP security, like "Essential PHP Security", by Chris Shiflett.
The author is an internationally-known and accomplished expert on PHP security. He is the founder of the PHP Security Consortium, a group of volunteers who help educate the PHP community, and a well-known contributor to the PHP-general mail digest. The book is designed to provide security information and guidelines and explain the most common types of attacks and how to prevent or repel them.
"Essential PHP Security" is a slight volume of only 109 pages, including index. Shiflett wastes no time and immediately jumps into his topic, starting with his opinion on the use of the PHP concept of "register globals", a configuration setting which he recommends against using in favor of "superglobal arrays". He next turns to how to configure your web server setup to properly deal with error reporting, both for the developer's use and to prevent providing clues to any interloper trying to illegally access your site.
The balance of Chapter 1 itemizes general principles of Internet security: Defense in Depth - redundantly using more than one technique to secure your site; Least Privileges - writing code to minimize access to the least needed for any particular user's needs; Simple is Beautiful - the writing of clear, simple code, to make troubleshooting and auditing easier; and Minimize Exposure - taking steps to design and implement programs to eliminate or at least minimize display of sensitive data or code - don't even store credit card information unless absolutely necessary, he suggests.
Next, comes "Best Practices" - balancing risk vs. usability, keeping track of data, filtering of all input, escaping output, and in all cases, distinguishing between filtered and tainted data. These principles and practices are illustrated with short code snippets comparing insecure vs. more secure code.
The next seven chapters deal with specific elements of a website, the types of attacks that can occur with each, and tips and suggestions on how to deal with these attacks. These elements include vulnerabilities in forms and URLs, databases and SQL, sessions and cookies, PHP "include" files, files and commands, authentication and authorization, and shared hosting.
The author credibly describes by examples the types of attacks against forms and URLs - cross-site scripting, cross site request forgeries, spoofing of forms, and insecure Raw HTTP requests. Authentication attacks include dictionary attacks, password sniffing, replay attacks, and cookie stealing. For each, he briefly describes how the attacks work, shows examples of insecure code, and provides examples of secure code.
For each of the elements dealt with, the author follows the same model: describe briefly the types of attacks against each element, show conventionally-used insecure code, and show how to eliminate the insecure parts of the code. Most of the security defenses entail filtering data from outside sources, especially form input, email, and XML documents from other web applications. Other defense techniques include using SSL for encrypted data transmissions, strengthening identification methods, hard-coding file paths, and using token techniques in addition to PHP encryption functions. Interestingly, Schiflett believes it is impossible to achieve a high level of security in a shared hosting situation. He provides suggestions on what security measures will help the most.
What is most useful about this book is the aggregation in one place of descriptions of all of these security attacks, and vulnerabilities in PHP code, along with suggestions on dealing with them. The organization of the material is good, however. I believe the author falls short in his code examples. There appears to be a disconnect between the descriptive text (which is clear enough) and the examples, which are not, at least to me, a novice in PHP. I could not readily follow the detailed code segments, although I could understand in principle what was going on.
Some of the code segments were barely explained and some were inadequately explained. The concepts of the attacking techniques were understandable, but the detailed implementations were not. There are a small handful of illustrations, but I found them too simplistic and inadequate. To be fair, this may be a failure of the reviewer. More experienced PHP folks may not complain about the presentations. For them, this book gives them what they need to know about handling the security aspects of their applications, but my guess is that it is the less accomplished coders who need the most help (although those same people are probably writing the types of applications and sites least likely to be targeted by miscreants.)
There are three short appendices presenting suggestions on how to configure a PHP installation to minimize weaknesses, suggestions about avoiding certain powerful PHP functions, especially system commands, to minimize risk, and a short segment on cryptography features in PHP.Essential PHP Security Overview
Being highly flexible in building dynamic, database-driven web applications makes the PHP programming language one of the most popular web development tools in use today. It also works beautifully with other open source tools, such as the MySQL database and the Apache web server. However, as more web sites are developed in PHP, they become targets for malicious attackers, and developers need to prepare for the attacks.

Security is an issue that demands attention, given the growing frequency of attacks on web sites. Essential PHP Security explains the most common types of attacks and how to write code that isn't susceptible to them. By examining specific attacks and the techniques used to protect against them, you will have a deeper understanding and appreciation of the safeguards you are about to learn in this book.

In the much-needed (and highly-requested) Essential PHP Security, each chapter covers an aspect of a web application (such as form processing, database programming, session management, and authentication).Chapters describe potential attacks with examples and then explain techniques to help you prevent those attacks.

Topics covered include:

Preventing cross-site scripting (XSS) vulnerabilities
Protecting against SQL injection attacks
Complicating session hijacking attempts

You are in good hands with author Chris Shiflett, an internationally-recognized expert in the field of PHP security. Shiflett is also the founder and President of Brain Bulb, a PHP consultancy that offers a variety of services to clients around the world.


Want to learn more information about Essential PHP Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Business in the Cloud: What Every Business Needs to Know About Cloud Computing Review

Business in the Cloud: What Every Business Needs to Know About Cloud Computing
Average Reviews:

(More customer reviews)
Are you looking to buy Business in the Cloud: What Every Business Needs to Know About Cloud Computing? Here is the right place to find the great deals. we can offer discounts of up to 90% on Business in the Cloud: What Every Business Needs to Know About Cloud Computing. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Business in the Cloud: What Every Business Needs to Know About Cloud Computing Review"Business in the Cloud...Computing" is an excellent,clear & easy to understand guide designed for a broad audience of business & technical leaders to balance the needs for a comprehensive framework to understand Cloud Computing and its Business Impact with the need for a simple & direct discussion of the key points without delving so deeply into specific details!
"Business in the Cloud...Computing" is divided into three parts. The first two chapters provide a basis for understanding current organizational & economic changes / realities! The next six chapters define Cloud Technology,strategies,tactics and lessons learned-to-date! Chapter six - The Transition from Managing Technology to Managing Business Processes is very direct & relevant! The last two chapters expand upon the information in previous chapters to the Business Impact of Cloud Computing & Global Implications of the Cloud!
"Business in the Cloud...Computing" is designed to clarify the often-vague concept of Cloud Computing to not only understand it but to put it to work!...Please review & use...All Cloud Innovators & Builders...Michael.Business in the Cloud: What Every Business Needs to Know About Cloud ComputingBusiness in the Cloud: What Every Business Needs to Know About Cloud Computing Overview
A close look at cloud computing's transformational role in business

Covering cloud computing from what the business leader needs to know, this book describes how IT can nimbly ramp up revenue initiatives, positively impact business operations and costs, and how this allows business leaders to shed worry about technology so they can focus on their business. It also reveals the cloud's effect on corporate organization structures, the evolution of traditional IT in the global economy, potential benefits and risks of cloud models and most importantly, how the IT function is being rethought by companies today who are making room for the coming tidal wave that is cloud computing.
Why IT and business thinking must change to capture the full potential of cloud computing
Topics including emerging cloud solutions, data security, service reliability, the new role of IT and new business organization structures
Other titles by Hugos include: Business Agility: Sustainable Prosperity in a Relentlessly Competitive World and Essentials of Supply Chain Management, 2nd Edition

Practical and timely, this book reveals why it's worth every company's time and effort to exploit cloud computing's potential for their business's survival and success.

Want to learn more information about Business in the Cloud: What Every Business Needs to Know About Cloud Computing?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

IBM WebSphere DataPower SOA Appliance Handbook Review

IBM WebSphere DataPower SOA Appliance Handbook
Average Reviews:

(More customer reviews)
Are you looking to buy IBM WebSphere DataPower SOA Appliance Handbook? Here is the right place to find the great deals. we can offer discounts of up to 90% on IBM WebSphere DataPower SOA Appliance Handbook. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

IBM WebSphere DataPower SOA Appliance Handbook ReviewI purchased this book at Amazon to use as a reference for a DataPower implementation and to supplement basic DataPower training. It has been very helpful as a reference and has an easy-to-read style (for a technical book) that has made it possible to read it from cover to cover. The book provides numerous examples with screen snapshots. Interestingly, the examples typically are associated with a book purchase service :). Our project is using DataPower systems for web services security, service virtualization, routing, web service enabling MQ®, logging and complex XML transformation. These topics are covered extensively in the book. I strongly recommend this book if you are launching a DataPower project.IBM WebSphere DataPower SOA Appliance Handbook OverviewExpert Guide to Deploying, Using, and Managing DataPower SOA AppliancesIBM® WebSphere® DataPower® appliances can simplify SOA deployment, strengthen SOA security, enhance SOA performance, and dramatically improve SOA return on investment. In this book, a team of IBM's leading experts show how to make the most of DataPower SOA appliances in any IT environment.The authors present IBM DataPower information and insights that are available nowhere else. Writing for working architects, administrators, and security specialists, they draw extensively on their deep experience helping IBM customers use DataPower technologies to solve challenging system integration problems.IBM WebSphere DataPower SOA Appliance Handbook begins by introducing the rationale for SOA appliances and explaining how DataPower appliances work from network, security, and Enterprise Service Bus perspectives. Next, the authors walk through DataPower installation and configuration; then they present deep detail on DataPower's role and use as a network device.Using many real-world examples, the authors systematically introduce the services available on DataPower devices, especially the "big three": XML Firewall, Web Service Proxy, and Multi-Protocol Gateway. They also present thorough and practical guidance on day-to-day DataPower management, including, monitoring, configuration build and deploy techniques.Coverage includes• Configuring DataPower's network interfaces for common scenarios• Implementing DataPower deployment patterns for security gateway, ESB, and Web service management applications• Proxying Web applications with DataPower• Systematically addressing the security vulnerabilities associated with Web services and XML• Integrating security with WebSphere Application Server• Mastering DataPower XSLT custom programming• Troubleshooting using both built-in and external tools

Want to learn more information about IBM WebSphere DataPower SOA Appliance Handbook?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition Review

Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition
Average Reviews:

(More customer reviews)
Are you looking to buy Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition ReviewHardly a week goes by that CNN does not report a high-profile Web site being defiled or an e-commerce site being penetrated. While most people know why these incidents occurred, Hacking Exposed explains how they occurred and, more important, how to prevent them from occurring.
The cover of Hacking Exposed announces that "Network security is Y2K without the deadline." That alarmist statement, however, is the only hype in the book. The work is packed with real-world examples and links to tools needed to assess the security of any type of client/server and Web system. As they detail the myriad vulnerabilities in different types of systems, the authors provide countermeasures for each of them.
Well organized, the book progresses in an orderly fashion. It methodically goes through the process of exploiting a target to penetrate a system--from identification and enumeration to actual penetration. The authors provide detailed instructions and explanations for many security features and flaws in Unix, Linux, Windows, NetWare, routers, firewalls, and more. Topics covered include state-of-the-art computer and network penetration, as viewed by both the attacker and the defender; remote system identification; vulnerability identification; war dialers; firewall circumvention; and denial-of-service attacks. An appendix explores the security characteristics of Windows 2000.
Some may argue that books such as this one only serve to motivate and educate hackers. The truth is that hackers are already aware of the book's contents. This book is designed for system administrators and managers who need to know their systems' risks and vulnerabilities and how to address them. When they are done with this book, system administrators and managers will be familiar with such critical topics as back channels, port redirection, banner grabbing, and buffer overflows. Hacking Exposed is a must-read for anyone who wants to know what is really happening on their network....Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition Overview

Want to learn more information about Hacking Exposed: Network Security Secrets and Solutions, Sixth Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

IT Auditing Using Controls to Protect Information Assets, 2nd Edition Review

IT Auditing Using Controls to Protect Information Assets, 2nd Edition
Average Reviews:

(More customer reviews)
Are you looking to buy IT Auditing Using Controls to Protect Information Assets, 2nd Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on IT Auditing Using Controls to Protect Information Assets, 2nd Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

IT Auditing Using Controls to Protect Information Assets, 2nd Edition ReviewI have no experience with auditing in the formal sense described by IT Auditing. I am familiar with the technical aspects of host and network security, but I wanted to know more about the goals and views of those who audit enterprises from a security standpoint. IT Auditing succeeds when it discusses the profession of auditing but I found some of the technical details lacking. Therefore, I recommend focusing on chapters 1-3 and 12-15, while using the technical chapters as indicators for outside research.
Chapter 1 makes clear that IT Auditing is written for internal audit teams. The author argues that involvement is better than "independence," since adhering to the later business approach is a recipe for outsourcing the audit function. I liked the beginning and end of IT Auditing because they emphasized how internal audit teams should work with business IT functions. These chapters answered questions on whether or not audit should review and comment upon projects before completion (yes) and related "soft" topics.
The middle of IT Auditing concentrates on how to audit data centers, infrastructure, operating systems, Web servers, databases, applications, and wireless/mobile devices. I found these chapters less appealing. When I read "it's much more common to find SNMP Version 2 in most corporate environment" (sic, p 121) or see mention of "Universal Data Ports (UDPs)" (sic, p 172) I question the validity of the technical recommendations. Other examples include equating NAT with proxies (p 117) and the statement that "network vulnerability scanning... is probably the most important type of security discovery or monitoring in most environments" I begin to understand the horror stories I hear from some who are audited.
When it came to understanding the audit mindset, I think IT Auditing really helped me. It seems auditors are far more likely to be interested in reviewing paperwork than really assessing effectiveness of security controls. Repeatedly I read statements like "evaluate the effectiveness of the security personnel function" by looking at documentation. In a few areas auditors seem to understand the value of real tests, e.g., trying to restore a backup rather than reviewing logs saying backups were completed. This focus on validating paperwork over operational activity is the single biggest problem with audits. It's clear a "system" could pass all its audit checks with flying colors while still being completely compromised. (Yes, p 201-2 mentions Chkrootkit, but that program is only effective in limited scenarios.) Audit is configuration and paperwork validation, not system integrity assessment.
I recommend reading IT Auditing if you want to get a better idea of how your auditors think and what they want to inspect. If you're an auditor who wants authoritative technical guidance you will probably learn more from dedicated system and network hardening books designed for administrators. IT Auditing's checklists can at least put you in the ballpark, however.IT Auditing Using Controls to Protect Information Assets, 2nd Edition Overview
Secure Your Systems Using the Latest IT Auditing Techniques
Fully updated to cover leading-edge tools and technologies, IT Auditing: Using Controls to Protect Information Assets, Second Edition, explains, step by step, how to implement a successful, enterprise-wide IT audit program. New chapters on auditing cloud computing, outsourced operations, virtualization, and storage are included. This comprehensive guide describes how to assemble an effective IT audit team and maximize the value of the IT audit function. In-depth details on performing specific audits are accompanied by real-world examples, ready-to-use checklists, and valuable templates. Standards, frameworks, regulations, and risk management techniques are also covered in this definitive resource.

Build and maintain an internal IT audit function with maximum effectiveness and value
Audit entity-level controls, data centers, and disaster recovery
Examine switches, routers, and firewalls
Evaluate Windows, UNIX, and Linux operating systems
Audit Web servers and applications
Analyze databases and storage solutions
Assess WLAN and mobile devices
Audit virtualized environments
Evaluate risks associated with cloud computing and outsourced operations
Drill down into applications to find potential control weaknesses
Use standards and frameworks, such as COBIT, ITIL, and ISO
Understand regulations, including Sarbanes-Oxley, HIPAA, and PCI
Implement proven risk management practices


Want to learn more information about IT Auditing Using Controls to Protect Information Assets, 2nd Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Professional Penetration Testing: Creating and Operating a Formal Hacking Lab Review

Professional Penetration Testing: Creating and Operating a Formal Hacking Lab
Average Reviews:

(More customer reviews)
Are you looking to buy Professional Penetration Testing: Creating and Operating a Formal Hacking Lab? Here is the right place to find the great deals. we can offer discounts of up to 90% on Professional Penetration Testing: Creating and Operating a Formal Hacking Lab. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Professional Penetration Testing: Creating and Operating a Formal Hacking Lab ReviewI had fairly high hopes for Professional Penetration Testing (PPT). The book looks very well organized, and it is published in the new Syngress style that is a big improvement over previous years. Unfortunately, PPT should be called "Professional Pen Testing Project Management." The vast majority of this book is about non-technical aspects of pen testing, with the remainder being the briefest overview of a few tools and techniques. You might find this book useful if you either 1) know nothing about the field or 2) are a pen testing project manager who wants to better understand how to manage projects. Those looking for technical content would clearly enjoy a book like Professional Pen Testing for Web Applications by Andres Andreu, even though that book is 3 years older and focused on Web apps.
PPT offers 18 chapters, with 12 chapters on project management and non-technical issues, and 6 ostensibly covering technical issues. The technical material is limited to the basics of conducting reconnaissance, running Nmap, Nessus, CORE IMPACT, Ettercap, Aircrack-ng, Netcat for "maintaining access," SSH for an "encrypted tunnel," and trivial file and script changes to "cover tracks." Seriously. I'm sure some review readers are saying "sometimes it's just that easy." That's true, but we don't need a 528 page book with an outrageous price tag to read about these well-known methods. If your experience with pen testing is limited to this book, take a look at Andres Andreu's title to see the sort of material you should expect in a book on pen testing.
I didn't find the project management parts all that helpful, either. Some of it just repeats material published in various guides like the Open Source Security Testing Methodology Manual. Other sections repeat certification descriptions found on vendor Web sites. It is clear the author really cares about project management, so maybe he should have just written a book on project management for security managers?
I gave the book three stars because I didn't find the book to be technically or managerially incorrect. (If that had been the case, I would have rated it two stars.) If you want much better coverage on technical matters not found in Andreu's book, try the core Hacking Exposed titles. They address the same topics that PPT barely introduces.Professional Penetration Testing: Creating and Operating a Formal Hacking Lab Overview

Want to learn more information about Professional Penetration Testing: Creating and Operating a Formal Hacking Lab?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Cloud Application Architectures: Building Applications and Infrastructure in the Cloud (Theory in Practice (O'Reilly)) Review

Cloud Application Architectures: Building Applications and Infrastructure in the Cloud (Theory in Practice (O'Reilly))
Average Reviews:

(More customer reviews)
Are you looking to buy Cloud Application Architectures: Building Applications and Infrastructure in the Cloud (Theory in Practice (O'Reilly))? Here is the right place to find the great deals. we can offer discounts of up to 90% on Cloud Application Architectures: Building Applications and Infrastructure in the Cloud (Theory in Practice (O'Reilly)). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Cloud Application Architectures: Building Applications and Infrastructure in the Cloud (Theory in Practice (O'Reilly)) ReviewAll it talks about is Amazon's EC2, S3, MapReduce. It does not talk about "Application Architecture". It does not have ideas about how to break up traditional programs into MapReduce paradigm. It should be called Cloud Operations Architecture. If it was named by that title, I'd give it 5 stars. The book itself is not bad, but it will get obsolete very quickly due to its specificity to Amazon.
subtitle should be :Building Applications and Infrastructure in Amazon CloudCloud Application Architectures: Building Applications and Infrastructure in the Cloud (Theory in Practice (O'Reilly)) Overview
If you're involved in planning IT infrastructure as a network or system architect, system administrator, or developer, this book will help you adapt your skills to work with these highly scalable, highly redundant infrastructure services. While analysts hotly debate the advantages and risks of cloud computing, IT staff and programmers are left to determine whether and how to put their applications into these virtualized services. Cloud Application Architectures provides answers -- and critical guidance -- on issues of cost, availability, performance, scaling, privacy, and security. With Cloud Application Architectures, you will:



Understand the differences between traditional deployment and cloud computing
Determine whether moving existing applications to the cloud makes technical and business sense
Analyze and compare the long-term costs of cloud services, traditional hosting, and owning dedicated servers
Learn how to build a transactional web application for the cloud or migrate one to it
Understand how the cloud helps you better prepare for disaster recovery
Change your perspective on application scaling

To provide realistic examples of the book's principles in action, the author delves into some of the choices and operations available on Amazon Web Services, and includes high-level summaries of several of the other services available on the market today.Cloud Application Architectures provides best practices that apply to every available cloud service. Learn how to make the transition to the cloud and prepare your web applications to succeed.


Want to learn more information about Cloud Application Architectures: Building Applications and Infrastructure in the Cloud (Theory in Practice (O'Reilly))?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

BackTrack 4: Assuring Security by Penetration Testing Review

BackTrack 4: Assuring Security by Penetration Testing
Average Reviews:

(More customer reviews)
Are you looking to buy BackTrack 4: Assuring Security by Penetration Testing? Here is the right place to find the great deals. we can offer discounts of up to 90% on BackTrack 4: Assuring Security by Penetration Testing. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

BackTrack 4: Assuring Security by Penetration Testing ReviewThis book is not just about learning a bunch of command line tools for p0wning a few poorly-maintained systems. In this book, the authors do a good job exposing the reader to the many facets of pen testing, and present the readers with the opportunity to try a few new things along the way, including virtualization, Linux, and BackTrack itself.
The authors introduce the idea that pen testing is not about randomly using a collection of tools to plink around a network. Instead, a structured, procedural methodology should be used to achieve timely, thorough, and reportable results. The author's also provide a detailed description of a security testing methodology to be used with BackTrack itself.
Each step in this methodology represents an element in the penetration testing life cycle management performed for each customer. The authors describe how this organized progression allows pen testers to determine their course of action, plan for needed resources, and not waste time and resources by duplicating effort. My only complaint is that this section is too small, and deserves expanding using actual case studies.
A considerable number of pen testing tools for each step in the methodology are covered with examples and instruction. Popular tools covered include Metasploit (Meterpreter), Maltego, NMap, NetXpose, and Nessus. Tools for exploiting (uh, testing) Web servers, databases, applications, and even Cisco devices are also covered.
I was very happy to see a chapter on Social Engineering. Experienced pen testers often remark that the most penetrable area of any system are the people who use and control it. The authors provide a detailed description of the psychology, tactics, and objectives of social engineering and how it is used to penetrate the "fleshy" parts of information systems.
This book is intended to educate both novice and experienced pen testers on how to successfully use BackTrack 4. I am sure not every professional pen testing will agree with everything in this book, as it represents the personal experience of only a few people in the profession. However, novices will find a tremendous amount of hands-on practice and enlightening information related to the pen testing profession in clear and readable instructions. Pros should a few things about becoming an even more efficient and versatile pen tester too.BackTrack 4: Assuring Security by Penetration Testing OverviewWritten as an interactive tutorial, this book covers the core of BackTrack with real-world examples and step-by-step instructions to provide professional guidelines and recommendations to you. The book is designed in a simple and intuitive manner, which allows you to explore the whole BackTrack testing process or study parts of it individually. If you are an IT security professional or network administrator who has a basic knowledge of Unix/Linux operating systems including awareness of information security factors, and you want to use BackTrack for penetration testing, then this book is for you.

Want to learn more information about BackTrack 4: Assuring Security by Penetration Testing?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Web Applications (Hacking Exposed) Review

Web Applications (Hacking Exposed)
Average Reviews:

(More customer reviews)
Are you looking to buy Web Applications (Hacking Exposed)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Web Applications (Hacking Exposed). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Web Applications (Hacking Exposed) ReviewI just finished reading Hacking Exposed Web Apps and was coming back to Amazon to fwd the recommendation to a friend who is a CSO at a Fortune 500 firm when I stumbled upon the review from hermie. I have to say that I disagree completely with hermie's assessment, and felt compelled enough to say so in print! First of all, the book does cover a number of web platforms besides IIS -- it's the only one I've seen that talks about web services in any detail (SOAP, UDDI, XML, etc.), and it also devotes entire chapters to both web app management and web client hacking as well (very salient but often overlooked topics in other books). Main author Scambray may be a Windows security expert, but the non-Windows expertise is very visible in the appendix on libwhisker and the chapters on surveying the app, attacking session state, and input validation, etc. This also calls into question the criticisms by hermie of the specific detail versus the depiction of broad concepts -- if you are after ancient security concepts, then you plainly shouldn't be reading the Hacking Exposed series! That's the point of each book in the series -- use fresh, relevant technical details on how to hack to illustrate cutting-edge *concepts* in computer and Internet security. I think hermie really missed the boat here. Finally, the straw that broke the camels back for me was the comparison to "Web Hacking" by McClure. McClure is an executive now running his own start-up, and the knock that I've heard on this book is that it is really non-technical and out-of-date in sections. McClure brought in strong contributors to drive the details, but apparently couldn't glue the right pieces together to make this book competitive. I have a borrowed copy on my shelf, but frankly could not get past the first three or so chapters. Sigh -- I guess that's the breaks when anyone can post their thoughts here in the review section :)Web Applications (Hacking Exposed) Overview

Want to learn more information about Web Applications (Hacking Exposed)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Innocent Code: A Security Wake-Up Call for Web Programmers Review

Innocent Code: A Security Wake-Up Call for Web Programmers
Average Reviews:

(More customer reviews)
Are you looking to buy Innocent Code: A Security Wake-Up Call for Web Programmers? Here is the right place to find the great deals. we can offer discounts of up to 90% on Innocent Code: A Security Wake-Up Call for Web Programmers. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Innocent Code: A Security Wake-Up Call for Web Programmers ReviewThis book is similar in many respects to Web Hacking: Attacks and Defense (ISBN 0201761769). While that book was aimed at security professionals who needed to understand the exposures and vulnerabilities in web systems that were commonly exploited by the bad guys and gals, this book is aimed more at developers.
Like for former book, this one systematically covers exposures and vulnerabilities, and provides remedies at the code level. What sets this book apart is every component of a modern web site, from web server to backend database is covered, problem areas from a developer's perspective are highlighted, and solutions for resolving the problem areas given. I like this book because developers, from casual hobbyists to professionals, will easily grasp the information. More importantly, the material is not insultingly simple to experienced developers, nor is it over the head of less experienced ones.
Another reason I like this book is in systematically uncovering exposures the QA team can also use this book as a sourcebook for developing a baseline set of test cases that will catch security-related problems during acceptance, functional qualification, or regression test cycles.
In my opinion not only should web developers (including DBAs) and QA professionals read this book, but it should also be adopted by development organizations and projects as a part of coding standards.Innocent Code: A Security Wake-Up Call for Web Programmers Overview
This concise and practical book shows where code vulnerabilities lie-without delving into the specifics of each system architecture, programming or scripting language, or application-and how best to fix them
Based on real-world situations taken from the author's experiences of tracking coding mistakes at major financial institutions
Covers SQL injection attacks, cross-site scripting, data manipulation in order to bypass authorization, and other attacks that work because of missing pieces of code
Shows developers how to change their mindset from Web site construction to Web site destruction in order to find dangerous code


Want to learn more information about Innocent Code: A Security Wake-Up Call for Web Programmers?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

MODx Web Development - Second Edition Review

MODx Web Development - Second Edition
Average Reviews:

(More customer reviews)
Are you looking to buy MODx Web Development - Second Edition? Here is the right place to find the great deals. we can offer discounts of up to 90% on MODx Web Development - Second Edition. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

MODx Web Development - Second Edition ReviewI reviewed the first version of this. It was a very positive review, because I felt that it filled a need, that of providing guidance to the new MODx user. It did this admirably well. Anyone who regularly uses open-source content management systems knows that much of the info is scattered in forums, individual blog posts, random other places, and sometimes even in official documentation. To me, it's useful to have much of this consolidated into one place.
I do agree with reviewers that said that it's not for gurus. They would not find much new info with either book. It seems to me that systems don't get guru books until they have a critical mass of popularity, and as much as I like MODx, I don't think it's quite there yet.
I have to scold the publisher and author on the title of this book, which is remarkably misguided. MODx 2 is Revolution (aka Revo), a completely new release, which has been out for awhile now. Accordingly, I was eager to see if there would be substantial Revo coverage. There isn't. They just have an extra chapter giving a quick overview of the Revo concepts. The entire rest of the book is devoted to MODx 1, aka Evolution or Evo.
I'm very puzzled by this. I can only think that maybe there was a publishing deadline, and Revo was not officially released at that date, so someone decided to put it out there with little Revo coverage. I think this is a mistake, both conceptually and commercially. In any case, if you want a book on Revo, you'll have to wait.
That said, Evo, in my opinion, will be operant for quite some time to come. It's still more stable than Revo, simply by virtue of its having been in use so long.
So if you're new to MODx, and want to learn the in's and out's of MODx 1, aka Evo, this book will be useful, and will also give you a very brief overview of Revo. If you already have the first book, I would pass on this.MODx Web Development - Second Edition OverviewThis book is an example-driven tutorial, which will take you from the installation of MODx through to configuration, customization, and deployment. Step-by-step instructions will enable you to build a fully-functional, feature-rich website quickly and without the knowledge of any programming language. This book is ideal for newcomers to MODx. Both beginners and experienced web developers will benefit from this comprehensive guide to MODx. No knowledge of PHP programming or any templating language is needed, but the more advanced chapters towards the end of the book will allow more confident developers to extend their applications even further by creating their own snippets.

Want to learn more information about MODx Web Development - Second Edition?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Secure Java: For Web Application Development Review

Secure Java: For Web Application Development
Average Reviews:

(More customer reviews)
Are you looking to buy Secure Java: For Web Application Development? Here is the right place to find the great deals. we can offer discounts of up to 90% on Secure Java: For Web Application Development. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Secure Java: For Web Application Development ReviewI bought this book with lot of expectations but this book FALLS SHORT on providing Java security fundamentals and design and implementation practices. The introductory chapters is more like high-level security topics that has nothing to do with Java security. There is NO coverage on security related to Java EE Web applications and Web services.
The book briefly touches upon Java Security on Chapters 8 and 9. If you are looking for Java security fundamentals, Java EE Web applications and Web Services security... sorry note this book will be nothing but a huge disappointment.Secure Java: For Web Application Development OverviewMost security books on Java focus on cryptography and access control, but exclude key aspects such as coding practices, logging, and web application risk assessment. Encapsulating security requirements for web development with the Java programming platform, Secure Java: For Web Application Development covers secure programming, risk assessment, and threat modeling-explaining how to integrate these practices into a secure software development life cycle. From the risk assessment phase to the proof of concept phase, the book details a secure web application development process. The authors provide in-depth implementation guidance and best practices for access control, cryptography, logging, secure coding, and authentication and authorization in web application development. Discussing the latest application exploits and vulnerabilities, they examine various options and protection mechanisms for securing web applications against these multifarious threats. The book is organized into four sections:Provides a clear view of the growing footprint of web applications Explores the foundations of secure web application development and the risk management processDelves into tactical web application security development with Java EEDeals extensively with security testing of web applicationsThis complete reference includes a case study of an e-commerce company facing web application security challenges, as well as specific techniques for testing the security of web applications. Highlighting state-of-the-art tools for web application security testing, it supplies valuable insight on how to meet important security compliance requirements, including PCI-DSS, PA-DSS, HIPAA, and GLBA. The book also includes an appendix that covers the application security guidelines for the payment card industry standards.

Want to learn more information about Secure Java: For Web Application Development?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Web Services Security Review

Web Services Security
Average Reviews:

(More customer reviews)
Are you looking to buy Web Services Security? Here is the right place to find the great deals. we can offer discounts of up to 90% on Web Services Security. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Web Services Security ReviewWith 2 book on our Web services library shelves, this book adds in as the best for getting introduction to Web services security specifications and popular implementations. If you are little lazy to read the specs from web sites, this book is an ideal choice to get an introduction to them. But again, this book is a bundle of content reproducing the specs of XML Security efforts at W3C, OASIS, WS-Security (IBM & Microsoft), Sun's Liberty, Microsoft Passport. Interestingly this book also contains some obsolete versions of Security specs (So be careful, before you assume things).
If your are an Architect seeking a practical implementation solution or a case study to practice in your architecture, this book DOES NOT add value at ALL. As I said, this book lacks practical implementation scenarios especially examples using real world security implementations like Passport, SunONE, EnTrust, Netegrity TransactionMinder etc. So think about it.
If you are newbie wants to get ideas about Web services security then this BOOK IS THE BEST at this time ! But always lookout for latest book so that you don't get buried with obsolete specifications.Web Services Security OverviewExplains how to implement secure Web services and includes coverage of trust, confidentiality, cryptography, authentication, authorization, and Kerberos. You'll also find details on Security Assertion Markup Language (SAML), XML Key Management Specification (XKMS), XML Encryption, Hypertext Transfer Protocol-Reliability (HTTP-R) and more.

Want to learn more information about Web Services Security?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Security for Web Services and Service-Oriented Architectures Review

Security for Web Services and Service-Oriented Architectures
Average Reviews:

(More customer reviews)
Are you looking to buy Security for Web Services and Service-Oriented Architectures? Here is the right place to find the great deals. we can offer discounts of up to 90% on Security for Web Services and Service-Oriented Architectures. Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Security for Web Services and Service-Oriented Architectures ReviewThe review is based only on the first three chapters that I have managed to read so far.
1. The premise of the book is pretty valuable. There is need for updated literature that takes web services security out of the standards world and makes it more approachable. On that count, I laud the initiative.
2. The book, however, suffers from several significant issues:
a. The proof-reading, for a book that purports to be a reference on the topic, is abysmal. Consider this snippet on page 35 related to threat modeling: "even though the security functions provided by the middleware are becoming more and more reach and complete,...". Any technical editor should have picked up the multiple mistakes in this sentence. Unfortunately, such mistakes abound in the book.
b. In trying to emphasize theory, the book often comes across as dry and irrelevant. For example, table 3.2 related to STRIDE Categories and the surrounding explanation on page 32, while being factually complete, seem like they belong to a Microsoft Press book. At the level the book aims for, what's important is not an explanation of STRIDE (why wouldn't I read Howard's or Swiderski's books for that?) but how that relates to Web services. Explaining the STRIDE concepts as related to a fictional Web Service might have been much more useful.
c.Some of the technical terms used in the book are downright incorrect. For example, on page 35, in the same paragraph as #2(a), the authors talk of "RBAC-based authorization mechanisms". RBAC itself stands for Role Based Access Control. What does it mean for an authorization mechanism to be RBAC-based?
d. If this book is to be useful at all, the figures need to be seriously improved. They are miniature, complex and hardly span a quarter of a page. In short, they are barely decipherable and there's a lot of text referring to such figures that becomes disconnected.
With all this said, I still give the book 3 stars because there is at least some method to the approach and it's much better than reading a bunch of W3C or OASIS standards. Not to mention the fact that chapter 3 refers to CAPEC that I had, in part, contributed attack patterns to :-)
I would definitely wish for the editors at Springer to take a serious look at the language and technical terminology and make figures more understandable. The book has a lot of promise and it would be a shame if such matters were to obscure that.Security for Web Services and Service-Oriented Architectures OverviewWeb services based on the eXtensible Markup Language (XML), the Simple Object Access Protocol (SOAP), and related standards, and deployed in Service-Oriented Architectures (SOA), are the key to Web-based interoperability for applications within and across organizations. It is crucial that the security of services and their interactions with users is ensured if Web services technology is to live up to its promise. However, the very features that make it attractive - such as greater and ubiquitous access to data and other resources, dynamic application configuration and reconfiguration through workflows, and relative autonomy - conflict with conventional security models and mechanisms.Elisa Bertino and her coauthors provide a comprehensive guide to security for Web services and SOA. They cover in detail all recent standards that address Web service security, including XML Encryption, XML Signature, WS-Security, and WS-SecureConversation, as well as recent research on access control for simple and conversation-based Web services, advanced digital identity management techniques, and access control for Web-based workflows. They explain how these implement means for identification, authentication, and authorization with respect to security aspects such as integrity, confidentiality, and availability.This book will serve practitioners as a comprehensive critical reference on Web service standards, with illustrative examples and analyses of critical issues; researchers will use it as a state-of-the-art overview of ongoing research and innovative new directions; and graduate students will use it as a textbook on advanced topics in computer and system security.

Want to learn more information about Security for Web Services and Service-Oriented Architectures?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Inside Java™ 2 Platform Security: Architecture, API Design, and Implementation (2nd Edition) Review

Inside Java™ 2 Platform Security: Architecture, API Design, and Implementation (2nd Edition)
Average Reviews:

(More customer reviews)
Are you looking to buy Inside Java™ 2 Platform Security: Architecture, API Design, and Implementation (2nd Edition)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Inside Java™ 2 Platform Security: Architecture, API Design, and Implementation (2nd Edition). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Inside Java™ 2 Platform Security: Architecture, API Design, and Implementation (2nd Edition) ReviewThe Java 2 security APIs are large, complex, and quite difficult to understand (in fact, their complexity makes me very much afraid that their use will lead to widespread security problems in deployed Java applications, as application writers and site administrators are going to have a hard time keeping track of everything).
Unfortunately, this book provides a difficult and dense coverage of Java 2 security. While it is doggedly thorough in its treatment of the security APIs, it does not ease the task of "pulling it all together" for the reader; if your understanding of Java 2 security is fragmentary when you start reading this book, it will not feel any more coherent when you are done.
Much of the book has the feel of a "laundry list" to me; it reads as if the author felt he had to enumerate absolutely every security feature in Java 2. The result is that sections that are likely to be of marginal interest to most readers, such as PKI certificate management, receive about the same amount of coverage as subtle and important topics such as domain handling and permission checking.
The prose in this book is simply leaden; on a number of occasions, I found myself having to read a paragraph several times, simply to figure out what the author was trying to say.
While this book is invaluable for the information it contains (I will grant that it is much easier to navigate than Sun's security web pages), it is a great disappointment to me.Inside Java™ 2 Platform Security: Architecture, API Design, and Implementation (2nd Edition) OverviewSeries: The Java Series Security is an integral part of the Java platform; all Java APIs are built on a solid security model. That model has always been stronger than the security of other platforms, never allowing for the proliferation of a large virus such as "Melissa" or "I Love You." Now improved security and robust performance peacefully coexist.This book provides a detailed look into the central workings of the Java security architecture, including coverage of the many v1.4 enhancements. This book reviews multiple security threats, such as Trojan horses and denial of service attacks, and the strategies used to combat them. Students will find a practical guide to the deployment of Java security, as well as tips on how to customize, extend, and refine the core security architecture. In addition, it touches on the evolution of Java security, from the restrictive days of the JDK 1.0 sandbox to the sophisticated security features available in Java 2. The book even includes a list of 11 security bugs found in early versions of Java.

Want to learn more information about Inside Java™ 2 Platform Security: Architecture, API Design, and Implementation (2nd Edition)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...

Web Server Administration (Web Warrior) Review

Web Server Administration (Web Warrior)
Average Reviews:

(More customer reviews)
Are you looking to buy Web Server Administration (Web Warrior)? Here is the right place to find the great deals. we can offer discounts of up to 90% on Web Server Administration (Web Warrior). Check out the link below:

>> Click Here to See Compare Prices and Get the Best Offers

Web Server Administration (Web Warrior) ReviewFirst and foremost this book is highly accessible, easy to read, and it's information is relevant, on-point and accurate for its time. Although written during a time where Web Server administration's pedagogy was in its infancy the book does an all around good job in instructing how HTTP works, the types of web servers and how to set up IIS, Apache and other various services such as DNS to get a webserver up and running on the internet along instructions and the science behind various extensions and modules, but lacks contents that digresses deeper into common tasks you may have to do as an administrator.
It's a good book for beginners but to someone who is more experienced with web server administration may look for a book that covers more administrative tasks that you may want to do.
Good for the beginner, but the more experienced administrators may look elsewhere.Web Server Administration (Web Warrior) OverviewWeb Server Administration offers a comprehensive overview of the tools and techniques needed to succeed as a Web Server Administrator as well as the tasks they are expected to perform. This text provides and introduction to the basics of this job role, covers server installation, and then moves on to the installation, configuration, and administration of Web servers. This text covers all topics for both Linux and a Microsoft Windows server environments. Work with Microsoft Windows 2000 Server and Windows Server 2003, Red Hat Linux, Internet Information Services (IIS), Apache Web server, Microsoft SQL Server, MySQL, Microsoft Exchange 2000 Server, sendmail, and more.

Want to learn more information about Web Server Administration (Web Warrior)?

>> Click Here to See All Customer Reviews & Ratings Now
Read More...