没有合适的资源?快使用搜索试试~ 我知道了~
首页hacking exposed web applications
hacking exposed web applications
需积分: 10 70 浏览量
更新于2023-05-28
评论
收藏 3.72MB PDF 举报
Implement bulletproof e-business security the proven Hacking Exposed way. Defend against the latest Web-based attacks by looking at your Web applications through the eyes of a malicious intruder. Fully revised and updated to cover the latest Web exploitation techniques, "Hacking Exposed Web Applications, Second Edition" shows you, step-by-step, how cyber-criminals target vulnerable sites, gain access, steal critical data, and execute devastating attacks. All of the cutting-edge threats and vulnerabilities are covered in full detail alongside real-world examples, case studies, and battle-tested countermeasures from the authors' experiences as gray hat security professionals.
资源详情
资源评论
资源推荐


Praise for Hacking Exposed™ Web Applications:
Web Application Security Secrets and Solutions, Third Edition
“Whether you are a business leader attempting to understand the threat space for your business,
or an engineer tasked with writing the code for those sites, or a security engineer attempting to
identify and mitigate the threats to your applications, this book will be an invaluable weapon in
your arsenal.”
—From the Foreword by Chris Peterson
Senior Director of Application Security, Zynga Game Network
Former Director of Security Assurance, Microsoft Corporation
“I cut my teeth reading Joel’s work, and this book is no disappointment. People often ask where to
find high-quality content that will help them gain a foothold in this daunting industry. This is the
kind of desk reference every web application security practitioner needs. It will certainly hold a
place of prominence in my personal library.”
—Robert “RSnake” Hansen
CEO SecTheory and founder of ha.ckers.org
“An eye-opening resource for realizing the realities of today’s web application security landscape,
this book explores the latest vulnerabilities as well as exploitation techniques and tradecraft being
deployed against those vulnerabilities. This book is a valuable read for both the aspiring engineer
who is looking for the first foray into the world of web application security and the seasoned
application-security, penetration-testing expert who wants to keep abreast of current techniques.”
—Chad Greene
Director, eBay Global Information Security
“As our businesses push more of their information and commerce to their customers through web-
applications, the confidentiality and integrity of these transactions is our fundamental, if not
mandatory, responsibility. Hacking Exposed Web Applications provides a comprehensive blueprint for
application developers and security professionals charged with living up to this responsibility. The
authors’ research, insight, and 30+ years as information security experts, make this an invaluable
resource in the application and information protection toolkit. Great Stuff!”
—Ken Swanson
CISM, IS Business Solution Manager, regionally based P&C insurance company
“This book is so much more then the authoritative primer on web application security; it’s also an
opportunity to accompany the foremost industry experts in an apprenticeship that even seasoned
professionals will enjoy.”
—Andrew Stravitz, CISSP
Director of Information Security, Barnes & Noble.com
“A very timely reference, as cloud computing continues to expand into the enterprise and web
security emerges as the new battleground for attackers and defenders alike. This comprehensive
text is the definitive starting point for understanding the contemporary landscape of threats and
mitigations to web applications. Particularly notable for its extensive treatment of identity
management, marking the first time that challenges around authentication have been surveyed
in-depth and presented in such an accessible fashion.”
—Cem Paya
Google Security Team

This page intentionally left blank

HACKING EXPOSED
™
WEB APPLICATIONS:
WEB APPLICATION SECURITY
SECRETS AND SOLUTIONS
THIRD EDITION
JOEL SCAMBRAY
VINCENT LIU
CALEB SIMA
New York Chicago San Francisco
Lisbon London Madrid Mexico City
Milan New Delhi San Juan
Seoul Singapore Sydney Toronto

Copyright © 2011 by Joel Scambray. All rights reserved. Except as permitted under the United States Copyright Act of 1976, no part of
this publication may be reproduced or distributed in any form or by any means, or stored in a database or retrieval system, without the
prior written permission of the publisher.
ISBN: 978-0-07-174042-5
MHID: 0-07-174042-2
The material in this eBook also appears in the print version of this title: ISBN: 978-0-07-174064-7,
MHID: 0-07-174064-3.
All trademarks are trademarks of their respective owners. Rather than put a trademark symbol after every occurrence of a trademarked
name, we use names in an editorial fashion only, and to the benefi t of the trademark owner, with no intention of infringement of the
trademark. Where such designations appear in this book, they have been printed with initial caps.
McGraw-Hill eBooks are available at special quantity discounts to use as premiums and sales promotions, or for use in corporate training
programs. To contact a representative please e-mail us at bulksales@mcgraw-hill.com.
Trademarks: McGraw-Hill, the McGraw-Hill Publishing logo, Hacking ExposedTM, and related trade dress are trademarks or registered
trademarks of The McGraw-Hill Companies and/or its affi liates in the United States and other countries and may not be used without
written permission. All other trademarks are the property of their respective owners. The McGraw-Hill Companies is not associated with
any product or vendor mentioned in this book.
Information has been obtained by McGraw-Hill from sources believed to be reliable. However, because of the possibility of human or
mechanical error by our sources, McGraw-Hill, or others, McGraw-Hill does not guarantee the accuracy, adequacy, or completeness of
any information and is not responsible for any errors or omissions or the results obtained from the use of such information.
TERMS OF USE
This is a copyrighted work and The McGraw-Hill Companies, Inc. (“McGrawHill”) and its licensors reserve all rights in and to the work.
Use of this work is subject to these terms. Except as permitted under the Copyright Act of 1976 and the right to store and retrieve one copy
of the work, you may not decompile, disassemble, reverse engineer, reproduce, modify, create derivative works based upon, transmit,
distribute, disseminate, sell, publish or sublicense the work or any part of it without McGraw-Hill’s prior consent. You may use the
work for your own noncommercial and personal use; any other use of the work is strictly prohibited. Your right to use the work may be
terminated if you fail to comply with these terms.
THE WORK IS PROVIDED “AS IS.” McGRAW-HILL AND ITS LICENSORS MAKE NO GUARANTEES OR WARRANTIES AS
TO THE ACCURACY, ADEQUACY OR COMPLETENESS OF OR RESULTS TO BE OBTAINED FROM USING THE WORK,
INCLUDING ANY INFORMATION THAT CAN BE ACCESSED THROUGH THE WORK VIA HYPERLINK OR OTHERWISE,
AND EXPRESSLY DISCLAIM ANY WARRANTY, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WAR-
RANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. McGraw-Hill and its licensors do not warrant
or guarantee that the functions contained in the work will meet your requirements or that its operation will be uninterrupted or error free.
Neither McGraw-Hill nor its licensors shall be liable to you or anyone else for any inaccuracy, error or omission, regardless of cause, in
the work or for any damages resulting therefrom. McGraw-Hill has no responsibility for the content of any information accessed through
the work. Under no circumstances shall McGraw-Hill and/or its licensors be liable for any indirect, incidental, special, punitive, conse-
quential or similar damages that result from the use of or inability to use the work, even if any of them has been advised of the possibility
of such damages. This limitation of liability shall apply to any claim or cause whatsoever whether such claim or cause arises in contract,
tort or otherwise.
剩余480页未读,继续阅读

















sinat_21954747
- 粉丝: 0
- 资源: 24
上传资源 快速赚钱
我的内容管理 收起
我的资源 快来上传第一个资源
我的收益
登录查看自己的收益我的积分 登录查看自己的积分
我的C币 登录后查看C币余额
我的收藏
我的下载
下载帮助

会员权益专享
最新资源
- Xilinx SRIO详解.pptx
- Informatica PowerCenter 10.2 for Centos7.6安装配置说明.pdf
- 现代无线系统射频电路实用设计卷II 英文版.pdf
- 电子产品可靠性设计 自己讲课用的PPT,包括设计方案的可靠性选择,元器件的选择与使用,降额设计,热设计,余度设计,参数优化设计 和 失效分析等
- MPC5744P-DEV-KIT-REVE-QSG.pdf
- 通信原理课程设计报告(ASK FSK PSK Matlab仿真--数字调制技术的仿真实现及性能研究)
- ORIGIN7.0使用说明
- 在VMware Player 3.1.3下安装Redhat Linux详尽步骤
- python学生信息管理系统实现代码
- 西门子MES手册 13 OpcenterEXCR_PortalStudio1_81RB1.pdf
资源上传下载、课程学习等过程中有任何疑问或建议,欢迎提出宝贵意见哦~我们会及时处理!
点击此处反馈



安全验证
文档复制为VIP权益,开通VIP直接复制

评论0