新書推薦:

《
海上墨林:大师眼中的海派画家
》
售價:NT$
449.0

《
赌注:海难、叛变和谋杀的故事
》
售價:NT$
352.0

《
工业机器人自动化生产线集成与运维 杨铨 黄洁
》
售價:NT$
356.0

《
战争与史学家:李维历史书写中的汉尼拔战争
》
售價:NT$
296.0

《
低卡料理,30天神奇变瘦
》
售價:NT$
305.0

《
古韵新声
》
售價:NT$
8568.0

《
常见中药炮制品在方剂中的选用
》
售價:NT$
454.0

《
工厂生产设备精细化、精益化、精进化管理手册
》
售價:NT$
352.0
|
內容簡介: |
Thisbookisapracticalguidetodiscoveringandexploitingsecurityflawsinwebapplications.Theauthorsexplaineachcategoryofvulnerabilityusingreal-worldexamples,screenshotsandcodeextracts.Thebookisextremelypracticalinfocus,anddescribesindetailthestepsinvolvedindetectingandexploitingeachkindofsecurityweaknessfoundwithinavarietyofapplicationssuchasonlinebanking,e-commerceandotherwebapplications.Thetopicscoveredincludebypassingloginmechanisms,injectingcode,exploitinglogicflawsandcompromisingotherusers.Becauseeverywebapplicationisdifferent,attackingthementailsbringingtobearvariousgeneralprinciples,techniquesandexperienceinanimaginativeway.Themostsuccessfulhackersgobeyondthis,andfindwaystoautomatetheirbespokeattacks.Thishandbookdescribesaprovenmethodologythatcombinesthevirtuesofhumanintelligenceandcomputerizedbruteforce,oftenwithdevastatingresults.Theauthorsareprofessionalpenetrationtesterswhohavebeeninvolvedinwebapplicationsecurityfornearlyadecade.TheyhavepresentedtrainingcoursesattheBlackHatsecurityconferencesthroughouttheworld.UnderthealiasPortSwigger,DafydddevelopedthepopularBurpSuiteofwebapplicationhacktools.
|
關於作者: |
DafyddStuttardisaPrincipalSecurityConsultantatNextGenerationSecuritySoftware,whereheleadsthewebapplicationsecuritycompetency.Hehasnineyears''experienceinsecurityconsultingandspecializesinthepenetrationtestingofwebapplicationsandcompiledsoftware.Dafyddhasworkedwithnumerousbanks,retailers,andotherenterprisestohelpsecuretheirwebapplications,andhasprovidedsecurityconsultingtoseveralsoftwaremanufacturersandgovernmentstohelpsecuretheircompiledsoftware.Dafyddisanaccomplishedprogrammerinseverallanguages,andhisinterestsincludedevelopingtoolstofacilitateallkindsofsoftwaresecuritytesting.DafyddhasdevelopedandpresentedtrainingcoursesattheBlackHatsecurityconferencesaroundtheworld.UnderthealiasPortSwigger,DafyddcreatedthepopularBurpSuiteofwebapplicationhackingtools.Dafyddholdsmaster''sanddoctoratedegreesinphilosophyfromtheUniversityofOxford.
MarcusPintoisaPrincipalSecurityConsultantatNextGenerationSecuritySoftware,whereheleadsthedatabasecompetencydevelopmentteam,andhasleadthedevelopmentofNGS''primarytrainingcourses.Hehaseightyears''experienceinsecurityconsultingandspecializesinpenetrationtestingofwebapplicationsandsupportingarchitectures.Marcushasworkedwithnumerousbanks,retailers,andotherenterprisestohelpsecuretheirwebapplications,andhasprovidedsecurityconsultingtothedevelopmentprojectsofseveralsecurity-criticalapplications.Hehasworkedextensivelywithlarge-scalewebapplicationdeploymentsinthefinancialservicesindustry.MarcushasdevelopedandpresenteddatabaseandwebapplicationtrainingcoursesattheBlackHatandothersecurityconferencesaroundtheworld.Marcusholdsamaster''sdegreeinphysicsfromtheUniversityofCambridge.
|
|