Hacking Web Apps: Detecting and Preventing Web Application Security Problems 1st Edition, Kindle Edition
Thumbnail 1

Hacking Web Apps: Detecting and Preventing Web Application Security Problems 1st Edition, Kindle Edition

产品编号: 118230169
安全交易
经常一起购买

描述

Full description not available

评论

D**E

Good reference, inadequate textbook

This books is a great reference work that covers - in good detail - concepts and techniques in hacking web applications. I found this somewhat lacking in bootstrapping me into practical application. I bought this book with the intent that it'd get me into basic XSS and SQL injection attacks, but there isn't much to "practice" per se.As a caveat, I'm not sure this within the scope of this text, and it is a very good primer on the various attack vectors and types. Make no mistake, I've read this book and used it to give me a leg up into the vocabulary of web application security, but I found other texts more useful as "how to" texts.

J**I

Alert book

All u learned is to write a alert, thanks

A**D

Hacking Web Apps - A Modern Introduction to Web Application Security with HTML5

Hacking Web Apps by Mike Shema is a contemporary guide on web application security. Mike's labor of love, as he likes to call this book, contains very relevant and distilled information on modern day web application attacks. The book is different from your garden variety web-application-top-n-style verbose texts with template vulnerabilities and hello-world solutions; Hacking web apps is a book with strong personality which shows in the eight chapters covering diverse topics from HTML5 security, XSS, CSRF, platform weaknesses to browser and privacy attacks.Starting with HTML5, author discussed security issues surrounding "new" DOM, CORS, web sockets, web storage, web workers in a concise and concrete manner. This first chapter, however brief, makes this book quite unique since very few books in my knowledge have dealt with security issues pertaining to HTML5. The book provides a nice knowledge upgrade to exploits and vulnerabilities when it comes to web 2.0 technologies. Packed with tips, epic failures and notes providing security anecdotes from the real-world, this text keeps you involved and entertained throughout. Going beyond usual CWE-SANS/OWASP top x vulnerabilities, author elaborates on design issues and draw parallels on how to apply these issues to other similar problems. The text tends to be language agnostic and code samples are in multiple languages (python, php etc) but I do miss the examples with specifics of libraries such as AntiForgeryToken in ASP.NET MVC. I have not read any of Mike's previous books so I cannot comment on how much is shared between his writings but for any web and server side developer interested in security, I'd highly recommend reading this book.

M**G

useful information on day to day

Los 'malos' siempre van por delante. Sabemos que la web no es segura. Hay que ir con mil ojos. No nos podemos quedar en lo que aprendimos hace años. Aquellas prácticas que ponemos en práctica en nuestros desarrollos pueden ya no ser seguras o recomendables. Vivimos de repetir nuestro código que nunca (o casi nunca) ha sido atacado. Trabajamos con frameworks y creemos que eso nos libra de todo mal, dejamos de pensar y delegamos en otros.Este libro, no es demasiado largo, va al grano y te da un buen paseo por muchos tipos de vulnerabilidades que pueden darse en la web, así como técnicas para intentar evitarlas y todo acompañado con código de ejemplo.El enfoque es rápido y claro. No busques una gran profundidad, pero es que realmente, en este tema no hace falta, ya que las variantes son casi infinitas. Lo que hay que tener claro es a lo que nos enfrentamos, tener un conocimiento general y adaptarlo a nuestras necesidades.Una compra totalmente recomendable y un conocimiento imprescindible.From Google translator ->The bad guys are always ahead. We know that the web is not safe. You should go with a thousand eyes. We can not stay on what we learned years ago. Those practices that we implement in our developments may no longer be safe or advisable. We live to repeat our code that never (or rarely) been attacked. And we work with frameworks that frees us from all evil, we stop thinking and delegate to others.This book is not too long, to the point and gives a smooth ride for many types of vulnerabilities that can occur in the web as well as techniques to try to avoid and all accompanied with sample code.The focus is fast and clear. Look no great depth, but is that really, this topic is not necessary, since the variations are almost endless. What must be clear is what we face, have a general knowledge and adapt it to our needs.Purchase fully recommended and essential knowledge.

A**R

A must read but lacked a competent editor

This book is a must read for anyone interested in web application security. I read it after I completed the author's previous work  Seven Deadliest Web Application Attacks (Seven Deadliest Attacks) .I wish I'd read this one first - as they are nearly identical but this is a super-set of his prior book, with better topic organization, and better examples (for instance the HTML insertion/XSS example tables.)That said the biggest complaint I had with the previous work still continues - the writing is marred by very poor editing - fortunately, not enough to detract from an otherwise excellent text.

N**E

Something we all need to read

In today's world, we absolutely must be concerned about security. There are quite a few ways our information including our passwords, bank account information and personal identity can be stolen via the web. Most of the attacks need only the browser to access this information, according to Mike Shema. Mr. Shema is a well-respected authority in the web security field.We, as web surfers, often buy products from various vendors on the web, and some of us even play games on the web, without a seconds' thought about the possible consequences. We believe our privacy to be safe and even sacrosanct. But, as consumers, and specially as retailers, we really need to pay attention and be aware of the possible dangers of what we do. We wouldn't leave the door unlocked while on vacation, or even while gone to work, the store, a movie or dinner date. So why do we often skip the security essentials of our web surfing,and our online activities? Are we really so complacent as to think that it couldn't have to us?In my not so humble opinion, we should all buy this book and follow its recommendations.

E**M

Printed in Blurry Font

I cannot comment on the content of the this book, because the book is printed in unclear, blurry font, which is hard and most unpleasant to read. It is as if the pages had first been printed then photographed or rendered into images, which were then printed to the book. Returned the item. If you need this book, buy the kindle edition, which is hopefully better.

T**A

I will definitely recommend it to my friends

Being a developer this is quite an interesting reading. I will definitely recommend it to my friends. thanx for the timely delivery

S**K

Sehr praktisch und auf neuestem Stand

Dieses Buch bietet einen ungewöhnlichen Einblick in Risiken die mit Webanwendungen verbunden sind.Man muss bereits einige Erfahrung im Umfeld haben, z.B. Grundwebentwicklungkenntnisse, wie HTTP-Protokol definiert is, Netzwerkprotokoll - und Datenbankkentnisse sind auch von Vorteil.Im Vergleich mit häufigen anderen Informationsquellen bietet das Buch eine andere Ansicht. Ich habe schon gewisse Erfahrung in IT-Security, beim Lesen habe ich aber neue Zusammenhänge gefunden. Die ArtikelnVerbesserungsvorschlag: Es wäre super, die Buchbeispiele als Quellcode online zu veröffentlichen.

常见问题

是的,所有产品均直接来自美国,英国,阿联酋和印度的授权零售商。我们保持严格的质量控制过程,并在运输前验证每种产品。所有项目都有适用的制造商保证,并由我们的标准退货政策涵盖。
送货时间因目的地国家 /地区不等,通常从3-9个工作日不等。每个订单都可以通过我们的系统完全跟踪。我们处理所有关闭范围,并使用可靠的快递合作伙伴进行最后一英里的交付。您将通过电子邮件和我们的应用程序定期收到有关您的订单状态的更新。
自2014年以来,落伍车是一个国际电子商务平台。我们每天在全球范围内安全地处理数千个订单。每个产品都会在交付前经过我们的质量验证过程,我们提供端到端订单跟踪,24/7客户支持以及全面的回报政策,以确保安全的购物体验。
我们的价格包括产品成本,国际运输,进口关税,关税和当地交货费用。我们处理所有海关和导入程序,确保交货时没有隐藏的费用。 Pro会员将获得额外的福利,包括免费送货。

TrustPilot

TrustScore 4.5 | 7,300多个评论

安妮塔· G.

体验不错,但跟踪更新可以更好。

2 个月前

Neha S.

整个订购过程中沟通顺畅。产品完美。

2 周前

全球购物,通过 Desertcart 享受优惠
物有所值
各种产品的价格具有竞争力
全球购物
为 100 多个国家的数百万购物者提供服务
增强保护
深受全球购物者喜爱的值得信赖的支付方式
客户保证
深受全球购物者喜爱的值得信赖的支付方式。
沙漠车应用程序
随时随地随时随地购物。
MOP$476

关税和税费包括

Macau店铺
1
免费退货

30天对于 PRO 会员用户

15天无会员资格

安全交易

向AI询问此产品

TrustPilot

TrustScore 4.5 | 7,300多个评论

Pooja R.

客户服务超出了我的预期。非常适合购买在其他地方找不到的产品。

1 周前

Meera L.

交易顺利,产品完好无损地到达。

3 周前

Hacking Web Apps Detecting And Preventing Web Application Security Problems | Desertcart Macau