Web Intrusion Security Testing and Countermeasures - (Includes CD-ROM)

Author: Andrew
Publisher:
Publish Date: 2006-10-01
Features: Without a doubt, hackers will launch brutal attacks on your web sites, applications, and servers. If your website has vulnerabilities, it's best that these hackers discover them first. Now there's an authoritative, portable guide for security testing of web-based software. In this book, two senior experts introduce various attacks targeting web software: attacks on clients, servers, state, user input, and more. With an in-depth understanding of the numerous critical and frequently exploited vulnerabilities in web architectures and code, you will gradually master powerful attack tools and techniques. The authors reveal how to identify potential threats and attack vectors, how to rigorously test them, and how to eliminate the issues discovered. The content covered includes:
· Client-side vulnerabilities, including attacks on client-side validation;
· State-based attacks: hidden fields, CGI parameters, cookie manipulation, URL jumping, and session hijacking;
· Attacks on user-submitted input data: cross-page scripting, SQL injection, and directory traversal;
· Language- and technology-based attacks: buffer overflows, canonicalization attacks, and NULL string attacks;
· Server-side attacks: SQL injection in stored procedures, command injection, and server authentication;
· Encryption, privacy, and attacks targeting web services.
The operation of web software is critical and cannot be taken lightly in the slightest. Whether you are a developer, tester, QA expert, or IT manager, this book will help you protect your software products—systematically.

📌 Related Posts