- Format
- Häftad (Paperback)
- Språk
- Engelska
- Antal sidor
- 296
- Utgivningsdatum
- 2011-01-19
- Utmärkelser
- Winner of Best Hacking and Pen Testing Books 2011 2011
- Förlag
- SYNGRESS MEDIA
- Medarbetare
- Vela Nava, Eduardo Alberto / Heyes, Gareth / Lindsay, David
- Illustrationer
- Approx. 22 Illustrations
- Dimensioner
- 231 x 188 x 23 mm
- Vikt
- Antal komponenter
- 1
- ISBN
- 9781597496049
- 599 g
Du kanske gillar
-
Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'
391- Skickas inom 10-15 vardagar.
- Gratis frakt inom Sverige över 199 kr för privatpersoner.
Passar bra ihop
De som köpt den här boken har ofta också köpt Tomorrow, And Tomorrow, And Tomorrow av Gabrielle Zevin (häftad).
Köp båda 2 för 560 krKundrecensioner
Har du läst boken? Sätt ditt betyg »Fler böcker av författarna
-
Scientific Writing = Thinking in Words
David Lindsay
-
A Voyage to Arcturus
David Lindsay
-
Science Fiction Novel Super Pack No. 1
Frederik Pohl, Clifford D Simak, David Lindsay, Lester Del Rey, Murray Leinster
-
Voyage to Arcturus
David Lindsay
Recensioner i media
"As the data stored in Web application systems becomes critical to business, the attacks against them are becoming increasingly complex. If you want to move your understanding beyond 'or 1=1--' this book provides the knowledge needed to bypass both filters and detection, crucial for both attack and defence." -- Andrew Waite, Security Researcher, InfoSanity Research
"Intended for advanced network security administrators, penetration testers and web application developers, this guide to web obfuscation presents an in depth technical discussion of the latest methods in site intrusion and Internet attacks. Chapters examine state of the art obfuscation attacks on major website components such as HTML, JavaScript and VBScript, CSS, PHP, SQL and web application firewalls. A final chapter discusses future problems such as the new HTML 5 standards and plug-in vulnerabilities. Chapters include numerous code examples in a variety of languages and formats. Heiderich is a web developer, Nava is a security researcher for Google, Heyes is a security contractor and Lindsay is a security consultant."--SciTechBookNews
Övrig information
Mario Heiderich is a Cologne, Germany-based freelancer and entrepreneur who is devoted to Web application development and security and is currently working on several projects while earning his Ph.D. at Ruhr University in Bochum. He graduated from the University of Applied Sciences in Friedberg/Hessen with a degree in media informatics, and has been working for several German and international companies as a developer and security consultant. In addition to being lead developer for the PHPIDS and author of a German book about Web application security, he has been a speaker at several conferences and a trainer for Web security classes around the world. His work is focused on client-side attacks and defense, especially markup, CSS, and JavaScript, on all major user agents. Eduardo Alberto Vela Nava (Application Security Specialist) works as an information security researcher at Google, Inc., with the task of improving the security of Google and the Internet as a whole, by researching security problems and creating solutions to them. His primary focus is Web application security and browser/plug-in security. He has been a presenter focusing on Web security at several conferences around the world. He previously worked at Alibaba Cloud Computing and Hi5 Networks. Gareth Heyes is based in the United Kingdom and does Web security contracting work and the occasional Web development project. He has been a speaker at the Microsoft BlueHat, Confidence Poland, and OWASP conferences, and is the author of many Web-based tools and sandboxes, including Hackvertor, JSReg, CSSReg, and HTMLReg. David Lindsay is a senior security consultant with Cigital Inc., where he works with industry-leading financial, healthcare, and software companies helping to secure their critical applications. He provides professional assessments and remediation assistance in the form of penetration tests, architecture risk analysis, code review, and security training. He researches Web application security vulnerabilities focusing on emerging security issues related to new standards, frameworks, and architectures. He has spoken at many leading security events over the past few years, including the Microsoft BlueHat, BlackHat, and OWASP conferences. David graduated from the University of Utah with a master's degree in mathematics.
Innehållsförteckning
Chapter 1: Introduction Chapter 2: HTML Chapter 3: JavaScript and VBScript Chapter 4: Nonalphanumeric JavaScript Chapter 5: CSS Chapter 6: PHP Chapter 7: SQL Chapter 8: Web Application Firewalls and Client-side Filters Chapter 9: Mitigating Bypasses and Attacks Chapter 10: Future Developments