当前位置: 首页 > 资源下载 > Web开发 > 查看资源

资源分类
Web开发
Java
.NET
编程语言
数据库
软件工程
图形动画
系统管理
网络通信安全
计算机理论
考试认证
人文百科
文档手册
硬件技术
办公软件

Web Security Testing Cookbook: Systematic Techniques to Find Problems Fast

Web Security Testing Cookbook: Systematic Techniques to Find Problems Fast

书名:Web Security Testing Cookbook: Systematic Techniques to Find Problems Fast

上传:石头

时间:2009-08-24

文件大小:8.7 MB

资源出处:查看资源出处 >>

收藏到网摘: n/a



作者:Paco Hope, Ben Walther
出版日期:October 28, 2008
出版社:O'Reilly
页数:312
ISBN:ISBN-10: 0596514832 ISBN-13: 978-0596514839
文件格式:CHM


Product Description
Among the tests you perform on web applications, security testing isperhaps the most important, yet it’s often the most neglected. Therecipes in the Web Security Testing Cookbook demonstrate how developersand testers can check for the most common web security issues, whileconducting unit tests, regression tests, or exploratory tests. Unlikead hoc security assessments, these recipes are repeatable, concise, andsystematic-perfect for integrating into your regular test suite.Recipes cover the basics from observing messages between clients andservers to multi-phase tests that script the login and execution of webapplication features. By the end of the book, you’ll be able to buildtests pinpointed at Ajax functions, as well as large multi-step testsfor the usual suspects: cross-site scripting and injection attacks.This book helps you: Obtain, install, and configure useful-andfree-security testing tools Understand how your applicationcommunicates with users, so you can better simulate attacks in yourtests Choose from many different methods that simulate common attackssuch as SQL injection, cross-site scripting, and manipulating hiddenform fields Make your tests repeatable by using the scripts andexamples in the recipes as starting points for automated testsDon’tlive in dread of the midnight phone call telling you that your site hasbeen hacked. With Web Security Testing Cookbook and the free tools usedin the book’s examples, you can incorporate security coverage into yourtest suite, and sleep in peace.About the Author
Paco Hope is a TechnicalManager at Cigital, Inc. and co-author of Mastering FreeBSD and OpenBSDSecurity (April 2005, O’Reilly, ISBN 0596006268). Mr. Hope has alsopublished articles on Misuse and Abuse Cases and PKI. He has beeninvited to conferences to speak on topics such as software securityre-quirements, web application security, and embedded system security.At Cigi-tal, he has served as a subject matter expert to MasterCardInternational for security policies and has assisted a Fortune 500hospitality company in writ-ing software security policy. He alsotrains software developers and testers in the fundamentals of softwaresecurity. In the gaming and mobile communica-tions industries he hasadvised several companies on software security. Mr. Hope majored inComputer Science and English at The College of William and Mary andreceived an M.S. in Computer Science from the University of Virginia.
Ben Walther is a consultant at Cigital and contributor to the EditCookies tool. He has a hand in both normal Quality Assurance andSoftware Security. Day to day, he designs and executes tests – and sohe understands the need for simple recipes, in the hectic QA world. Yethe has also given talks on web ap-plication testing tools to members ofthe Open Web Application Security Pro-ject (OWASP). Through Cigital, hetests systems ranging from financial data processing to slot machines.Mr. Walther has a B.S. in Information Science from Cornell University.
Tags:COOKBOOKFastFindSecurityTesting


相关书籍

  • Network Security Technologies and Solutions
  • Network Security Technologies and Solutions
  • Router Security Strategies: Securing IP Network Traffic Planes (PDF英文版)
  • Network Security Technologies and Solutions
  • Security Power Tools

评论 (1) 1 All

登陆 | 还没注册?