|Amazon Price||New from||Used from|
Web applications are everywhere, and they're insecure. Banks,retailers, and others have deployed millions of applications thatare full of holes, allowing attackers to steal personal data, carryout fraud, and compromise other systems. This book shows you howthey do it.
This fully updated edition contains the very latest attacktechniques and countermeasures, showing you how to break intotoday's complex and highly functional applications. Roll up yoursleeves and dig in.
Discover how cloud architectures and social networking haveadded exploitable attack surfaces to applications
Leverage the latest HTML features to deliver powerful cross-sitescripting attacks
Deliver new injection exploits, including XML external entityand HTTP parameter pollution attacks
Learn how to break encrypted session tokens and other sensitivedata found in cloud services
Discover how technologies like HTML5, REST, CSS and JSON can beexploited to attack applications and compromise users
Learn new techniques for automating attacksand dealing withCAPTCHAs and cross-site request forgery tokens
Steal sensitive data across domains using seemingly harmlessapplication functions and new browser features
Find help and resources at http://mdsec.net/wahh
Source code for some of the scripts in the book
Links to tools and other resources
A checklist of tasks involved in most attacks
Answers to the questions posed in each chapter
Hundreds of interactive vulnerability labs
MARCUS PINTO delivers security consultancy and trainingon web application attack and defense to leading globalorganizations in the financial, government, telecom, gaming, andretail sectors.
The authors cofounded MDSec, a consulting company that providestraining in attack and defense-based security.