How to Break Web Software: Functional and Security Testing of Web Applications and Web Services
Course
Online
Description
-
Type
Course
-
Methodology
Online
-
Start date
Different dates available
In this book, the authors demonstrate how rigorous web testing can help prevent and prepare websites and web-based applications for attack by hackers etc.
Facilities
Location
Start date
Start date
Reviews
Subjects
- IT
- Web
- IT Security
- Security
- Testing
Course programme
In this book, the authors demonstrate how rigorous web testing can help prevent and prepare websites and web-based applications for attack by hackers etc.
Program
Since its early days as an information exchange tool limited to academe, researchers, and the military, the web has grown into a commerce engine that is now omnipresent in all facets of our lifes. More websites are created daily and more applications are developed to allow users to learn, research, and purchase online. As a result, web development is often rushed, which increases the risk of attacks from hackers. Furthermore, the need for secure applications has to be balanced with the need for usability, performance, and reliability.
In this book, the authors demonstrate how rigorous web testing can help prevent and prepare for such attacks. They point out that methodical testing must include identifying threats and attack vectors to establish and then implement the appropriate testing techniques, manual or automated.
Topics covered in this book include:
- Client vulnerabilities, including attacks on client-side validation.
- State-based attacks: hidden fields, CGI parameters, cookie poisoning, URL jumping, and session hijacking.
- Attacks on user-supplied inputs: cross-site scripting, SQL injection, and directory traversal.
- Language- and technology-based attacks: buffer overflows, canonicalization, and NULL string attacks.
- Server attacks: SQL Injection with stored procedures, command injection, and server fingerprinting.
- Cryptography, privacy, and attacks on Web services.
Included with this book is a companion CD which contains full source code for one testing tool which you can modify and extend, free Web security testing tools, and complete code from a flawed Web site designed to give you hands-on practice in identifying security holes.
Reviews of the Book
'The techniques in this book are not an option for testers-they are mandatory and these are the guys to tell you how to apply them!'
-Harry Robinson, Google .
Authors: Mike Andrews, James Whittaker
Publisher: Addison Wesley Professional
ISBN 10: 0321369440
ISBN 13: 9780321369444
Pages: 240
Format: Soft Cover
Published Date: Feb 2006
Availability: Ex Stock
How to Break Web Software: Functional and Security Testing of Web Applications and Web Services