I just read the Dafydd Stuttard's 2nd edition of The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws. I've read many book on penetration testing. But this one takes the lead as far as securing your web applications go.
I'm going to start by comparing it to the first. The first book on Web Application hacking, The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws
The second book which has a slightly different title, The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
Below are new topics included in this 2nd edition which differ from the first book (as mentioned in Amazon):
- Discover how cloud architectures and social networking have added exploitable attack surfaces to applications
- Leverage the latest HTML features to deliver powerful cross-site scripting attacks
- Deliver new injection exploits, including XML external entity and HTTP parameter pollution attacks
- Learn how to break encrypted session tokens and other sensitive data found in cloud services
- Discover how technologies like HTML5, REST, CSS and JSON can be exploited to attack applications and compromise users
- Learn new techniques for automating attacks and dealing with CAPTCHAs and cross-site request forgery tokens
- Steal sensitive data across domains using seemingly harmless application functions and new browser features
So if you really want to learn something about web application hacking and if you have the tenacity to research on topics that seem unclear. Then go for The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
. You won't just gain the top-level familiarity often provided by most security books. You will surely learn the skills needed to hack web applications. Guaranteed. That's why even seasoned veterans would even but for this awesome reference.
I would definitely recommend getting this to beef up your knowledge arsenal on web application security.
No comments:
Post a Comment