Professional Pen Testing for Web Applications
暫譯: 專業網頁應用程式滲透測試
Andres Andreu
- 出版商: Wrox Press
- 出版日期: 2006-07-01
- 定價: $1,800
- 售價: 2.2 折 $399
- 語言: 英文
- 頁數: 548
- 裝訂: Paperback
- ISBN: 0471789666
- ISBN-13: 9780471789666
-
相關分類:
資訊安全、駭客 Hack
立即出貨(限量) (庫存=4)
買這商品的人也買了...
-
$980$833 -
$490$382 -
$299$254 -
$350$298 -
$880$695 -
$490$417 -
$450$383 -
$780$663 -
$680$578 -
$3,026$2,875 -
$520$442 -
$650$507 -
$680$578 -
$980$774 -
$299Enterprise Integration with Ruby (Paperback)
-
$520$442 -
$880$695 -
$490$382 -
$750$638 -
$680$578 -
$450$383 -
$780$616 -
$199From Java to Ruby: Things Every Manager Should Know
-
$720$612 -
$399CCNA ICND2 Official Exam Certification Guide (CCNA Exams 640-816 and 640-802), 2/e
相關主題
商品描述
Description
There is no such thing as "perfect security" when it comes to keeping all systems intact and functioning properly. Good penetration (pen) testing creates a balance that allows a system to be secure while simultaneously being fully functional. With this book, you'll learn how to become an effective penetrator (i.e., a white hat or ethical hacker) in order to circumvent the security features of a Web application so that those features can be accurately evaluated and adequate security precautions can be put in place.
After a review of the basics of web applications, you'll be introduced to web application hacking concepts and techniques such as vulnerability analysis, attack simulation, results analysis, manuals, source code, and circuit diagrams. These web application hacking concepts and techniques will prove useful information for ultimately securing the resources that need your protection.
What you will learn from this book
- Surveillance techniques that an attacker uses when targeting a system for a strike
- Various types of issues that exist within the modern day web application space
- How to audit web services in order to assess areas of risk and exposure
- How to analyze your results and translate them into documentation that is useful for remediation
- Techniques for pen-testing trials to practice before a live project
Who this book is for
This book is for programmers, developers, and information security professionals who want to become familiar with web application security and how to audit it.
Wrox Professional guides are planned and written by working programmers to meet the real-world needs of programmers, developers, and IT professionals. Focused and relevant, they address the issues technology professionals face every day. They provide examples, practical solutions, and expert education in new technologies, all designed to help programmers do a better job.
商品描述(中文翻譯)
**描述**
在保持所有系統完整且正常運作的情況下,並不存在所謂的「完美安全」。良好的滲透測試(pen testing)能夠創造一種平衡,使系統在安全的同時仍然能夠完全運行。透過本書,您將學習如何成為一名有效的滲透者(即白帽駭客或道德駭客),以繞過網路應用程式的安全功能,從而能夠準確評估這些功能並採取適當的安全預防措施。
在回顧網路應用程式的基本知識後,您將接觸到網路應用程式駭客的概念和技術,例如漏洞分析、攻擊模擬、結果分析、手冊、源代碼和電路圖。這些網路應用程式駭客的概念和技術將對最終保護需要您保護的資源提供有用的信息。
您將從本書中學到的內容:
- 攻擊者在針對系統進行攻擊時所使用的監控技術
- 當今網路應用程式領域中存在的各種問題
- 如何審核網路服務以評估風險和暴露的領域
- 如何分析您的結果並將其轉化為有助於修復的文檔
- 在實際項目之前進行滲透測試的練習技術
本書的讀者對象:
本書適合希望熟悉網路應用程式安全及其審核方法的程式設計師、開發人員和資訊安全專業人士。
Wrox Professional 指南由現職程式設計師規劃和撰寫,以滿足程式設計師、開發人員和 IT 專業人士的實際需求。這些指南專注且相關,針對技術專業人士每天面臨的問題提供解決方案、實用範例和新技術的專家教育,旨在幫助程式設計師更好地完成工作。