相關主題
商品描述
HTML5 is fast becoming one of the most popular technologies for creating highly responsive and complex content-driven web applications today. With the introduction of new APIs such as Web Workers, Geolocation, Web Storage, WebSockets, Cross-Document Messaging and Application Cache, this technology has been adopted by many development teams to create applications that provide features previously only possible in thick-client applications. It is also one of the leading candidates for cross-platform mobile application development. This means that it is also one of the most popular targets for attack.
The addition of these complex and feature-rich APIs increases the potential attack surface of your applications, giving smart hackers more opportunities for reaching your private data. Although the W3C have given more consideration to security issues while defining the HTML5 standard than with previous HTML iterations, it is still very possible to introduce security flaws in your web applications with improper use of these APIs. The Definite Guide to HTML5 Security details these security and privacy flaws that arise due to the insecure implementation of the HTML5 APIs and provides methods to secure your applications and websites against them.
The Definitive Guide to HTML5 Security:
- Introduces you to the potent
ial security and privacy flaws that may occur due to insecure implementation of the various HTML5 APIs.
- Provides information that will help you make the right security decisions while designing and conceptualizing various application components.
- Provides detailed examples and walkthroughs, showing ways to implement these features securely.
商品描述(中文翻譯)
HTML5 正迅速成為當今創建高度響應和複雜內容驅動的網頁應用程式最受歡迎的技術之一。隨著 Web Workers、地理位置 (Geolocation)、網頁儲存 (Web Storage)、WebSockets、跨文件消息傳遞 (Cross-Document Messaging) 和應用快取 (Application Cache) 等新 API 的引入,許多開發團隊已經採用這項技術來創建提供以前僅在厚客戶端應用程式中才能實現的功能的應用程式。它也是跨平台行動應用程式開發的主要候選技術之一。這意味著它也是最受攻擊者青睞的目標之一。
這些複雜且功能豐富的 API 的增加擴大了應用程式的潛在攻擊面,給聰明的駭客提供了更多接觸您私人數據的機會。儘管 W3C 在定義 HTML5 標準時比以往的 HTML 版本更考慮安全問題,但不當使用這些 API 仍然很可能在您的網頁應用程式中引入安全漏洞。《HTML5 安全性權威指南》詳細說明了由於不安全實現 HTML5 API 而產生的這些安全和隱私漏洞,並提供了保護您的應用程式和網站免受這些漏洞影響的方法。
《HTML5 安全性權威指南:》
- 介紹了由於各種 HTML5 API 的不安全實現可能出現的潛在安全和隱私漏洞。
- 提供有助於您在設計和構思各種應用程式組件時做出正確安全決策的信息。
- 提供詳細的範例和步驟說明,展示如何安全地實現這些功能。