Mastering Modern Web Penetration Testing
暫譯: 精通現代網頁滲透測試

Prakhar Prasad

  • 出版商: Packt Publishing
  • 出版日期: 2016-10-28
  • 售價: $2,010
  • 貴賓價: 9.5$1,910
  • 語言: 英文
  • 頁數: 298
  • 裝訂: Paperback
  • ISBN: 1785284584
  • ISBN-13: 9781785284588
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

商品描述

Key Features

  • This book covers the latest technologies such as Advance XSS, XSRF, SQL Injection, Web API testing, XML attack vectors, OAuth 2.0 Security, and more involved in today's web applications
  • Penetrate and secure your web application using various techniques
  • Get this comprehensive reference guide that provides advanced tricks and tools of the trade for seasoned penetration testers

Book Description

Web penetration testing is a growing, fast-moving, and absolutely critical field in information security. This book executes modern web application attacks and utilises cutting-edge hacking techniques with an enhanced knowledge of web application security.

We will cover web hacking techniques so you can explore the attack vectors during penetration tests. The book encompasses the latest technologies such as OAuth 2.0, Web API testing methodologies and XML vectors used by hackers. Some lesser discussed attack vectors such as RPO (relative path overwrite), DOM clobbering, PHP Object Injection and etc. has been covered in this book.

We'll explain various old school techniques in depth such as XSS, CSRF, SQL Injection through the ever-dependable SQLMap and reconnaissance.

Websites nowadays provide APIs to allow integration with third party applications, thereby exposing a lot of attack surface, we cover testing of these APIs using real-life examples.

This pragmatic guide will be a great benefit and will help you prepare fully secure applications.

What you will learn

  • Get to know the new and less-publicized techniques such PHP Object Injection and XML-based vectors
  • Work with different security tools to automate most of the redundant tasks
  • See different kinds of newly-designed security headers and how they help to provide security
  • Exploit and detect different kinds of XSS vulnerabilities
  • Protect your web application using filtering mechanisms
  • Understand old school and classic web hacking in depth using SQL Injection, XSS, and CSRF
  • Grasp XML-related vulnerabilities and attack vectors such as XXE and DoS techniques
  • Get to know how to test REST APIs to discover security issues in them

About the Author

Prakhar Prasad is a web application security researcher and penetration tester from India. He has been a successful participant in various bug bounty programs and has discovered security flaws on websites such as Google, Facebook, Twitter, PayPal, Slack, and many more. He secured the tenth position worldwide in the year 2014 at HackerOne's platform. He is OSCP and OSWP certified, which are some of the most widely respected certifications in the information security industry. He occasionally performs training and security assessment for various government, non-government, and educational organizations.

Table of Contents

  1. Common Security Protocols
  2. Information Gathering
  3. Cross-Site Scripting
  4. Cross-Site Request Forgery
  5. Exploiting SQL Injection
  6. File Upload Vulnerabilities
  7. Metasploit and Web
  8. XML Attacks
  9. Emerging Attack Vectors
  10. OAuth 2.0 Security
  11. API Testing Methodology

商品描述(中文翻譯)

**主要特點**

- 本書涵蓋了當今網路應用程式中涉及的最新技術,如進階 XSS、XSRF、SQL 注入、Web API 測試、XML 攻擊向量、OAuth 2.0 安全等。
- 使用各種技術滲透並保護您的網路應用程式。
- 獲得這本全面的參考指南,提供資深滲透測試人員的進階技巧和行業工具。

**書籍描述**

網路滲透測試是一個不斷增長、快速發展且絕對關鍵的資訊安全領域。本書執行現代網路應用程式攻擊,並利用尖端的駭客技術,增強對網路應用程式安全的知識。

我們將涵蓋網路駭客技術,以便您在滲透測試中探索攻擊向量。本書包含最新技術,如 OAuth 2.0、Web API 測試方法論和駭客使用的 XML 向量。一些較少討論的攻擊向量,如 RPO(相對路徑覆蓋)、DOM 擠壓、PHP 物件注入等,也在本書中有所涵蓋。

我們將深入解釋各種老派技術,如 XSS、CSRF、SQL 注入,通過可靠的 SQLMap 和偵查進行說明。

如今的網站提供 API 以允許與第三方應用程式整合,從而暴露出大量攻擊面,我們將使用實際案例來涵蓋這些 API 的測試。

這本務實的指南將對您大有裨益,幫助您準備完全安全的應用程式。

**您將學到的內容**

- 了解新穎且不太公開的技術,如 PHP 物件注入和基於 XML 的向量。
- 使用不同的安全工具自動化大部分冗餘任務。
- 了解各種新設計的安全標頭及其如何提供安全性。
- 利用和檢測不同類型的 XSS 漏洞。
- 使用過濾機制保護您的網路應用程式。
- 深入理解老派和經典的網路駭客技術,包括 SQL 注入、XSS 和 CSRF。
- 掌握與 XML 相關的漏洞和攻擊向量,如 XXE 和 DoS 技術。
- 了解如何測試 REST API 以發現其中的安全問題。

**關於作者**

**Prakhar Prasad** 是來自印度的網路應用程式安全研究員和滲透測試人員。他在各種漏洞獎勵計畫中表現出色,並在 Google、Facebook、Twitter、PayPal、Slack 等網站上發現了安全缺陷。他在 2014 年於 HackerOne 平台上獲得全球第十名。他擁有 OSCP 和 OSWP 認證,這些是資訊安全行業中最受尊敬的認證之一。他偶爾為各種政府、非政府和教育機構進行培訓和安全評估。

**目錄**

1. 常見安全協議
2. 資訊收集
3. 跨站腳本攻擊
4. 跨站請求偽造
5. 利用 SQL 注入
6. 檔案上傳漏洞
7. Metasploit 和網路
8. XML 攻擊
9. 新興攻擊向量
10. OAuth 2.0 安全
11. API 測試方法論

最後瀏覽商品 (20)