Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions

Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions

作者: Rich Cannings Himanshu Dwivedi Zane Lackey
出版社: McGraw-Hill Education
出版在: 2008-01-07
ISBN-13: 9780071494618
ISBN-10: 0071494618
裝訂格式: Paperback
總頁數: 258 頁





內容描述


Description 

Lock down next-generation Web services
"This book concisely identifies the types of attacks which are faced daily
by Web 2.0 sites, and the authors give solid, practical advice on how to
identify and mitigate these threats." --Max Kelly, CISSP, CIPP, CFCE, Senior
Director of Security, Facebook
Protect your Web 2.0 architecture against the latest wave of cybercrime
using expert tactics from Internet security professionals. Hacking Exposed
Web 2.0 shows how hackers perform reconnaissance, choose their entry
point, and attack Web 2.0-based services, and reveals detailed countermeasures
and defense techniques. You'll learn how to avoid injection and buffer
overflow attacks, fix browser and plug-in flaws, and secure AJAX, Flash, and
XML-driven applications. Real-world case studies illustrate social networking
site weaknesses, cross-site attack methods, migration vulnerabilities, and IE7
shortcomings.

Plug security holes in Web 2.0 implementations the proven Hacking
Exposed way
Learn how hackers target and abuse vulnerable Web 2.0 applications,
browsers, plug-ins, online databases, user inputs, and HTML forms
Prevent Web 2.0-based SQL, XPath, XQuery, LDAP, and command injection
attacks
Circumvent XXE, directory traversal, and buffer overflow exploits
Learn XSS and Cross-Site Request Forgery methods attackers use to bypass
browser security controls
Fix vulnerabilities in Outlook Express and Acrobat Reader add-ons
Use input validators and XML classes to reinforce ASP and .NET security
Eliminate unintentional exposures in ASP.NET AJAX (Atlas), Direct Web
Remoting, Sajax, and GWT Web applications
Mitigate ActiveX security exposures using SiteLock, code signing, and
secure controls

Find and fix Adobe Flash vulnerabilities
and DNS rebinding attacks 

Table of Contents

Foreword Acknowledgments Introduction Part I: Attacking Web 2.0
Chapter 1. Common Injection Attacks Chapter 2. Cross-Site Scripting
Part II: Next Generation Web Application Attacks Chapter 3.
Cross-Domain Attacks Chapter 4. Malicious JavaScript and AJAX Chapter

  1. .Net Security Part III: AJAX Chapter 6. AJAX Types, Discovery, and
    Parameter Manipulation Chapter 7. AJAX Framework Exposures Part IV:
    Thick Clients Chapter 8. ActiveX Security Chapter 9. Attacking Flash
    Applications
    Index



相關書籍

力抗暗黑:Azure 資安天使的逆襲(iT邦幫忙鐵人賽系列書)

作者 葛明淞

2008-01-07

Security Design Consulting: The Business of Security System Design

作者 Brian Gouin

2008-01-07

Web 應用系統安全|現代 Web 應用程式開發的資安對策 (Web Application Security)

作者 Andrew Hoffman 江湖海 譯

2008-01-07