Professional Pen 测试 Professional Pen Testing for Web Applications 下载 pdf 百度网盘 epub 免费 2025 电子书 mobi 在线

Professional Pen 测试 Professional Pen Testing for Web Applications 精美图片
》Professional Pen 测试 Professional Pen Testing for Web Applications 电子书籍版权问题 请点击这里查看《

Professional Pen 测试 Professional Pen Testing for Web Applications 书籍详细信息

  • ISBN:9780471789666
  • 作者:暂无作者
  • 出版社:暂无出版社
  • 出版时间:2006-12
  • 页数:522
  • 价格:317.70
  • 纸张:胶版纸
  • 装帧:平装
  • 开本:暂无开本
  • 语言:未知
  • 丛书:暂无丛书
  • TAG:暂无
  • 豆瓣评分:暂无豆瓣评分
  • 豆瓣短评:点击查看
  • 豆瓣讨论:点击查看
  • 豆瓣目录:点击查看
  • 读书笔记:点击查看
  • 原文摘录:点击查看
  • 更新时间:2025-01-20 18:21:05

内容简介:

  There is no such thing as "perfect security" when it comes to keeping all systems intact and functioning properly. Good penetration (pen) testing creates a balance that allows a system to be secure while simultaneously being fully functional. With this book, you'll learn how to become an effective penetrator (i.e., a white hat or ethical hacker) in order to circumvent the security features of a Web application so that those features can be accurately evaluated and adequate security precautions can be put in place.

After a review of the basics of web applications, you'll be introduced to web application hacking concepts and techniques such as vulnerability analysis, attack simulation, results analysis, manuals, source code, and circuit diagrams. These web application hacking concepts and techniques will prove useful information for ultimately securing the resources that need your protection.

What you will learn from this book

* Surveillance techniques that an attacker uses when targeting a system for a strike

* Various types of issues that exist within the modern day web application space

* How to audit web services in order to assess areas of risk and exposure

* How to analyze your results and translate them into documentation that is useful for remediation

* Techniques for pen-testing trials to practice before a live project

Who this book is for

This book is for programmers, developers, and information security professionals who want to become familiar with web application security and how to audit it.

Wrox Professional guides are planned and written by working programmers to meet the real-world needs of programmers, developers, and IT professionals. Focused and relevant, they address the issues technology professionals face every day. They provide examples, practical solutions, and expert education in new technologies, all designed to help programmers do a better job.


书籍目录:

Acknowledgments.

Introduction.

Chapter 1: Penetration Testing Web Applications.

Chapter 2: Web Applications: Some Basics.

Chapter 3: Discovery.

Chapter 4: Vulnerability Analysis.

Chapter 5: Attack Simulation Techniques and Tools: Web Server.

Chapter 6: Attack Simulation Techniques and Tools: Web Application.

Chapter 7: Attack Simulation Techniques and Tools: Known Exploits.

Chapter 8: Attack Simulation Techniques and Tools: Web Services.

Chapter 9: Documentation and Presentation.

Chapter 10: Remediation.

Chapter 11: Your Lab.

Appendix A: Basic SQL.

Appendix B: Basic LDAP.

Appendix C: XPath and XQuery.

Appendix D: Injection Attack Dictionaries.

Index.


作者介绍:

暂无相关内容,正在全力查找中


出版社信息:

暂无出版社相关信息,正在全力查找中!


书籍摘录:

暂无相关书籍摘录,正在全力查找中!



原文赏析:

暂无原文赏析,正在全力查找中!


其它内容:

编辑推荐

作者简介:

Andres Andreu, CISSP-ISSAP, GSEC currently operates neuroFuzz Application Security LLC (http://www.neurofuzz.com), and has a strong background with the U.S. government. He served the United States of America in Information Technology and Security capacities within a “3-Letter” federal law enforcement agency. The bulk of his time there was spent building the IT Infrastructure and working on numerous intelligence software programs for one of the largest Title III Interception Operations within the continental U.S. He worked there for a decade and during that time he was the recipient of numerous agency awards for outstanding performance.

  He holds a bachelor’s degree in Computer Science, graduating Summa Cum Laude with a 3.9 GPA from the American College of Computer and Informational Sciences. Mr. Andreu specializes in software, application, and Web services security, working with XML security, TCP and HTTP(S) level proxying technology, and strong encryption. He has many years of experience with technologies like LDAP, Web services (SOA, SOAP, and so on), enterprise applications, and application integration.


书籍介绍

There is no such thing as "perfect security" when it comes to keeping all systems intact and functioning properly. Good penetration (pen) testing creates a balance that allows a system to be secure while simultaneously being fully functional. With this book, you'll learn how to become an effective penetrator (i.e., a white hat or ethical hacker) in order to circumvent the security features of a Web application so that those features can be accurately evaluated and adequate security precautions can be put in place.

After a review of the basics of web applications, you'll be introduced to web application hacking concepts and techniques such as vulnerability analysis, attack simulation, results analysis, manuals, source code, and circuit diagrams. These web application hacking concepts and techniques will prove useful information for ultimately securing the resources that need your protection.

What you will learn from this book

* Surveillance techniques that an attacker uses when targeting a system for a strike

* Various types of issues that exist within the modern day web application space

* How to audit web services in order to assess areas of risk and exposure

* How to analyze your results and translate them into documentation that is useful for remediation

* Techniques for pen-testing trials to practice before a live project

Who this book is for

This book is for programmers, developers, and information security professionals who want to become familiar with web application security and how to audit it.

Wrox Professional guides are planned and written by working programmers to meet the real-world needs of programmers, developers, and IT professionals. Focused and relevant, they address the issues technology professionals face every day. They provide examples, practical solutions, and expert education in new technologies, all designed to help programmers do a better job.


书籍真实打分

  • 故事情节:5分

  • 人物塑造:9分

  • 主题深度:5分

  • 文字风格:3分

  • 语言运用:9分

  • 文笔流畅:8分

  • 思想传递:3分

  • 知识深度:5分

  • 知识广度:9分

  • 实用性:5分

  • 章节划分:4分

  • 结构布局:6分

  • 新颖与独特:5分

  • 情感共鸣:6分

  • 引人入胜:8分

  • 现实相关:3分

  • 沉浸感:6分

  • 事实准确性:3分

  • 文化贡献:6分


网站评分

  • 书籍多样性:9分

  • 书籍信息完全性:7分

  • 网站更新速度:6分

  • 使用便利性:7分

  • 书籍清晰度:3分

  • 书籍格式兼容性:3分

  • 是否包含广告:7分

  • 加载速度:5分

  • 安全性:4分

  • 稳定性:4分

  • 搜索功能:4分

  • 下载便捷性:3分


下载点评

  • 排版满分(327+)
  • 差评少(444+)
  • 中评(59+)
  • 值得下载(260+)
  • 藏书馆(348+)
  • 体验好(302+)
  • 可以购买(399+)

下载评价

  • 网友 仰***兰: ( 2025-01-15 02:05:52 )

    喜欢!很棒!!超级推荐!

  • 网友 石***烟: ( 2024-12-24 01:19:34 )

    还可以吧,毕竟也是要成本的,付费应该的,更何况下载速度还挺快的

  • 网友 权***颜: ( 2025-01-06 10:21:04 )

    下载地址、格式选择、下载方式都还挺多的

  • 网友 常***翠: ( 2024-12-21 21:10:56 )

    哈哈哈哈哈哈

  • 网友 印***文: ( 2025-01-07 17:52:40 )

    我很喜欢这种风格样式。

  • 网友 宫***凡: ( 2025-01-19 14:12:25 )

    一般般,只能说收费的比免费的强不少。

  • 网友 谭***然: ( 2025-01-02 04:06:02 )

    如果不要钱就好了

  • 网友 邱***洋: ( 2025-01-03 12:53:48 )

    不错,支持的格式很多

  • 网友 寿***芳: ( 2024-12-22 16:22:27 )

    可以在线转化哦

  • 网友 汪***豪: ( 2024-12-31 11:59:02 )

    太棒了,我想要azw3的都有呀!!!

  • 网友 饶***丽: ( 2024-12-20 19:36:06 )

    下载方式特简单,一直点就好了。

  • 网友 曾***文: ( 2025-01-18 04:58:57 )

    五星好评哦

  • 网友 辛***玮: ( 2024-12-21 05:01:09 )

    页面不错 整体风格喜欢


随机推荐