Amazon.com: SQL Injection Attacks and Defense (9781597494243): Justin Clarke: Books

Buy New

or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
Kindle Edition
Read instantly on your iPad, PC or Mac, no Kindle required
Buy Price: $43.16
Rent From: $22.01
 
 
 
Buy Used
Used - Good See details
$29.87 & this item ships for FREE with Super Saver Shipping. Details

or
Sign in to turn on 1-Click ordering.
 
   
Sell Back Your Copy
For a $14.29 Gift Card
Trade in
More Buying Choices
Have one to sell? Sell yours here
SQL Injection Attacks and Defense
 
 

SQL Injection Attacks and Defense [Paperback]

Justin Clarke (Author)
4.8 out of 5 stars  See all reviews (12 customer reviews)

List Price: $59.95
Price: $47.96 & this item ships for FREE with Super Saver Shipping. Details
You Save: $11.99 (20%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Want it delivered Friday, February 24? Choose One-Day Shipping at checkout. Details
Textbook Student FREE Two-Day Shipping for students on millions of items. Learn more

Formats

Amazon Price New from Used from
 
Kindle Edition
Rent from
$43.16
$22.01
 
Paperback $47.96  
Sell Back Your Copy for $14.29
Whether you buy it used on Amazon for $29.87 or somewhere else, you can sell it back through our Book Trade-In Program at the current price of $14.29.
Used Price$29.87
Trade-in Price$14.29
Price after
Trade-in
$15.58

Book Description

May 15, 2009 1597494240 978-1597494243 1st

Winner of the Best Book Bejtlich Read in 2009 award!

"SQL injection is probably the number one problem for any server-side application, and this book is unequaled in its coverage." Richard Bejtlich, http://taosecurity.blogspot.com/

SQL injection represents one of the most dangerous and well-known, yet misunderstood, security vulnerabilities on the Internet, largely because there is no central repository of information to turn to for help. This is the only book devoted exclusively to this long-established but recently growing threat. It includes all the currently known information about these attacks and significant insight from its contributing team of SQL injection experts.

  • What is SQL injection?-Understand what it is and how it works

  • Find, confirm, and automate SQL injection discovery

  • Discover tips and tricks for finding SQL injection within the code

  • Create exploits using SQL injection

  • Design to avoid the dangers of these attacks

  • Frequently Bought Together

    SQL Injection Attacks and Defense + The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws + Metasploit: The Penetration Tester's Guide
    Price For All Three: $106.70

    Show availability and shipping details

    Buy the selected items together
    • In Stock.
      Ships from and sold by Amazon.com.
      This item ships for FREE with Super Saver Shipping. Details

    • The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws $31.50

      In Stock.
      Ships from and sold by Amazon.com.
      This item ships for FREE with Super Saver Shipping. Details

    • Metasploit: The Penetration Tester's Guide $27.24

      In Stock.
      Ships from and sold by Amazon.com.
      This item ships for FREE with Super Saver Shipping. Details



    Editorial Reviews

    Review

    "With SQL Injection Attacks and Defense penetration testers now have a resource to fill in the gaps between all of the scattered tutorials on the Internet. Learn to recognize and take advantage of SQL injection flaws of all varieties on all platforms."--Devon Kearns, IS Security Analyst

    From the Back Cover

    SQL injection represents one of the most dangerous and well-known, yet misunderstood, security vulnerabilities on the Internet, largely because there is no central repository of information to turn to for help. This is the only book devoted exclusively to this long-established but recently growing threat. It includes all the currently known information about these attacks and significant insight from its contributing team of SQL injection experts.

    • What is SQL injection?-Understand what it is and how it works
    • Find, confirm, and automate SQL injection discovery
    • Discover tips and tricks for finding SQL injection within the code
    • Create exploits using SQL injection
    • Design to avoid the dangers of these attacks

    Product Details

    • Paperback: 474 pages
    • Publisher: Syngress; 1st edition (May 15, 2009)
    • Language: English
    • ISBN-10: 1597494240
    • ISBN-13: 978-1597494243
    • Product Dimensions: 8.9 x 7.4 x 1.2 inches
    • Shipping Weight: 2.1 pounds (View shipping rates and policies)
    • Average Customer Review: 4.8 out of 5 stars  See all reviews (12 customer reviews)
    • Amazon Best Sellers Rank: #47,249 in Books (See Top 100 in Books)

    More About the Author

    Justin Clarke is a co-founder and Director at Gotham Digital Science, based in the United Kingdom. He has over twelve years of experience in assessing the security of networks, web applications, and wireless networks for large financial, retail, technology and government clients in the United States, the United Kingdom and New Zealand.

    Justin is the the technical editor and lead author of "SQL Injection Attacks and Defense" (Syngress 2009), co-author of "Network Security Tools: Writing, Hacking, and Modifying Security Tools" (O'Reilly 2005), a contributing author to "Network Security Assessment: Know Your Network, 2nd Edition" (O'Reilly 2007), as well as a speaker at a number of conferences and events on security topics, including Black Hat USA, EuSecWest, OSCON, ISACA, RSA, SANS, OWASP, and the British Computer Society. He is the author of the open source SQLBrute blind SQL injection testing tool, and is the Chapter Leader for the London chapter of OWASP.

     

    Customer Reviews

    12 Reviews
    5 star:
     (11)
    4 star:    (0)
    3 star:
     (1)
    2 star:    (0)
    1 star:    (0)
     
     
     
     
     
    Average Customer Review
    4.8 out of 5 stars (12 customer reviews)
     
     
     
     
    Share your thoughts with other customers:
    Most Helpful Customer Reviews

    12 of 12 people found the following review helpful:
    5.0 out of 5 stars Finally, the "Bible" for SQL Injection, May 27, 2009
    By 
    Mike (Long Island, NY USA) - See all my reviews
    This review is from: SQL Injection Attacks and Defense (Paperback)
    I'm giving "SQL Injection Attacks and Defenses" five stars for a few reasons.

    First, the book is extremely comprehensive, covering everything from basic "What is SQL Injection?" information to advanced exploit development and static analysis tools (including open source tools).

    Second, this book was obviously written very recently. The content is fresh and cutting-edge.

    Finally, the book is advanced. Though the reader doesn't necessarily need to know much about SQL Injection in order to start reading it, the book covers as much as anyone would need to know about the subject.

    SQL Injection Attacks and Defenses is a well written, comprehensive book that can be extremely useful to security professionals, developers, and database administrators interested in writing or maintaining secure code. It could easily be called the "bible" of SQL Injection.
    Help other customers find the most helpful reviews 
    Was this review helpful to you? Yes No


    6 of 6 people found the following review helpful:
    5.0 out of 5 stars Another serious contender for Best Book Bejtlich Read 2009, October 24, 2009
    This review is from: SQL Injection Attacks and Defense (Paperback)
    I just finished reviewing The Web Application Hacker's Handbook, calling it a "Serious candidate for Best Book Bejtlich Read
    2009." SQL Injection Attacks and Defense (SIAAD) is another serious contender for BBBR09. In fact, I recommend reading TWAHH first because it is a more comprehensive overview of Web application security. Next, read SIAAD as the definitive treatise on SQL injection. Syngress does not have a good track record when it comes to books with multiple authors -- SIAAD has ten! -- but SIAAD is clearly a winner.

    SIAAD is very detailed, with code samples to demonstrate the author's attack patterns. They cover multiple programming languages, multiple databases, and flood the book with examples. It's clear the authors utilize these methods for their daily work. Just about every situation is addressed, like returning database query results using DNS, HTTP, database connections, and even email. I admit I laughed when reading that chapter 7 offered "advanced topics." I thought the first 6 chapters were advanced enough, given the depth of the material!

    I had no real issues with this book, but it's important to realize you won't read about attacks against PostgreSQL, for example. Other reviewers noted this as well. However, the authors do concentrate on the methodology and offensive mindset needed to attack any SQL database. I believe dedicated readers could apply the lessons of SIAAD to products beyond MS-SQL, Oracle, and MySQL.

    Great work -- this is the sort of "niche book" that should be referenced by anyone else who wants to cover Web-related attacks.
    Help other customers find the most helpful reviews 
    Was this review helpful to you? Yes No


    4 of 4 people found the following review helpful:
    5.0 out of 5 stars Tour de Force Coverage of SQL Injection Issues, July 24, 2009
    This review is from: SQL Injection Attacks and Defense (Paperback)
    This is a book that I can heartily endorse. My bailiwick, and probably yours too if you are looking here, is data management and database administration. And if you function within that realm, you should be familiar with SQL injection attacks and how to defend them. Not surprisingly, given its title, that is just what this book provides.

    SQL injection is quite dangerous, and yet is commonly misunderstood by many. This book, which is devoted exclusively to the SQL injection threat and how to defend against it, provides the knowledge and tactics you will need to understand and combat SQL injection attacks.

    From the basics of vulnerability to discovery, exploitation, prevention, and mitigation measures, the book is a SQL injection tour de force. The book is up-to-date and covers unique, publicly unavailable information. One quick example of a a major benefit of this book: you can make the code level and platform level defenses offered in Chapters 8 and 9 can available to the developers and system administrators responsible for Internet development at your shop... which should minimize the risk of SQL injection attacks.

    If you are a DBA, programmer, or system analyst involved in writing Internet applications using database systems, then you owe it to yourself to buy and read SQL Injection Attacks and Defense. It just may save your data!
    Help other customers find the most helpful reviews 
    Was this review helpful to you? Yes No

    Share your thoughts with other customers: Create your own review
     
     
     
    Most Recent Customer Reviews










    Only search this product's reviews



    Inside This Book (learn more)
    Browse Sample Pages:
    Front Cover | Table of Contents | First Pages | Index | Surprise Me!
    Search Inside This Book:


    Tags Customers Associate with This Product

     (What's this?)
    Click on a tag to find related items, discussions, and people.
     
    (2)
    (2)

    Your tags: Add your first tag
     

    Customer Discussions

    This product's forum
    Discussion Replies Latest Post
    No discussions yet

    Ask questions, Share opinions, Gain insight
    Start a new discussion
    Topic:
    First post:
    Prompts for sign-in
     


    Active discussions in related forums
    Search Customer Discussions
    Search all Amazon discussions
       
    Related forums





    Look for Similar Items by Category


    Look for Similar Items by Subject