Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
65 used & new from $0.65

Have one to sell? Sell yours here
 
   
Web Hacking: Attacks and Defense
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get yours here.
 
  

Web Hacking: Attacks and Defense (Paperback)

by Stuart McClure (Author), Saumil Shah (Author), Shreeraj Shah (Author)
4.5 out of 5 stars See all reviews (13 customer reviews)

List Price: $49.99
Price: $34.21 & this item ships for FREE with Super Saver Shipping. Details
You Save: $15.78 (32%)
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Thursday, July 16? Choose One-Day Shipping at checkout. Details
21 new from $15.69 44 used from $0.65

Frequently Bought Together

Customers buy this book with Web Security for Network and System Administrators by David Mackey

Web Hacking: Attacks and Defense + Web Security for Network and System Administrators
Price For Both: $145.16

Show availability and shipping details

  • This item: Web Hacking: Attacks and Defense by Stuart McClure

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Web Security for Network and System Administrators by David Mackey

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details


Customers Who Bought This Item Also Bought

Guide to Computer Forensics and Investigations

Guide to Computer Forensics and Investigations

by Bill Nelson
3.8 out of 5 stars (6)  $64.23
HackNotes(tm) Web Security Pocket Reference

HackNotes(tm) Web Security Pocket Reference

by Mike Shema
4.2 out of 5 stars (5)  $26.99
Hacking: The Art of Exploitation, 2nd Edition

Hacking: The Art of Exploitation, 2nd Edition

by Jon Erickson
4.3 out of 5 stars (56)  $32.97
The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws

The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws

by Dafydd Stuttard
4.9 out of 5 stars (14)  $31.50
CISSP Certification All-in-One Exam Guide, Fourth Edition

CISSP Certification All-in-One Exam Guide, Fourth Edition

by Shon Harris
4.2 out of 5 stars (31)  $50.39
Explore similar items

Editorial Reviews

Product Description
Exposes complete methodologies showing the actual techniques and attacks. Shows countermeasures, tools, and eye-opening case studies. Covers the web commerce playground, describing web languages and protocols, web and database servers, and payment systems. Softcover.

From the Back Cover
"Both novice and seasoned readers will come away with an increased understanding of how Web hacking occurs and enhanced skill at developing defenses against such Web attacks. Technologies covered include Web languages and protocols, Web and database servers, payment systems and shopping carts, and critical vulnerabilities associated with URLs. This book is a virtual battle plan that will help you identify and eliminate threats that could take your Web site off line..."
--From the Foreword by William C. Boni, Chief Information Security Officer, Motorola"Just because you have a firewall and IDS sensor does not mean you aresecure; this book shows you why."
--Lance Spitzner, Founder, The Honeynet ProjectWhether it's petty defacing or full-scale cyber robbery, hackers are moving to the Web along with everyone else. Organizations using Web-based business applications are increasingly at risk. Web Hacking: Attacks and Defense is a powerful guide to the latest information on Web attacks and defense. Security experts Stuart McClure (lead author of Hacking Exposed), Saumil Shah, and Shreeraj Shah present a broad range of Web attacks and defense.

Features include:

  • Overview of the Web and what hackers go after
  • Complete Web application security methodologies
  • Detailed analysis of hack techniques
  • Countermeasures
  • What to do at development time to eliminate vulnerabilities
  • New case studies and eye-opening attack scenarios
  • Advanced Web hacking concepts, methodologies, and tools

"How Do They Do It?" sections show how and why different attacks succeed, including:

  • Cyber graffiti and Web site defacements
  • e-Shoplifting
  • Database access and Web applications
  • Java™ application servers; how to harden your Java™ Web Server
  • Impersonation and session hijacking
  • Buffer overflows, the most wicked of attacks
  • Automated attack tools and worms

Appendices include a listing of Web and database ports, cheat sheets for remote command execution, and source code disclosure techniques.

Web Hacking informs from the trenches. Experts show you how to connect the dots--how to put the stages of a Web hack together so you can best defend against them. Written for maximum brain absorption with unparalleled technical content and battle-tested analysis, Web Hacking will help you combat potentially costly security threats and attacks.



0201761769B07192002

See all Editorial Reviews

Product Details

  • Paperback: 528 pages
  • Publisher: Addison-Wesley Professional (August 18, 2002)
  • Language: English
  • ISBN-10: 0201761769
  • ISBN-13: 978-0201761764
  • Product Dimensions: 8.9 x 7.4 x 1.3 inches
  • Shipping Weight: 2 pounds (View shipping rates and policies)
  • Average Customer Review: 4.5 out of 5 stars See all reviews (13 customer reviews)
  • Amazon.com Sales Rank: #664,238 in Books (See Bestsellers in Books)

Look Inside This Book


What Do Customers Ultimately Buy After Viewing This Item?


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
Check the boxes next to the tags you consider relevant or enter your own tags in the field below.

Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

13 Reviews
5 star:
 (8)
4 star:
 (4)
3 star:
 (1)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.5 out of 5 stars (13 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
29 of 30 people found the following review helpful:
5.0 out of 5 stars Eclectic, September 28, 2002
By Marco De Vivo "mata-hackers" (Miami, Florida United States) - See all my reviews
(REAL NAME)   
So you heard all this hype on Web Hacking, and want to know more about this matter.

Well, if you think about the web as an e-commerce platform, then just Buy 'Web Security, Privacy & Commerce' by Garfinkel and Spafford, an excellent and classic book.

Are you interested in 'pure hacking'? I mean 'perl scripts', cross site and traversal attacks, hackers jargon, and all the related issues..... then buy 'Hacking Web Applications Exposed' by Scambray and Shema. Excellent book too, and excellent authors. But beware, it is not for newbies. You MUST have a lot of background to fully understand the attacks.

Now, what about an easier generic book, covering the same issues as the others but in a step by step and kinder way.? A book to start from zero, but leading to understand all the currently related themes. Well, if this is what you want, then 'Web Hacking' is your book. It covers all that need to be covered in this area. In an easy and well structured way. The reading is very light and the authors 'break down' of the matter, makes the contents very intuitive.

The book is structured into four main sections (covering the same areas as the previously referred books) :

** The E-commerce Playground
** URLs Unraveled
** How Do They Do It?
** Advanced Web Kung Fu

It includes also, several interesting appendixes (specially useful the 'cheat sheet' appendix).

A lot of simple case studies (of the kind 'Bob and Alice') are presented as well as some more technical analyses (Code Red, Nimda etc.)

If I were to select a book as a reference for a first course on web security, 'Web Hacking' would be my choise. Definitively.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
16 of 17 people found the following review helpful:
5.0 out of 5 stars Excellent, a _must_ read, August 20, 2002
By "nit_d" (Seattle, WA USA) - See all my reviews
This book has a wealth of information on the subject of Web Hacking. As an administrator responsible for the well-being of various web servers, it is important for me to keep up with the vulnerabilities and know the tactics of crackers, and this book filled me in with more than enough knowledge.

The book starts out with good introduction on the topic of web languages, and leads you to various topics such as finding and exploiting buffer overflows. There is a _lot_ of ground covered in this book including databases, cracking tools, SQL code injection, countermeasures, etc.

If you are responsible for any host sitting on the internet, this is your bible.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
11 of 11 people found the following review helpful:
5.0 out of 5 stars Grab a cup of joe curl up in a comfy place and get ready f, August 28, 2002
By Robin Carver "robin@greatheartbouv.com" (Newmarket, Ontario, Canada) - See all my reviews
Web Hacking, Attacks and Defense by Stuart McClure, Saumil Shah and Shreeraj Shah is an excellent introductory level book to the world of web hacking. If you are a seasoned professional you will also enjoy having this book in your collection, as it is an excellent resource book.

Ever wonder how anyone can enter a web site and see more than what's presented? With a clear understanding of the protocols, web languages, an understanding of the processes behind e commerce and a bit of historical knowledge you too can hack a web site, and wind up on the FBI's most wanted list. But by the same token, a little bit of knowledge is a powerful thing, with the information presented here you can easily get started on the road to keeping the hackers out, and damage to a minimum if they do get in.

The chapters are clearly laid out, and include code with explanations of the weaknesses, referrals to more in depth study, precautionary measures you can take to help secure your site and a look at the various tools available to harden your site.

IIS and Apache are reviewed, along with Oracle and SQL Server to show some of the more popular Web Servers and Databases, how they work, are exploited and ways to harden them against attack. The protocols used by the web, web programming languages, and an explanation of how a browser interprets commands are graphically laid out with examples presented. It would be hard to come away from this book with out an understanding of the concepts, as they are so clearly defined.

Everything from setting a common understanding of terms to basic E Commerce concepts to unraveling Code Red and a truly unique presentation of IDS (Intrusion Detection Systems) is presented and well worth the time it takes to read.

Enjoy!

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars Great Book for Web Developers or Administrators
This book is great if you develop websites, especially if you maintain a webserver. I am fairly well versed on basic security measures, but there was alot of stuff in this book... Read more
Published on April 2, 2005 by Robert Spellings Jr.

5.0 out of 5 stars Excellent
This book is an excellent start. While you can find alot of usefull hacking material on the web, this book gives it to you well organized.
Published on September 13, 2004 by E. Krinker

3.0 out of 5 stars Rehash of basic web technologies
I was disappointed in what this book had to offer. I was hoping for a full text of web exploits and how to defend against them. Read more
Published on August 5, 2004 by G. F Robison

5.0 out of 5 stars If you are responsible for a web site, get this book
This no-fluff book weighs in at just under 500 pages that are guaranteed to quell any feelings of complacency you may have about the safety of your website. Read more
Published on March 28, 2004 by Stephen Northcutt

4.0 out of 5 stars Good Overview Of Attacks & Defense
This is a pretty informative book on hacking. After reading this book you will have a good overview of many different attacks and defenses. Read more
Published on October 12, 2003

4.0 out of 5 stars Excellent book on web security
Web Hacking: Attacks and Defense is quite similar to `Hacking Exposed Web Applications' by Joel Scambray & Mike Shema. Read more
Published on November 24, 2002 by Ben Rothke

4.0 out of 5 stars Case-based approach brings web hacking to the masses
"Web Hacking: Attacks and Defenses" is a book the shows how, and in some cases why, web platforms are compromised. Read more
Published on November 17, 2002 by Richard Bejtlich

5.0 out of 5 stars Hacking - Readers Are Shown How It's Done!
During the last several years we have seen a sharp rise in the number of methods employed to hack into computer systems worldwide. Read more
Published on September 20, 2002 by Jim Moran

4.0 out of 5 stars Entertaining and educational
Web services infrastructure for electronic commerce. So hard to built,
even harder to secure. With this great book, it is sooo easy to
subvert, destroy, corrupt and... Read more
Published on September 3, 2002 by Dr Anton Chuvakin

5.0 out of 5 stars Engrossing, thorough and full of surprises
Although this book's primary purpose is to explain how to defend against web hacking, it's also one of the most thorough descriptions of how web servers, applications servers and... Read more
Published on August 25, 2002 by Mike Tarrani

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]


Active discussions in related forums
   


Product Information from the Amapedia Community

Beta (What's this?)


So You'd Like to...


Look for Similar Items by Category


Don't Slip and Slide

HeatTrak Heated Walkway

Keep your walkways safe and clear of snow and ice using the HeatTrak heated walkway.

Shop all HeatTrak heated walkways

 

Big Savings in Books

Bargain Books
Find great titles at fantastic prices in our Bargain Books Store.
 

Dive into Summer Reading

Summer Reading for Kids and Teens
Don't even think about hitting the beach without browsing the books in our Summer Reading Store. Discover bestsellers, paperback picks, beach reads, and more terrific titles all summer long.
 

Set the Tone of Your Bathroom

Shop for bathroom vanities
If you want to transform your bathroom, a unique bathroom vanity will complete your look.

Shop for bathroom vanities

 

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Paranoia
Paranoia by Joseph Finder
My Soul to Lose
My Soul to Lose by Rachel Vincent
Glenn Beck's Common Sense
Glenn Beck's Common Sense

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates