See buying choices for this item to see if it's one of the millions that are eligible for Amazon Prime.

39 used & new from $0.01

Have one to sell? Sell yours here
 
   
Designing Secure Web-Based Applications for Microsoft  Windows  2000 (Dv-Mps Designing)
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get yours here.
 
  

Designing Secure Web-Based Applications for Microsoft Windows 2000 (Dv-Mps Designing) (Paperback)

by Michael Howard (Author)
4.6 out of 5 stars See all reviews (15 customer reviews)


Available from these sellers.


14 new from $3.95 25 used from $0.01

Editorial Reviews

Amazon.com Review
"Web-based applications" is getting to be a redundant term, but that only highlights the fact that up-to-date programmers need to be familiar with the strategies and practices used to build modern networked software. Designing Secure Web-Based Applications for Microsoft Windows 2000 explains precisely what its title specifies: the mechanisms for allowing Windows programs to communicate over the network while maintaining security, plus their ways of fitting into complete product architectures. It's a complete engineering document with considerable information on identifying security threats, giving them relative weight, and deciding how to deal with them in the designs of your systems. The author has both done his homework and worked in the industry, and it's a pleasure to read his distilled knowledge.

Early sections are rather academic (which is not to say they're not worthwhile), while later sections deal with specific security strategies and the security features of particular products. The author isn't vague--he tells you how he thinks you should design your programs (storing hashes, instead of passwords, in a database to allow for intrusion into the database, for example) and what specifically you need to do (there's enough code here to give heft to what otherwise would be purely high-level advice). Although the author sticks to the Microsoft world, he isn't reluctant to point out security problems in Windows. This is a great volume for anyone designing Windows software that will share information over a network and need to use authentication, nonrepudiation, encryption, and other security techniques. --David Wall

Topics covered: Network security features of Windows 2000, Internet Explorer 5.0, SQL Server 7.0, SQL Server 2000, and COM+ 1.0, as well as the engineering tradeoffs involved in making software secure enough for safety, but open enough for reliability.

Product Description
Bullet-proof security is one of the strengths of Microsoft Windows 2000, but until now, no one has presented a complete picture of Windows 2000 Web server, component-level, and database security features and considerations. DESIGNING SECURE WEB-BASED APPLICATIONS FOR MICROSOFT WINDOWS 2000 offers an integrated, authoritative, pragmatic, end-to-end view of Windows 2000 security topics. The book starts by providing a solid foundation in Windows 2000 security theory and concepts, explaining the key software design considerations for various categories and levels of security, and showing how isolated security "islands" interact. It explains core security issues such as risk analysis, threats, authentication, authorization, and privacy, and then discusses ways to apply the appropriate security to an application to mitigate risk. It covers a range of security technologies such as NTLM authentication, Kerberos authentication, SSL/TLS, CryptoAPI, ACLs, Active Directory(tm), Certificates, Web security capabilities, and COM+ security. Finally, the author uses Web services, certificates, components, and database access to build a Web-based application (included on a companion CD) to show how Windows 2000 security features work in concert to protect applications and data.


Product Details

  • Paperback: 450 pages
  • Publisher: Microsoft Press (August 26, 2000)
  • Language: English
  • ISBN-10: 0735609950
  • ISBN-13: 978-0735609952
  • Product Dimensions: 9.2 x 7.4 x 1.4 inches
  • Shipping Weight: 2.3 pounds
  • Average Customer Review: 4.6 out of 5 stars See all reviews (15 customer reviews)
  • Amazon.com Sales Rank: #1,450,478 in Books (See Bestsellers in Books)

Look Inside This Book


Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

15 Reviews
5 star:
 (13)
4 star:    (0)
3 star:
 (1)
2 star:    (0)
1 star:
 (1)
 
 
 
 
 
Average Customer Review
4.6 out of 5 stars (15 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
18 of 18 people found the following review helpful:
5.0 out of 5 stars This is NOT a rehash of Microsoft whitepapers or help files., September 7, 2000
By Jason Fossen (Dallas, Tx) - See all my reviews
This is the best IIS security book I've found yet, and I do Microsoft network security consulting for a living. Most IIS books simply rehash the IIS help files or Resource Kit-- this doesn't. Moreover, IIS 5.0 on Windows 2000 is substantially different than IIS 4.0 on NT, but nobody else I've read tackles the new heavy features like Kerberos authentication, digital certificate mapping to Active Directory, IPsec packet filtering for HTTP, distributed applications with COM+/DCOM, WMI, ADSI, etc.. The CD-ROM is also very useful; for example, it includes a Perl script which will search IIS logs for common attack signatures for intrusion detection. This book is written for security administrators and web-application developers. It has saved me MANY hours of trying to track down IIS 5.0 security internals that might not be documented anywhere else.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
10 of 10 people found the following review helpful:
5.0 out of 5 stars Excellent broad coverage, an easy read., November 25, 2000
By "bruce1055" (Moutain View, CA USA) - See all my reviews
The book covers a great deal of ground very quickly. Importantly, the material is easy to read and useful. While the focus is on Windows 2000-based technology, much of the book (most notably, threat modelling, and practical authentication, authorization, privacy and non-repudiation) can be applied to other non-MS technologies.

The really cool thing I like the most about the book is it is practical, rather then theoretical.

The book gave me ammunition to convince management that they need to spend time/money/resources to insure a secure system, and then the book showed me how to choose appropriate technologies to solve security problems.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
8 of 8 people found the following review helpful:
5.0 out of 5 stars Worth every Penny, November 5, 2000
By Aaron (Berlin, Germany) - See all my reviews
A great source of wisdom if you build or deploy web-sites. Well written, greath depth and most of all - easy to read. There is lots of new information previously unpublished.

It explains how to design, build, and deploy secure systems without resorting to scare-tactics.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars Best book I read on the subject
enjoyable and very informative
Published on February 23, 2003 by JAKUBOVITZ ITZHAK

5.0 out of 5 stars Very beneficial.
I had no background in networking and Windows security. This book allowed me to understand how to employ security in Windows distributed applications. Read more
Published on June 20, 2002

5.0 out of 5 stars The most complete web application security on the market
This book covers all issues pertaining to building and securing web applications. From the browser all the way to the database server. Read more
Published on May 8, 2001 by mike332

5.0 out of 5 stars Exceptional
Incredible security coverage of IIS, Windows 2000, COM+, IE and SQL Server. The best IIS security book out there. But it focuses on other topics, not just IIS.
Published on April 26, 2001 by Pete

1.0 out of 5 stars Worse than nothing
Probably the worse book I've read on IIS security. This is what the books says on setting File security on your web: "use the wizard". Read more
Published on April 23, 2001

3.0 out of 5 stars Great if you're new to MS Security but not enough for others
I was dissapointed with this book because it did not go to the depth a developer would need to make the most of the Windows 2000/NT security technologies. Read more
Published on November 22, 2000

5.0 out of 5 stars It Answered Many Questions!
I have always thought that n-tier security was next to impossible. This books proves it isn't. The book discusses the pros and cons of various ways of building secure n-tier... Read more
Published on October 31, 2000

5.0 out of 5 stars Superb!
The best book I've read regarding web security. Covers a lot of ground, quickly and logically. I didn't realise there was so much to learn. Read more
Published on October 31, 2000

5.0 out of 5 stars Superb!
Simply put - I learned more about security from this book than any other book I have previously read. Read more
Published on October 23, 2000 by harryw@earthlink.net

5.0 out of 5 stars EXCELLENT-Highly Recommended
I've read many books about computer and network security, and this blows away all of them. It's easy to read, extremeley pragmatic and, as far as I know, it is the ONLY BOOK that... Read more
Published on October 11, 2000 by MarkR

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]

   


Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Up to 50% Off Chocolates

Leonidas Chocolates Sale
Save up to 50% on gourmet chocolates from Ghirardelli, Godiva, Leonidas Belgian Chocolates, and more from Amazon Gourmet.
 

Best Books of 2008

Best of 2008
Find our top 100 editors' picks as well as customers' favorites in dozens of categories in our Best Books of 2008 Store.
 

Summer Reading for Kids & Teens

Summer Reading for Kids and Teens
Discover everything from beach reads and board books to teen romance and action-adventure series in Summer Reading for Kids & Teens. And, check off the kids' required reading lists in our Summer School Reading Store.
 

Keep Your Temperature Under Control

Shop for Thermostats
Make sure the temperature is regulated in your home with a reliable thermostat.

Shop all thermostats

 

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.



Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Glenn Beck's Common Sense
Glenn Beck's Common Sense
Darkfever
Darkfever by Karen Marie Moning
The Adventures of Sherlock Holmes
The Adventures of Sherlock Holmes by Arthur Conan, Sir, 1859-1930 Doyle

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates