Product Description
Now you can benefit from the many lessons Microsoft has learned about testing Web applications for security bugs. A must-have reference for every Web developer and tester, this book presents a comprehensive, structured methodology for identifying and addressing the most common, real-world security issues for Web applications throughout the development process. Written by the principal, front-line Web security assessment team at Microsoft, this guide walks you through each of the critical stages for effective security testing, including designing for and assessing security features; identifying security vulnerabilities and executing the assessment; and enhancing infrastructure security before application deployment, including best practices for locking down Microsoft® Windows Server 2003, Microsoft Internet Information Services (IIS), and Microsoft SQL Server. Get the entire books sample code via the Weband easily apply this expert author teams techniques and tools to your own programs.
About the Author
Irfan A. Chaudry, Justin Clarke, Shawn Veney, Eric Rachner, Jessika Sutton, and Tony Dang: This team is the designated authority on Web application attack and penetration testing within Microsoft. It is responsible for helping ensure the security of business applications produced by Microsoft.







