This item is not eligible for Amazon Prime, but millions of other items are. Join Amazon Prime today. Already a member? Sign in.


Digital Delivery
(How does this work?)
 

Hack Proofing Your Web Applications: The Only Way to Stop a Hacker Is to Think Like One
 
 

Hack Proofing Your Web Applications: The Only Way to Stop a Hacker Is to Think Like One [DOWNLOAD: PDF] (Digital)

by Syngress (Author)
Key Phrases: code grinder, keystore file, mobile code attacks, Frequently Asked Questions, Internet Explorer, Visual Basic (more...)
3.0 out of 5 stars See all reviews (3 customer reviews)

List Price: $49.95
Price: $49.95
Available for download now.
Ships from and sold by Amazon.com.

Edition: e-document (Learn more)
Also Available in: List Price: Our Price: Other Offers:
Kindle Edition (Kindle Book) $39.96
Paperback (Illustrated) 21 used & new from $0.31

Customers Who Bought This Item Also Bought

Wireless Hacking: Projects for Wi-Fi Enthusiasts

Wireless Hacking: Projects for Wi-Fi Enthusiasts

by Lee Barken
3.2 out of 5 stars (4)  $29.54
eBay Secrets: How to create Internet auction listings that make 30% more money while selling every item you list

eBay Secrets: How to create Internet auction listings that make 30% more money while selling every item you list

by Steven Ellis White
4.4 out of 5 stars (71)  $7.77
Hacking the Code: ASP.NET Web Application Security

Hacking the Code: ASP.NET Web Application Security

by Mark Burnett
4.4 out of 5 stars (10)  $36.68
Penetration Tester's Open Source Toolkit

Penetration Tester's Open Source Toolkit

by Jay Beale
Explore similar items

Editorial Reviews

Product Description
As a developer, the best possible way to focus on security is to begin to think like a hacker. Examine the methods that hackers use to break into and attack Web sites and use that knowledge to prevent attacks. You already test your code for functionality; one step further is to test it for security—attempt to break into it by finding some hole that you may have unintentionally left in.

About the Author
Julie Traxler is a Senior Software Tester for an Internet software company. During her career, Julie has worked for such organizations as DecisionOne, EXE Technologies, and TV Guide. She has held several positions including Project Manager, Business Analyst, and Technical Writer and has specialized in software systems analysis and design. During her tenure at several organizations, Julie has worked to provide a starting point for software quality assurance and has helped to build QA teams and implement testing processes and strategies. The testing plans she has developed include testing for functionality, usability, requirements, acceptance, release, regression, security, integrity, and performance.

Jeff Forristal is the Lead Security Developer for Neohapsis, a Chicago-based security solution/consulting firm. Apart from assisting in network security assessments and application security reviews (including source code review), Jeff is the driving force behind Security Alert Consensus, a joint security alert newsletter published on a weekly basis by Neohapsis, Network Computing, and the SANS Institute.

Kevin Ziese is a Computer Scientist at Cisco Systems, Inc. Prior to joining Cisco he was a Senior Scientist and Founder of the Wheelgroup Corporation, which was acquired by Cisco Systems in April of 1998. Prior to starting the Wheelgroup Corporation, he was Chief of the Advanced Countermeasures Cell at the Air Force Information Warfare Center. --This text refers to an out of print or unavailable edition of this title.


Product Details

    Do you have the free reader for this item?
    Adobe Reader
  • Format: Adobe Reader (PDF)
  • Printable: Yes. This title is printable
  • Mac OS Compatible: OS 9.x or later
  • Windows Compatible: Yes
  • Handheld Compatible: Yes. Adobe Reader is available for PalmOS, Pocket PC, and Symbian OS.
  • Digital: 512 pages
  • Publisher: Syngress (May 15, 2001)
  • Average Customer Review: 3.0 out of 5 stars See all reviews (3 customer reviews)
  • Amazon.com Sales Rank: #3,050,991 in Books (See Bestsellers in Books)

    Popular in these categories: (What's this?)

    #55 in  Books > eDocs > Formats > PDF (printable) > Computers & Internet > Security
    #70 in  Books > eDocs > Subjects > Computers & Internet > Internet
    #75 in  Books > eDocs > Formats > PDF (printable) > Computers & Internet > Web Design & Internet
  • Required Free Software: Adobe Reader

Inside This Book (learn more)
Browse and search another edition of this book.



Books on Related Topics (learn more)
 
 

Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

 

Customer Reviews

3 Reviews
5 star:    (0)
4 star:
 (2)
3 star:    (0)
2 star:    (0)
1 star:
 (1)
 
 
 
 
 
Average Customer Review
3.0 out of 5 stars (3 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
6 of 8 people found the following review helpful:
1.0 out of 5 stars Hack Proofing Your Web Applications, April 6, 2002
I'm working on a presentation on Web Application Security, and I
picked up this text as a reference. What a mistake! The text is
vague, poorly formatted and rife with errors.

Just one example:
p. 131 shows a sample CGI script for submitting comments to
FreeBSD.org. First of all, the screenshot references a page that
doesn't exist, tarnishing FreeBSD for no good reason. Secondly, the
Perl CGI script doesn't set PATH, doesn't use taint, and doesn't check
exit values. Third, the form uses a hidden field for the submit
address -- making it a juicy spam tool since the user could simply
replace "mcross@freebsd.org" with any address she chooses. And I
could go on and on with just that one script.

Other
gripes:
p. 465, "SSL makes the man-in-the-middle attack fail".
Wrong. ...

How about this: The authors refer to Perl as the
"Practical Extraction and Reporting Language." (p. 151, p. 223) Are
they trying to impress newbies?

SSL & PKI: only 20 pages of 565
are devoted to SSL & PKI, and those are mostly screen shots of Windows
MMC.

I'm not picking nits here, just citing examples that
particularly irk me while flipping through it. The author seems to
have little to say about Securing Web Applications, so he rambles on
with useless background and repeats himself often. This might be
useful had it been edited down to 100 pages.

I recommend Garfinkel
and Spafford's 'Web Security, Privacy & Commerce,' however Forristal
does minimally discuss ASP, which Garfinkel and Spafford neglect.
Also, Forristal has some interesting ideas for code review.

...












Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
1 of 1 people found the following review helpful:
4.0 out of 5 stars Fragmented and a bit self-important, but still useful, July 25, 2003
By Frank Carver (Ipswich, Suffolk United Kingdom) - See all my reviews
This book aims to be a "one stop shop" covering all aspects of web application security, however your app is written: Java. CGI, Perl, PHP, Active X. To a large extent it succeeds, and in a surprisingly readable way. Each chapter covers on aspect of hacking or security, and ends with a summary, a "fast track" checklist, and a FAQ for the topics covered. The book is sold like software - you can register for a "1-year upgrade", to keep the content fresh.

Important topics include both detailed and general hints on how to read and spot security holes in code in different languages; and how to "think like a hacker", and use hacker tools to test your own security. Above all, the book emphasizes the need for creative thinking and to avoid producing code carelessly.

I know from experience that security is often ignored if it's seen as too hard to understand, plan or test. Don't be a victim of your own ignorance, read this book.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
4 of 10 people found the following review helpful:
4.0 out of 5 stars Another surprisingly good security book from Syngress, October 17, 2001
I am a senior engineer for network security operations. Since I am not a developer, I was initially reluctant to read and review a book seemingly targeted towards programmers. From a non-developer, security professional standpoint, I believe "Hack Proofing Your Web Applications" (HPYWA) is an excellent book. Because HPYWA provides sufficient background, administrators will find it enlightening. Programmers should find it practical as well.

HPYWA is unique. One sees dozens of general networking and security texts, but few on securing applications. Since attackers are gravitating towards exploiting subtle application flaws, HPYWA's advice is timely and sorely needed. Talented authors (who should be credited chapter-by-chapter) explain security strategies for Visual Basic for Applications, CGI, Java, XML, ActiveX, and Cold Fusion. They tell how to avoid becoming a "code grinder" ("a developer who lacks creativity... bound by rules and primitive techniques"). They also discuss general exploit techniques, but not to the depth of a "Hacking Exposed" volume.

Crucially, throughout the book, the authors do not assume the reader is an expert in all technologies. They instead begin with solid introductions to languages and tools. These help non-programmers understand the issues, and give developers common foundations for code improvement.

I was particularly impressed by chapter 6, which explained how to conduct code audits and reverse engineering. Even without a great deal of programming background, I understood the author's explanations of format string vulnerabilities, cross-site scripting, and related problems. Chapter 7 was also excellent, as it showed how to disassemble Java byte code and alter it with a hex editor.

HPYWA is not perfect, however. Despite offering very strong coding advice, discussions of network-based security issues contained flaws. For example, the descriptions of denial of service on pages 13-14 and 285-286 are confused. On page 171, "SMTP" is not "Sendmail Transfer Protocol." Since I didn't read HPYWA to learn network security techniques, I didn't weigh these errors too heavily.

Developers will probably view HPYWA as a useful reminder of sound programming practices. They will also find the specific recommendations (avoid certain system calls, watch out for these formatting errors, etc.) practical and immediately applicable to their work. System administrators and security professionals will gain an understanding of the underlying weaknesses in the technologies they deploy and maintain. In short, HPYWA has a place on the bookshelves of both communities.[....]
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]

   


Product Information from the Amapedia Community

Beta (What's this?)



Look for Similar Items by Category


Plumbing Products in the Value Center

Home Improvement Value Center Plumbing Products
Turn it on for less with spectacular deals on brand-name faucets, showerheads, and more in the Home Improvement Value Center.

Shop the Value Center

 

Best Books of 2008

Best of 2008
Find our top 100 editors' picks as well as customers' favorites in dozens of categories in our Best Books of 2008 Store.
 

On the Bright Side

Shop the Lighting & Electrical Store
Not only does good lighting make your home safer, it also enhances the look and feel of your home. Browse the Lighting & Electrical Store now.

Shop Lighting & Electrical

 

Best Books

Best of the Month
See our editors' picks and more of the best new books on our Best of the Month page.
 

Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Glenn Beck's Common Sense
Glenn Beck's Common Sense
Darkfever
Darkfever by Karen Marie Moning
The Lost Symbol
The Lost Symbol by Dan Brown
$16.17

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates