My Account Log in

3 options

How to attack and defend your website / Henry Dalziel.

Ebook Central Academic Complete Available online

View online

Ebook Central College Complete Available online

View online

O'Reilly Online Learning: Academic/Public Library Edition Available online

View online
Format:
Book
Author/Creator:
Dalziel, Henry, author.
Language:
English
Subjects (All):
Internet--Security measures.
Internet.
Web servers--Security measures.
Web servers.
World Wide Web--Security measures.
World Wide Web.
Physical Description:
1 online resource (1 volume) : illustrations
Edition:
1st edition
Place of Publication:
Waltham, Massachusetts : Syngress, 2015.
System Details:
text file
Summary:
How to Attack and Defend Your Website is a concise introduction to web security that includes hands-on web hacking tutorials. The book has three primary objectives: to help readers develop a deep understanding of what is happening behind the scenes in a web application, with a focus on the HTTP protocol and other underlying web technologies; to teach readers how to use the industry standard in free web application vulnerability discovery and exploitation tools – most notably Burp Suite, a fully featured web application testing tool; and finally, to gain knowledge of finding and exploiting the most common web security vulnerabilities. This book is for information security professionals and those looking to learn general penetration testing methodology and how to use the various phases of penetration testing to identify and exploit common web protocols. How to Attack and Defend Your Website is be the first book to combine the methodology behind using penetration testing tools such as Burp Suite and Damn Vulnerable Web Application (DVWA), with practical exercises that show readers how to (and therefore, how to prevent) pwning with SQLMap and using stored XSS to deface web pages. Learn the basics of penetration testing so that you can test your own website's integrity and security Discover useful tools such as Burp Suite, DVWA, and SQLMap Gain a deeper understanding of how your website works and how best to protect it
Contents:
Cover
Title Page
Copyright Page
Table of contents
Author Biography
Contributing Editor Biography
Introduction
Chapter 1 - Web Technologies
1.1 - Web servers
1.2 - Client-side versus server-side programming languages
1.3 - JavaScript - what is it?
1.4 - What can JavaScript do?
1.5 - What can JavaScript not do?
1.6 - Databases
1.7 - What about HTML?
1.8 - Web technologies - putting it together
1.9 - Digging deeper
1.10 - Hypertext Transfer Protocol (HTTP)
1.11 - Verbs
1.12 - Special characters and encodings
1.13 - Cookies, sessions, and authentication
1.14 - Short exercise: Linux machine setup
1.15 - Using the Burp Suite intercepting proxy
1.16 - Why is the intercepting proxy important?
1.17 - Short exercise - using the Burp Suite decoder
1.18 - Short exercise - getting comfortable with HTTP and Burp Suite
1.18.1 - Solution
1.19 - Understanding the application
1.20 - The Burp Suite site map
1.21 - Discovering content and structures
1.22 - Understanding an application
Chapter 2 - Exploitation
2.1 - Bypassing client side controls
2.1.1 - Steps for Bypassing Controls
2.2 - Bypassing client-side controls - example
2.2.1 - Short Exercise: Bypassing Client-Side Control
2.3 - Bypassing client-side controls - exercise solution
2.4 - SQL injection
2.5 - SQL injection
2.6 - Short Exercise: Pwning with SQLMap
2.6.1 - Hack Steps
2.6.2 - Solution: Pwning with SQLMap
2.7 - Cross-site scripting (XSS)
2.8 - Stored cross-site scripting XSS
2.9 - Short exercise: using stored XSS to deface a website
2.9.1 - Solution - Using Stored XSS
Chapter 3 - Finding Vulnerabilities
3.1 - The basic process - steps
3.2 - Exercise - finding vulnerabilities.
Notes:
Description based on online resource; title from PDF title page (ebrary, viewed January 10, 2015).
ISBN:
9780128027325
0128027320
9780128027547
0128027541
OCLC:
900652229

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account