- 主頁 /
- 書籍 /
- 電腦和技術 /
- Programming /
- Software Design, Testing & Engineering /
- 測試 /
- Mastering Modern Web Penetration Testing
Mastering Modern Web Penetration Testing
85% of respondents would recommend this to a friend
TWD 2353
Price Details
Excluding Shipping & Custom charges ( Shipping and custom charges will be calculated on checkout )
*All items will import from 美國
QTY:
Ubuy works hard to protect your security and privacy. Our advanced payment security system ensures confidentiality by encrypting your information during transmission using AES (Advanced Encryption Standards) and SSL (Secure Socket Layer) protocols. Your payment details are 100% secure as we do not share your payment details with third party sellers.
This pragmatic guide will be a great benefit and will help you prepare fully secure applications.
Fast
Shipping
Free
Return*
Secure Packaging
100% Original Products
PCI DSS Compliance
ISO 27001 Certified
What Stands Out
產品詳情
- Key FeaturesThis book covers the latest technologies such as Advance XSS, XSRF, SQL Injection, Web API testing, XML attack vectors, OAuth 2.0 Security, and more involved in today's web applicationsPenetrate and secure your web application using various techniquesGet this comprehensive reference guide that provides advanced tricks and tools of the trade for seasoned penetration testersBook DescriptionWeb penetration testing is a growing, fast-moving, and absolutely critical field in information security. This book executes modern web application attacks and utilises cutting-edge hacking techniques with an enhanced knowledge of web application security.We will cover web hacking techniques so you can explore the attack vectors during penetration tests. The book encompasses the latest technologies such as OAuth 2.0, Web API testing methodologies and XML vectors used by hackers. Some lesser discussed attack vectors such as RPO (relative path overwrite), DOM clobbering, PHP Object Injection and etc. has been covered in this book.We'll explain various old school techniques in depth such as XSS, CSRF, SQL Injection through the ever-dependable SQLMap and reconnaissance. Websites nowadays provide APIs to allow integration with third party applications, thereby exposing a lot of attack surface, we cover testing of these APIs using real-life examples. This pragmatic guide will be a great benefit and will help you prepare fully secure applications.What you will learnGet to know the new and less-publicized techniques such PHP Object Injection and XML-based vectorsWork with different security tools to automate most of the redundant tasksSee different kinds of newly-designed security headers and how they help to provide securityExploit and detect different kinds of XSS vulnerabilitiesProtect your web application using filtering mechanismsUnderstand old school and classic web hacking in depth using SQL Injection, XSS, and CSRFGrasp XML-related vulnerabilities and attack vectors such as XXE and DoS techniquesGet to know how to test REST APIs to discover security issues in themAbout the AuthorPrakhar Prasad is a web application security researcher and penetration tester from India. He has been a successful participant in various bug bounty programs and has discovered security flaws on websites such as Google, Facebook, Twitter, PayPal, Slack, and many more. He secured the tenth position worldwide in the year 2014 at HackerOne's platform. He is OSCP and OSWP certified, which are some of the most widely respected certifications in the information security industry. He occasionally performs training and security assessment for various government, non-government, and educational organizations.Table of ContentsCommon Security ProtocolsInformation GatheringCross-Site ScriptingCross-Site Request ForgeryExploiting SQL InjectionFile Upload VulnerabilitiesMetasploit and WebXML AttacksEmerging Attack VectorsOAuth 2.0 SecurityAPI Testing Methodology
| Publisher | Packt Publishing |
| Publication date | October 28, 2016 |
| Language | English |
| Print length | 298 pages |
| ISBN-10 | 1785284584 |
| ISBN-13 | 978-1785284588 |
| Item Weight | 1.14 pounds (520 grams) |
| Dimensions | 7.5 x 0.68 x 9.25 inches (19.1 x 1.7 x 23.5 cm) |
Who Should Buy?
-
Aspiring Penetration Testers
Individuals looking to start a career in cybersecurity and penetration testing will find practical insights and techniques.
-
Security Professionals
Experienced security practitioners seeking to update their skills with modern web vulnerabilities and testing methodologies will benefit.
-
Developers and Engineers
Web developers aiming to understand security implications in their coding can enhance their applications' security.
-
Beginner Or General Users
Complete novices without foundational cybersecurity knowledge may struggle with advanced concepts and terminology presented.
產品描述
客戶問題與解答
-
問題:
What kind of security techniques are included in this book?
Answer: The book covers advanced techniques like Cross-Site Scripting, SQL Injection, API testing, and emerging attack vectors. -
問題:
Who is the author of this book?
Answer: Prakhar Prasad, a web application security researcher and experienced penetration tester. -
問題:
Is this book suitable for beginners?
Answer: While it provides advanced insights, it serves as a comprehensive guide that may benefit those with prior knowledge of web security. -
問題:
Is this book suitable for beginners?
Answer: Yes, this book is recommended for beginners and provides the basics of web exploits. -
問題:
Does this book cover new techniques?
Answer: Yes, the book covers various new techniques in web pen testing. -
問題:
Is this book worth the price?
Answer: Opinions on the price vary. Some readers find it expensive while others think it's worth it.
Testing Editorial Review
Mastering Modern Web Penetration Testing is a book that provides useful information for beginners and some helpful content for medium-level readers. However, it falls short for advanced readers who expected more in-depth and advanced material. The book covers a range of web app attacks, including the latest attack methods, and provides examples of such attacks. While it may not make you a true master of web pen testing, it serves as a valuable additional resource. Some reviewers found the book to be coherent and well-organized, but wished for more information on certain topics. Others criticized the book for being poorly written and lacking coherent explanations and relevant examples. Overall, the book is praised for its quality and the practical screenshots provided. However, some readers found it to be expensive. It is considered a good book for beginners and those interested in bug bounty in web applications.
Customer Reviews & Ratings
-
5 星
45%
-
4 星
31%
-
3 星
9%
-
2 星
7%
-
1 星
8%
評論這個產品
和其他客戶分享您的想法
優點
- The quality of the book is really good
- Covers a range of web app attacks, including the latest methods
- Provides examples of attacks
- Coherent and well-organized
- Practical screenshots provided
缺點
- Includes a lot of very basic concepts known to many people
Platform Trust & Buyer Confidence
“Easy to use and always helpful and sorts any issues I've had past and present”
“I always receive support when I engage customer service. Overall my experience with UBUY has been top notch. Keep up the good work.”
“The delivery was fast and the product came undamaged and authentic.”
“Ubuy is extremely efficient and to order online is an easy process. The verity of products to buy is really unlimited! My order was urgent and I got it on time. The products are great! Thank you Ubuy!”
“Fast, convenient and cheap. Great store!”
Product Price History
重要資訊
- 限制:對於國際運輸的產品,請注意任何製造商保修可能無效;製造商服務選項可能不可用;產品手冊、說明和安全警告可能不是目的地國家的語言;產品(及隨附材料)的設計可能不符合目的地國家的標準、規範和標籤要求;並且產品可能不符合目的地國家的電壓和其他電氣標準(如果適用,需要使用適配器或轉換器)。收件人有責任確保產品可以合法進口到目的地國家。當從Ubuy或其關聯公司訂購時,收件人是記錄在案的進口人,並且必須遵守目的地國家的所有法律和法規。
- 由於Ubuy是一個全球搜索引擎,因此並非Ubuy上列出的所有產品都在出售。產品受出口/貿易法規的約束。
TWD 2353
立即訂購並活動它 Monday, 九月 14
This item is not restrict in my country.(Please click on above link if this item is not restrict in your country, So our team will review and allow.)
QTY:
PCI DSS compliant and ISO 27001:2022 certified, with encrypted payments and full buyer protection on every order.
特色和優勢
- Covers advanced web penetration techniques including XSS, XSRF, SQL Injection, and more.
- Features the latest technologies in web application security such as OAuth 2.0 and Web API testing.
- Explains lesser-discussed attack vectors like PHP Object Injection and XML vulnerabilities.
- Includes practical examples for testing and securing REST APIs.
- Offers in-depth knowledge of old-school hacking methods along with modern strategies.
- Written by a respected penetration tester with extensive experience in the field.
Ubuy Assurance
Experience worry-free shopping with 100% original products, PCI DSS-compliant payment security, ISO 27001-certified data protection, the fastest cross-border delivery, free returns *, and secure packaging on every order.