shopping cart
Call us:  800-878-7323 HELP
McAfee SECURE helps keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams.
Powell's Q&A, Q&A | June 24, 2009

All posts by Colum McCann Powell's Q&A: Colum McCann

"'Why do writers write? Because it isn't there.'" Continue »


  1. $17.50 Sale Hardcover add to wish list

Ships free on qualified orders.
$39.99
TRADE PAPER, NEW
Ships in 1 to 3 days
Add to Wishlist
Available for In-store Pickup
in 7 to 12 days
Qty Store Section
2 Remote Warehouse General- General
1 Remote Warehouse Software Engineering- General


Other titles in the Programmer to Programmer series:

  1. A Preview of VB.NET Programming with the Public Beta
  2. Access 2003 VBA Programmer's Reference
  3. Adobe Air: Create - Modify - Reuse
  4. ASP.Net 2.0 Beta Preview
  5. ASP.NET 2.0 Instant Results with CDROM
  6. ASP.Net 2.0 MVP Hacks and Tips
  7. ASP.Net 2.0 Website Programming Problem - Design - Solution
  8. ASP.Net Website Programming: Problem - Design - Solution
  9. ASP.NET Website Programming: Problem - Design - Solution
  10. Beginning Access 2000 VBA with CDROM
  11. Beginning Access 2003 VBA
  12. Beginning Active Server Pages 3.0
  13. Beginning Ajax
  14. Beginning AppleScript
  15. Beginning ASP Databases
  16. Beginning ASP.Net 1.0 with C#
  17. Beginning ASP.NET 1.0: With Visual Basic .NET
  18. Beginning ASP.Net 1.1 with Visual C# .Net 2003
  19. Beginning ASP.Net 2.0
  20. Beginning ASP.Net 2.0 Ajax
  21. Beginning ASP.Net 2.0 Databases: Beta Preview
  22. Beginning ASP.Net 3.5: In C# and VB
  23. Beginning ASP.Net Databases Using VB.NET: Written and Tested or Final Relwase of Net V 1.0
  24. Beginning C# 2005 Databases
  25. Beginning Cryptography with Java
  26. Beginning DotNetNuke Skinning and Design
  27. Beginning Dreamweaver MX 2004
  28. Beginning Dynamic Websites: With ASP.Net Web Matrix with CDROM
  29. Beginning Excel Services
  30. Beginning Fedoratm 2
  31. Beginning Infopath 2003
  32. Beginning Java 2 SDK 1.4 Edition
  33. Beginning Javascript 2ND Edition
  34. Beginning Javascript 3RD Edition
  35. Beginning JavaScript TM
  36. Beginning JavaServer Pages Small TM/Small
  37. Beginning Linux Programming 3RD Edition
  38. Beginning Lua Programming
  39. Beginning Mysql
  40. Beginning PHP 4
  41. Beginning PHP5
  42. Beginning PHP5, Apache, Mysql Web Development
  43. Beginning Python
  44. Beginning Red Hat Linux 9 with CDROM
  45. Beginning Regular Expressions
  46. Beginning Sharepoint 2007: Building Team Solutions with Moss 2007
  47. Beginning Shell Scripting
  48. Beginning SQL
  49. Beginning SQL Server 2005 Programming
  50. Beginning Transact-SQL with SQL Server 2000 and 2005
  51. Beginning Unix
  52. Beginning VB.net 2ND Edition
  53. Beginning VB.net 3RD Edition
  54. Beginning Visual C#
  55. Beginning Xcode
  56. Beginning XML 4TH Edition
  57. C# 2005 Programmer's Reference
  58. Code Leader: Using People, Tools, and Processes to Build Successful Software
  59. CSS Instant Results
  60. DotNetNuke Websites: Problem - Design - Solution
  61. Dreamweaver MX: PHP Web Development
  62. Excel 2002 VBA Programmers Reference
  63. Excel 2003 VBA Programmer's Reference
  64. Excel 2007 VBA Programmer's Reference
  65. Expert Access 2007 Programming
  66. Expert One-on-One J2EE Design and Development
  67. Expert SQL Server 2005 Integration Services
  68. Facebook Application Development
  69. Flickr Mashups
  70. Ivor Horton's Beginning Visual C++ 2005
  71. Net Domain-Driven Design with C#: Problem - Design - Solution
  72. Photoshop Elements 2
  73. Professional .Net 2.0 Generics
  74. Professional .Net Framework 2.0
  75. Professional Adobe Flex 2
  76. Professional Ajax
  77. Professional Ajax 2ND Edition
  78. Professional Apache Tomcat 5
  79. Professional Asp.net 1.0
  80. Professional ASP.Net 1.1
  81. Professional ASP.Net 2.0
  82. Professional ASP.Net 2.0 Ajax
  83. Professional ASP.NET 2.0 Design: CSS, Themes, and Master Pages
  84. Professional ASP.NET 2.0 XML
  85. Professional ASP.Net 3.5 in C# and VB
  86. Professional Assembly Language
  87. Professional Blackberry
  88. Professional C# 2ND Edition
  89. Professional C# 3RD Edition
  90. Professional C++
  91. Professional Community Server
  92. Professional Community Server Themes
  93. Professional Dotnetnuke 4: Open Source Web Application Framework for ASP.Net 2.0
  94. Professional Excel Services
  95. Professional Haxe and Neko
  96. Professional Hibernate
  97. Professional IBM Websphere 5.0 Application Server
  98. Professional IIS 7
  99. Professional Jakarta Struts
  100. Professional Java Native Interfaces With SWT/Jface (Programmer To Programmer)
  101. Professional Java Tools for Extreme Programming: Ant, XDoclet, JUnit, Cactus, and Maven
  102. Professional Joomla!
  103. Professional Linq
  104. Professional Linux Programming
  105. Professional Microsoft Virtual Server 2005
  106. Professional Outlook 2007 Programming
  107. Professional Php5
  108. Professional Portal Development with Open Source Tools: Javatm  Portlet API, Lucene, James, Slide
  109. Professional Powershell for Exchange Server 2007 Sp1
  110. Professional Python Frameworks: Web 2.0 Programming with Django and TurboGears
  111. Professional Rich Internet Applications: Ajax and Beyond
  112. Professional Rootkits
  113. Professional Ruby on Rails
  114. Professional Search Engine Optimization with PHP: A Developer's Guide to SEO
  115. Professional SharePoint 2007 Development
  116. Professional Slickedit
  117. Professional Software Testing with Visual Studio 2005 Team System: Tools for Software Developers and Test Engineers
  118. Professional SQL Server 2000 Dts (Data Transformation Services)
  119. Professional SQL Server 2000 Programming
  120. Professional SQL Server 2005 CLR Programming: With Stored Procedures, Functions, Triggers, Aggregates, and Types
  121. Professional SQL Server 2005 Integration Services
  122. Professional SQL Server 2005 Performance Tuning
  123. Professional SQL Server 2005 Programming
  124. Professional SQL Server 2005 XML
  125. Professional SQL Server Analysis Services 2005 with MDX
  126. Professional VB 2005
  127. Professional VB 2005 with .Net 3.0
  128. Professional VB.net 2ND Edition
  129. Professional Visual Basic 2008
  130. Professional Visual Studio 2005
  131. Professional Visual Studio 2005 Team System
  132. Professional VMware Server
  133. Professional Vsto 2005: Visual Studio 2005 Tools for Office
  134. Professional WCF Programming: .Net Development with the Windows Communication Foundation
  135. Professional Web APIs with PHP: Ebay, Google, Paypal, Amazon, Fedex Plus Web Feeds
  136. Professional Wikis
  137. Professional Windows Desktop and Server Hardening
  138. Professional Windows Live Programming
  139. Professional Windows Powershell
  140. Professional Windows Vista Gadgets Programming
  141. Professional Winfx Beta: Covers "Avalon" Windows Presentation Foundation and "Indigo" Windows Communication Foundation
  142. Professional XML
  143. Programming Interviews Exposed 2ND Edition
  144. Real World Sharepoint 2007: Indispensable Experiences from 16 Moss and Wss Mvps
  145. Rexx Programmer's Reference
  146. Sharepoint 2007 and Office Development Expert Solutions
  147. SQL Functions: Programmer's Reference
  148. The Art of Rails: The Coming Age of Web Development
  149. Vbscript Programmer's Reference
  150. VBScript Programmer's Reference
  151. Visual Basic 2005 Instantresults
  152. Visual Basic 2005 Programmer's Reference
  153. Visual Basic 2008 Programmer's Reference
  154. Wrox's ASP.NET 2.0 Visual Web Developer 2005 Express Edition Starter Kit with CDROM
  155. Wrox's SQL Server 2005 Express Edition Starter Kit with CDROM
  156. Wrox's Visual Basic 2005 Express Edition Starter Kit with CDROM
  157. Wrox's Visual C# 2005 Express Edition Starter Kit
  158. XML: Problem - Design - Solution
  159. Xpath 2.0 Programmer's Reference
  160. XSLT 2.0 and Xpath 2.0 Programmer's Reference
  161. Xslt 2.0 Programmers Reference 3RD Edition

Professional Pen Testing for Web Applications (Programmer to Programmer)

by Andres Andreu

Professional Pen Testing for Web Applications (Programmer to Programmer) Cover

ISBN13: 9780471789666
ISBN10: 0471789666
All Product Details

Only 3 left in stock at $39.99!

Synopses & Reviews

Publisher Comments:

There is no such thing as "perfect security" when it comes to keeping all systems intact and functioning properly. Good penetration (pen) testing creates a balance that allows a system to be secure while simultaneously being fully functional. With this book, you'll learn how to become an effective penetrator (i.e., a white hat or ethical hacker) in order to circumvent the security features of a Web application so that those features can be accurately evaluated and adequate security precautions can be put in place. After a review of the basics of web applications, you'll be introduced to web application hacking concepts and techniques such as vulnerability analysis, attack simulation, results analysis, manuals, source code, and circuit diagrams. These web application hacking concepts and techniques will prove useful information for ultimately securing the resources that need your protection. What you will learn from this book * Surveillance techniques that an attacker uses when targeting a system for a strike * Various types of issues that exist within the modern day web application space * How to audit web services in order to assess areas of risk and exposure * How to analyze your results and translate them into documentation that is useful for remediation * Techniques for pen-testing trials to practice before a live project Who this book is for This book is for programmers, developers, and information security professionals who want to become familiar with web application security and how to audit it. Wrox Professional guides are planned and written by working programmers to meet the real-world needs of programmers, developers, and IT professionals. Focused and relevant, they address the issues technology professionals face every day. They provide examples, practical solutions, and expert education in new technologies, all designed to help programmers do a better job.

Synopsis:

Wrox Professional guides are planned and written by working programmers to meet the real-world needs of programmers, developers, and IT professionals. Focused and relevant, they address the issues technology professionals face every day. They provide examples, practical solutions, and expert education in new technologies, all designed to help programmers do a better job.

Synopsis:

What the Book Covers:   The first two chapters of the book reviews the basics of web applications and their protocols, especially authentication aspects, as a launching pad for understanding the inherent security vulnerabilities, covered later in the book. Immediately after this coverage, The author gets right down to basics of information security, covering vulnerability analysis, attack simulation, and results analysis, focusing the reader on the “ outcomes” aspects needed for successful pen testing. The author schools the reader on how to present findings to internal and external critical stakeholders, and then moves on to remediation or hardening of the code and applications, rather than the servers (often covered in other books).

Real World Web Solutions: The culmination is Chapter 9, the build out of a personal pen testing lab, replete with a baseline list of products, with installation guidance: Linux – Fedora VMWare Apache MySQL PHP Perl JBoss OpenLDAP OpenSSL OpenSSH Windows (with IIS installed)

Each one of these products will have its respective installation covered as part of this book.  Where appropriate we will also go into the configuration of the product.  This is in preparation for the honeypot applications we will be installed as well, consisting of WebGoat Hacme

Product Details

ISBN:
9780471789666
Author:
Andreu, Andres
Publisher:
Wrox Press
Author:
Andreu, A.
Subject:
Computer networks
Subject:
Computer security
Subject:
Networking/Security
Subject:
Computer networks -- Security measures.
Series:
Programmer to Programmer
Publication Date:
July 2006
Binding:
Paperback
Language:
English
Illustrations:
Y
Pages:
522
Dimensions:
9.18x7.34x1.26 in. 1.73 lbs.

Other books you might like

  1. $59.95 New Trade Paper add to wish list
  2. $50.00 New Trade Paper add to wish list
  3. $49.99 New Trade Paper add to wish list
  4. $39.99 New Trade Paper add to wish list
  5. $50.00 New Trade Paper add to wish list
  6. $39.95 Used Trade Paper add to wish list

Related Aisles

  • back to top

Powell's City of Books is an independent bookstore in Portland, Oregon, that fills a whole city block with more than a million new, used, and out of print books. Shop those shelves — plus literally millions more books, DVDs, and eBooks — here at Powells.com.