TMCnet News

Research and Markets: The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws, 2nd Edition
[January 05, 2012]

Research and Markets: The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws, 2nd Edition


(M2 PressWIRE Via Acquire Media NewsEdge) Dublin - Research and Markets (http://www.researchandmarkets.com/research/f7639e/the_web_applicatio) has announced the addition of John Wiley and Sons Ltd's new book "The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws, 2nd Edition" to their offering.



There have been two broad trends that have evolved since the first edition and will be covered in detail in this edition: Various new and modified technologies have appeared that are being used in web applications, including new remoting frameworks, HTML5, cross-domain integration techniques.

Many new attack techniques have been developed, particularly in relation to the client side, including UI redress (clickjacking), framebusting, HTTP parameter pollution, XML external entity injection, bypasses for new browser anti-XSS filters, hybrid file (GIFAR) attacks.


The web site to accompany the book will comprise: - Code appearing in the book.

- Answers to the questions posed at the end of each chapter.

- Links to tools discussed in the book.

- A summarized methodology and checklist of tasks For several years the authors have delivered a very popular course on web application hacking at venues around the world, andthey are constantly being asked to create an online version of the course for people who arent able to attend conferences. The authorswill make parts oftheir existing course available online on a subscription basis in the coming months. They will use some examples from the online course within this second edition of the book, so that (in contrast to the first edition which uses purely fictional examples), people who wish to practice on the examples in the book will be able to do so if they wish.

Author: - Dafydd Stuttard is an expert in web application security. He has delivered training on this topic at numerous conferences and other venues around the world. Under the alias PortSwigger, Dafydd created the popular Burp Suite of tools for security testing of web applications.

- Marcus Pinto works specifically with web application security, providing consultancy to the financial and e-commerce sectors. He has helped establish the de facto standard for web application assessment within the UK.

For more information visit http://www.researchandmarkets.com/research/f7639e/the_web_applicatio CONTACT: Research and Markets Laura Wood, Senior Manager, [email protected] U.S. Fax: 646-607-1907 Fax (outside U.S.): +353-1-481-1716 ((M2 Communications disclaims all liability for information provided within M2 PressWIRE. Data supplied by named party/parties. Further information on M2 PressWIRE can be obtained at http://www.presswire.net on the world wide web. Inquiries to [email protected])).

(c) 2012 M2 COMMUNICATIONS

[ Back To TMCnet.com's Homepage ]