

Buy anything from 5,000+ international stores. One checkout price. No surprise fees. Join 2M+ shoppers on Desertcart.
Desertcart purchases this item on your behalf and handles shipping, customs, and support to Austria.
The highly successful security book returns with a new edition, completely updated Web applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of ever-evolving web applications. You'll explore the various new technologies employed in web applications that have appeared since the first edition and review the new attack techniques that have been developed, particularly in relation to the client side. Reveals how to overcome the new technologies and techniques aimed at defending web applications against attacks that have appeared since the previous edition Discusses new remoting frameworks, HTML5, cross-domain integration techniques, UI redress, framebusting, HTTP parameter pollution, hybrid file attacks, and more Features a companion web site hosted by the authors that allows readers to try out the attacks described, gives answers to the questions that are posed at the end of each chapter, and provides a summarized methodology and checklist of tasks Focusing on the areas of web application security where things have changed in recent years, this book is the most current resource on the critical topic of discovering, exploiting, and preventing web application security flaws. Review: Accessible, informative and relevant despite the age - Other reviewers have said that this book is best used as a reference, they say not to read this ~700 page book cover-to-cover. I read this cover to cover. While on a first read-through it was not possible to take everything in, I found this to be highly accessible for a technical book. The writing style was quite casual. Examples are made from an informed perspective and relevant background for every exploit was presented in an understandable way. This is not a "cook-book" of ready to use exploits, but more an explanation of the mind-set required to develop your own exploits and a presentation of the background to specific circumstances that allow such exploits. I have to say that this is an old book considering the pace of technological advancement and reference is made to deprecated technologies such as Flash and Silverlight, but as a primer, a historical snapshot and an introduction to the mind-set required to effectively use exploits in general, this was a very good read. Don't expect to sit down and have an easy time, this is a technical book and I found it challenging in this respect, but I am extremely glad I decided to purchase this book and read it cover-to-cover. I would say this book is best read while dividing time with more current resources such as the Portswigger Academy, labs provided by sites such as TryHackMe, etc. Dafydd Stuttard, one of the authors, is the core developer of BurpSuite (by Portswigger), and reading this summary of the web hacking landscape has given me a new perspective on this world-leading application. I would strongly recommend this to anyone interested in web hacking specifically, but also hacking in general. Review: Much more than SQL Injection and XSS - I read this book in preparation for the Live Course which was presented by Marcus. While reading the book i found it was quite dry because i was not doing the practical excersises available online. As you have to pay for them i wasn't sure if it would be worth it. With hindsight after doing the course i would highly recommend using them. It will make the content a lot more interesting but also teach a key skill which the book doesn't: The key to most pen testing and vulnerability research is persistence and logical thinking. It is very well to think you know how a certain bug works but it can still be quite a challenge to actually implement it. I feel very lucky to have been able to attend the live course for hands on help from the authors but you can definitely get all the information and practice you need purely from the book and the website. Its a shame that there isn't a couple of hours of practical time included when you buy the book. It is very well written and covers all the areas you would expect. A lot of the old school web bugs explained such as SQL injection and less common now because of better programming practices and interfaces. Later chapters in the book such as the methodologies and logic flaw errors are timeless. The book also provides real world solutions and mitigation's for the attacks described so this is highly recommended for anyone who develops web applications swell as people who carry out penetration testing on them. While this may not be the best book ever written i think it definitively describes the topic therefore i have given it 5 stars.
| Best Sellers Rank | 330,645 in Books ( See Top 100 in Books ) 231 in Internet Applications 1,022 in E-Commerce & E-Business 1,375 in Web Administration |
| Customer Reviews | 4.7 out of 5 stars 1,103 Reviews |
M**S
Accessible, informative and relevant despite the age
Other reviewers have said that this book is best used as a reference, they say not to read this ~700 page book cover-to-cover. I read this cover to cover. While on a first read-through it was not possible to take everything in, I found this to be highly accessible for a technical book. The writing style was quite casual. Examples are made from an informed perspective and relevant background for every exploit was presented in an understandable way. This is not a "cook-book" of ready to use exploits, but more an explanation of the mind-set required to develop your own exploits and a presentation of the background to specific circumstances that allow such exploits. I have to say that this is an old book considering the pace of technological advancement and reference is made to deprecated technologies such as Flash and Silverlight, but as a primer, a historical snapshot and an introduction to the mind-set required to effectively use exploits in general, this was a very good read. Don't expect to sit down and have an easy time, this is a technical book and I found it challenging in this respect, but I am extremely glad I decided to purchase this book and read it cover-to-cover. I would say this book is best read while dividing time with more current resources such as the Portswigger Academy, labs provided by sites such as TryHackMe, etc. Dafydd Stuttard, one of the authors, is the core developer of BurpSuite (by Portswigger), and reading this summary of the web hacking landscape has given me a new perspective on this world-leading application. I would strongly recommend this to anyone interested in web hacking specifically, but also hacking in general.
M**H
Much more than SQL Injection and XSS
I read this book in preparation for the Live Course which was presented by Marcus. While reading the book i found it was quite dry because i was not doing the practical excersises available online. As you have to pay for them i wasn't sure if it would be worth it. With hindsight after doing the course i would highly recommend using them. It will make the content a lot more interesting but also teach a key skill which the book doesn't: The key to most pen testing and vulnerability research is persistence and logical thinking. It is very well to think you know how a certain bug works but it can still be quite a challenge to actually implement it. I feel very lucky to have been able to attend the live course for hands on help from the authors but you can definitely get all the information and practice you need purely from the book and the website. Its a shame that there isn't a couple of hours of practical time included when you buy the book. It is very well written and covers all the areas you would expect. A lot of the old school web bugs explained such as SQL injection and less common now because of better programming practices and interfaces. Later chapters in the book such as the methodologies and logic flaw errors are timeless. The book also provides real world solutions and mitigation's for the attacks described so this is highly recommended for anyone who develops web applications swell as people who carry out penetration testing on them. While this may not be the best book ever written i think it definitively describes the topic therefore i have given it 5 stars.
U**R
A timeless and definitive guide on web application security
This is the definitive guide on attacking and defending web applications. Anyone looking to enter the field of security consulting can't do much better than reading this book cover to cover. It is, admittedly, a long read at over 900 pages, and not one that I think people could or should sit down and push through quickly. Although the book is a few years old now, most of the content is still very much relevant to today's web applications and it is absolutely recommended for anyone looking to get a better idea of web application security, particularly those who haven't had a background in the security field.
C**S
A good reference
I find this book to be a good reference. As a beginner pen-tester, i'm learning the ropes and this book makes sense in some parts and doesn't make sense in others. It's probably because it's huge - with so many pages, it's aiming to take care of so many topics and cover subject matter for both newbie pen-testers and experienced pen-testers. I think as time goes on, the book will become even more useful for me. For the price and the staggering amount of detail and information, it's a no-brainer. This is basically a fantastic reference book and knowledge-base for anyone who is serious about digital security.
K**N
Great Book
I've actually met these guys before in Dublin at the Google building at set of OWASP presentations on web app security - and the guys definitely know their stuff. The book itself is really good and i find it very helpful to have on the desk, and to be able to reference to understand a topic better and to get ideas.
K**U
Satisfactory
Satisfactory
J**Y
Old but gold
Old book but information still relevant
R**N
excellent book with sound engineering and logic throughout
One of the best books on the subject of web application pen testing. The use of a strong logical approach (maybe using Dafydd philosophy background) helps to get the key concepts across. The test checklist at the end of the book is very useful if you need a quick guide to get you started while testing websites.
A**Y
SI quereis aprender seguridad web desde 0
SI quereis aprender seguridad web desde 0, es mejor pista para comenzar, va desde bases hasta cosas muy avanzadas. y facil de leer! Asi que recomendable
M**G
impec'
il m'aura fallu du temps pour le finir mais le contenu vaut le prix sans soucis :) un bon bouquin interessant et relativement complet.
M**I
Still relevant!
This book took me months to finish, but it's worth it. Some of the hacking tools mentioned don't exist anymore and you cannot test the vulnerabilities on the WAHH website because it doesn't exist. All the vulnerabilities mentioned are still relevant, except for a few related to Flash and Silverlight which I promptly skipped. The summary and questions at the end of each chapter are good to consolidate knowledge. Chapter 12 on cross site scripting is simultaneously the longest, most important, and most boring, in my opinion. It's funny that there is an entire chapter (9) devoted to SQL but only a paragraph about NoSQL which says "it's not popular enough so we won't discuss it". How times have changed!
R**M
Good condition book
Very good condition book
A**A
Portswigger web academy
Portswigger web academy labları yardımcı olması için aldım kesinlikle alınır
Trustpilot
5 days ago
1 day ago