The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws

The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws

Authored by Dafydd Stuttard
Website Hacking 17 views 0 downloads 2011
Published 2011
Language eng
Publisher John Wiley & Sons
'the-web-application-hackers-handbook' by Dafydd Stuttard is universally regarded as the definitive bible of web application security and penetration testing. Authored by world-renowned AppSec experts, this comprehensive guide delivers an exhaustive breakdown of the attack surfaces, vulnerability classes, and defensive countermeasures in modern web systems.

The book provides hands-on methodologies for attacking authentication, session management, access controls, data stores, and back-end logic. Readers learn deep technical exploitation of SQL Injection, Cross-Site Scripting (XSS), CSRF, SSRF, XML/XXE, and command injection, supported by Burp Suite testing techniques and code review strategies.

Mandatory reading for penetration testers, bug bounty hunters, application security engineers, and web developers seeking to secure modern web environments.
Contents at a Glance
Chapter 1: Web Application (In)security: Core Fundamentals
Chapter 2: Core Defense Mechanisms: Authentication, Session, Access Control
Chapter 3: Web Application Technologies: HTTP, Cookies, Encoding
Chapter 4: Mapping the Application Attack Surface
Chapter 5: Bypassing Client-Side Controls and Input Validation
Chapter 6: Attacking Authentication: Brute Force, Token Flaws, Reset Vulnerabilities
Chapter 7: Attacking Session Management: Fixation, Hijacking, Prediction
Chapter 8: Attacking Access Controls: IDOR, Privilege Escalation, Path Traversal
Chapter 9: Attacking Data Stores: SQL Injection, Blind SQLi, NoSQL Injection
Chapter 10: Attacking Back-End Components: Command Injection, XML/XXE, SSRF
Chapter 11: Attacking Application Logic and Race Conditions
Chapter 12: Attacking Users: Reflected, Stored, and DOM-Based XSS
Chapter 13: Attacking Users: Cross-Site Request Forgery (CSRF) & Clickjacking
Chapter 14: Attacking Web Services, REST APIs, and SOAP
Chapter 15: Finding Vulnerabilities in Source Code: Static and Dynamic Review
Chapter 16: The Application Hacker's Complete Methodology & Checklist
Index & Further Reading