Hacking Web Apps: Detecting and Preventing Web Application Security Problems

Hacking Web Apps: Detecting and Preventing Web Application Security Problems

Authored by Mike Shema
Website Hacking 6 views 0 downloads 2012
Published 2012
Language English
Publisher Syngress
'Hacking Web Apps Detecting and Preventing Web Application Security Problems' provides an in-depth, hands-on exploration of web application security, vulnerability assessment, and offensive exploitation techniques. Focusing on the critical weaknesses that plague modern dynamic websites, APIs, and cloud services, this guide delivers practical methodology for security testing.

Readers examine client-side and server-side flaw discovery, input validation bypasses, session hijacking, authorization flaws, injection attacks (SQLi, Command Injection), Cross-Site Scripting (XSS), and automated scanning with industry-standard tools like Burp Suite and OWASP ZAP. Practical labs and vulnerability reporting guidelines are emphasized.

A valuable guide for penetration testers, bug bounty hunters, and web developers striving to build resilient, hardened web applications.
Contents at a Glance
Chapter 1: Introduction to Penetration Testing Methodologies & Standards
Chapter 2: Target Scoping, Rules of Engagement, and Legal Frameworks
Chapter 3: Passive and Active Reconnaissance Techniques
Chapter 4: Network Scanning, Service Enumeration, and Vulnerability Assessment
Chapter 5: Exploitation: Gaining Initial Access and Shell Delivery
Chapter 6: Post-Exploitation: Local Enumeration and Privilege Escalation
Chapter 7: Lateral Movement, Pivoting, and Internal Reconnaissance
Chapter 8: Data Exfiltration, Cleanup, and Executive Reporting
Index & Further Reading