Amazon Kindleでは、 The Web Application Hacker's Handbook をはじめとする140万冊以上の本をご利用いただけます。 詳細はこちら

Would you like to see this page in English? Click here.


または
1-Clickで注文する場合は、サインインをしてください。
または
Amazonプライム会員に適用。注文手続きの際にお申し込みください。詳細はこちら
こちらからも買えますよ
この商品をお持ちですか? マーケットプレイスに出品する
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
 
 
1分以内にKindleで The Web Application Hacker's Handbook をお読みいただけます。

Kindle をお持ちでない場合、こちらから購入いただけます。 Kindle 無料アプリのダウンロードはこちら

The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws [ペーパーバック]

Dafydd Stuttard , Marcus Pinto

参考価格: ¥ 5,233
価格: ¥ 5,092 通常配送無料 詳細
OFF: ¥ 141 (3%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
4点在庫あり。(入荷予定あり) 在庫状況について
この商品は、Amazon.co.jp が販売、発送します。 ギフトラッピングを利用できます。
多読の一助に
英語学習にぴったり、10万冊以上の中から自分のレベルに合った洋書が探せる「英語 難易度別リーディングガイド」 がオープン!

フォーマット

Amazon 価格 新品 中古品
Kindle版 ¥ 2,706  
ペーパーバック ¥ 5,092  

会員なら、この商品は10%Amazonポイント還元 (ポイントが表示されている場合は、表示ポイント+10%還元)。

キャンペーンおよび追加情報


よく一緒に購入されている商品

The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws + The Tangled Web: A Guide to Securing Modern Web Applications
合計価格: ¥ 10,179

選択された商品をまとめて購入

この商品を買った人はこんな商品も買っています


商品の説明

内容説明

The highly successful security book returns with a new edition, completely updated

Web applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of ever-evolving web applications. You'll explore the various new technologies employed in web applications that have appeared since the first edition and review the new attack techniques that have been developed, particularly in relation to the client side.

  • Reveals how to overcome the new technologies and techniques aimed at defending web applications against attacks that have appeared since the previous edition
  • Discusses new remoting frameworks, HTML5, cross-domain integration techniques, UI redress, framebusting, HTTP parameter pollution, hybrid file attacks, and more
  • Features a companion web site hosted by the authors that allows readers to try out the attacks described, gives answers to the questions that are posed at the end of each chapter, and provides a summarized methodology and checklist of tasks

Focusing on the areas of web application security where things have changed in recent years, this book is the most current resource on the critical topic of discovering, exploiting, and preventing web application security flaws.

著者について

DAFYDD STUTTARD is an independent security consultant, author, and software developer specializing in penetration testing of web applications and compiled software. Under the alias PortSwigger, Dafydd created the popular Burp Suite of hacking tools.

MARCUS PINTO delivers security consultancy and training on web application attack and defense to leading global organizations in the financial, government, telecom, gaming, and retail sectors.
The authors cofounded MDSec, a consulting company that provides training in attack and defense-based security.


登録情報

  • ペーパーバック: 912ページ
  • 出版社: Wiley; 2版 (2011/9/27)
  • 言語 英語, 英語, 英語
  • ISBN-10: 1118026470
  • ISBN-13: 978-1118026472
  • 発売日: 2011/9/27
  • 商品パッケージの寸法: 18.7 x 4.7 x 23.3 cm
  • Amazon ベストセラー商品ランキング: 洋書 - 36,956位 (洋書のベストセラーを見る)
  •  カタログ情報、または画像について報告

  • 目次を見る

この本のなか見!検索より (詳細はこちら
この本のサンプルページを閲覧する
おもて表紙 | 著作権 | 目次 | 抜粋 | 索引 | 裏表紙
この本の中身を閲覧する:

この商品を見た後に買っているのは?


カスタマーレビュー

Amazon.co.jp にはまだカスタマーレビューはありません
星5つ
星4つ
星3つ
星2つ
星1つ
Amazon.com で最も参考になったカスタマーレビュー (beta)
Amazon.com: 5つ星のうち 4.2  16件のカスタマーレビュー
33 人中、33人の方が、「このレビューが参考になった」と投票しています。
5つ星のうち 5.0 The Book That Keeps on Giving... 2011/10/14
By Jason Haddix - (Amazon.com)
形式:ペーパーバック|Amazon.co.jpで購入済み
There's a running joke we have on our assessment team about the Web Application Hackers Handbook. Every time we see a new technology, or have to deal with a one-off situation, we start doing research online only to find it was already referenced in WAHH somewhere. We've all read this book several times too, it's like Dafydd and Marcus sneak into our houses at night and add content...

Joking aside though, there is no other reference for web hacking as thorough or complete as WAHH.

With WAHH2 the authors added a significant amount content and rehashed existing chapters that were already deeply technical. The bonus in WAHH2 is its associated labs. Dafydd and Marcus have been giving a live WAHH training for years and have now moved the stellar CTF like challenges to the cloud. You can buy credits ($7 for 1hr) and move right along as you read the book (MDSec.net). When I say the labs are stellar, I mean it. The labs come almost straight from the class and start trivial and then get crazy. The injection labs were by far my favorite, housing 30-40 different injection types/variants each between XSS/SQLi. The CTF in the class (which i'll mention again is where the MDSec.com labs are based from) gets ridiculous toward the end. Even seasoned web testers fall around questions 14-16. But i digress...

WAHH2 is now the defacto buy for any pentest/QA/Audit team. Its usage will surpass any other book on your bookshelf if you are doing practical testing.

5 stars, i'd give it 10 if I could.
18 人中、18人の方が、「このレビューが参考になった」と投票しています。
5つ星のうち 5.0 An Improvement on the Best 2011/10/2
By Daniel Miessler - (Amazon.com)
形式:ペーパーバック|Amazon.co.jpで購入済み
This book improves on what I already thought was the best book on the subject.

The advantage of this book (and now the new version even more so) is in the way it breaks down the topics. Many books sort of jump around with their various sections, while the WAHH takes the precise line that I think is best when building on one's understanding of this topic.

The updated material is significant, and definitely worth the re-purchase. I bought both the dead-tree and the Kindle version.

100% definitely recommended.
26 人中、23人の方が、「このレビューが参考になった」と投票しています。
5つ星のうち 2.0 2 stars b/c the author's are using a stupid "make money the online labs" scheme 2012/10/7
By C. Brittain - (Amazon.com)
形式:ペーパーバック
Pains me to write a bad review for a book that has SO much great stuff. Really, it's full to the brim of really great info.

But where they went way way wrong: they keep referencing "Try it!" modules that refer to an online site, where the have different tutorials set up on a virtual server. You're allowed to try the hack techniques against the server for a "mere 7 dollars per hour".

But that's actually really really expensive (if you don't have a company paying for you, hell, even if you do). The online labs are sophisticated, but not THAT sophisticated. The author could have EASILY put them online for free, or run them cheaper. It'll take you HOURS to figure out anything on his labs, unless youre a seasoned pentest guy.

it's 7 per hour, and you have to choose 1 hour increments. So I found myself listing things i wanted to try in that hour...which i never got through, because HE DIDN'T INCLUDE ANSWERS, OR A GUIDE! You're supposed to figure it out on the go, which is fine and dandy if youre just browsing a site, but not when youre paying 7 dollars an hour to be on a site.

F that...could have done it better/different.
これらのレビューは参考になりましたか?   ご意見はクチコミでお聞かせください。

クチコミ

クチコミは、商品やカテゴリー、トピックについて他のお客様と語り合う場です。お買いものに役立つ情報交換ができます。
この商品のクチコミ一覧
内容・タイトル 返答 最新の投稿
まだクチコミはありません

複数のお客様との意見交換を通じて、お買い物にお役立てください。
新しいクチコミを作成する
タイトル:
最初の投稿:
サインインが必要です
 

クチコミを検索
すべてのクチコミを検索
   


リストマニア

リストを作成

関連商品を探す


フィードバック


Amazon.co.jpのプライバシー ステートメント Amazon.co.jpの発送情報 Amazon.co.jpでの返品と交換