Home > Computing and Information Technology > Computer security > Computer fraud and hacking > Hacking the Code: Auditor's Guide to Writing Secure Code for the Web
26%
Hacking the Code: Auditor's Guide to Writing Secure Code for the Web

Hacking the Code: Auditor's Guide to Writing Secure Code for the Web

          
5
4
3
2
1

Out of Stock


Premium quality
Premium quality
Bookswagon upholds the quality by delivering untarnished books. Quality, services and satisfaction are everything for us!
Easy Return
Easy return
Not satisfied with this product! Keep it in original condition and packaging to avail easy return policy.
Certified product
Certified product
First impression is the last impression! Address the book’s certification page, ISBN, publisher’s name, copyright page and print quality.
Secure Checkout
Secure checkout
Security at its finest! Login, browse, purchase and pay, every step is safe and secured.
Money back guarantee
Money-back guarantee:
It’s all about customers! For any kind of bad experience with the product, get your actual amount back after returning the product.
On time delivery
On-time delivery
At your doorstep on time! Get this book delivered without any delay.
Notify me when this book is in stock
Add to Wishlist

About the Book

Hacking the Code has over 400 pages of dedicated exploit, vulnerability, and tool code with corresponding instruction. Unlike other security and programming books that dedicate hundreds of pages to architecture and theory based flaws and exploits, Hacking the Code dives right into deep code analysis. Previously undisclosed security research in combination with superior programming techniques from Foundstone and other respected organizations is included in both the Local and Remote Code sections of the book. The book is accompanied with a FREE COMPANION CD containing both commented and uncommented versions of the source code examples presented throughout the book. In addition to the book source code, the CD also contains a copy of the author-developed Hacker Code Library v1.0. The Hacker Code Library includes multiple attack classes and functions that can be utilized to quickly create security programs and scripts. These classes and functions simplify exploit and vulnerability tool development to an extent never before possible with publicly available software.

Table of Contents:
Chapter 1 Managing Users Introduction Understanding the Threats Establishing User Credentials Enforcing Strong Passwords Avoiding Easily Guessed Credentials Preventing Credential Harvesting Limiting Idle Accounts Managing Passwords Storing Passwords Password Aging and Histories Changing Passwords Resetting Lost or Forgotten Passwords Resetting Passwords Sending Information Via E-Mail Assigning Temporary Passwords Using Secret Questions Empowering Users Educating Users Involving Users Coding Standards Fast Track Establishing User Credentials Managing Passwords Resetting Lost or Forgotten Passwords Empowering Users Code Audit Fast Track Establishing User Credentials Managing Passwords Resetting Lost or Forgotten Passwords Empowering Users Frequently Asked Questions Chapter 2 Authenticating and Authorizing Users Introduction Understanding the Threats Authenticating Users Building Login Forms Using Forms Authentication Using Windows Authentication Using Passport Authentication Blocking Brute-Force Attacks Authorizing Users Deciding How to Authorize Employing File Authorization Applying URL Authorization Authorizing Users Through Code Coding Standards Fast Track Authenticating Users Authorizing Users Code Audit Fast Track Authenticating Users Authorizing Users Frequently Asked Questions Chapter 3 Managing Sessions Introduction Session Tokens Authentication Tokens Understanding the Threats Maintaining State Designing a Secure Token Selecting a Token Mechanism Using State Providers Using ASP.NET Tokens Using Cookies Working with View State Enhancing ASP.NET State Management Creating Tokens Terminating Sessions Coding Standards Fast Track Maintaining State Using ASP.NET Tokens Enhancing ASP.NET State Management Code Audit Fast Track Maintaining State Using ASP.NET Tokens Enhancing ASP.NET State Management Frequently Asked Questions Chapter 4 Encrypting Private Data Introduction Using Cryptography in ASP.NET Employing Symmetric Cryptography Using Asymmetric Cryptography Working with Hashing Algorithms Working with .NET Encryption Features Creating Random Numbers Keeping Memory Clean Protecting Secrets Protecting Communications with SSL Coding Standards Fast Track Using Cryptography in ASP.NET Working with .NET Encryption Features Code Audit Fast Track Using Cryptography in ASP.NET Working with .NET Encryption Features Frequently Asked Questions Chapter 5 Filtering User Input Introduction Handling Malicious Input Identifying Input Sources Programming Defensively Constraining Input Bounds Checking Pattern Matching Data Reflecting Encoding Data Encapsulating Parameterizing Double Decoding Syntax Checking Exception Handling Honey Drops Limiting Exposure to Malicious Input Reducing the Attack Surface Limiting Attack Scope Hardening Server Applications Coding Standards Fast Track Handling Malicious Input Constraining Input Limiting Exposure to Malicious Input Code Audit Fast Track Handling Malicious Input Limiting Exposure to Malicious Input Frequently Asked Questions Chapter 6 Accessing Data Introduction Securing Databases Securing the Database Location Limiting the Attack Surface Ensuring Least Privilege Securing the Database Writing Secure Data Access Code Connecting to the Data Source Preventing SQL Injection Writing Secure SQL Code Reading and Writing to Data Files Coding Standards Fast Track Securing Database Drivers Securing Databases Writing Secure Data Access Code Code Audit Fast Track Securing Database Drivers Securing the Database Writing Secure Data Access Code Frequently Asked Questions Chapter 7 Developing Secure ASP.NET Applications Introduction Understanding the Threats Writing Secure HTML Constructing Safe HTML Preventing Information Leaks Handling Exceptions Using Structured Error Handling Reporting and Logging Errors Coding Standards Fast Track Writing Secure HTML Handling Exceptions Code Audit Fast Track Writing Secure HTML Handling Exceptions Frequently Asked Questions Chapter 8 Securing XML Introduction Applying XML Encryption Encrypting XML Data Applying XML Digital Signatures Signing XML Data Coding Standards Fast Track Applying XML Encryption Applying XML Digital Signatures Coding Audit Fast Track Applying XML Encryption Applying XML Digital Signatures Frequently Asked Questions Appendix A Understanding .NET Security Introduction Permissions Principal Authentication Authorization Security Policy Type Safety Code Access Security .NET Code Access Security Model Role-Based Security Principals Role-Based Security Checks Security Policies Creating a New Permission Set Modifying the Code Group Structure Remoting Security Cryptography Security Tools Summary Security Fast Track Frequently Asked Questions Appendix B Glossary of Web Application Security Threats Index


Best Sellers


Product Details
  • ISBN-13: 9781932266658
  • Publisher: Syngress Media,U.S.
  • Publisher Imprint: Syngress Media,U.S.
  • Height: 229 mm
  • No of Pages: 550
  • Series Title: English
  • Sub Title: Auditor's Guide to Writing Secure Code for the Web
  • Width: 178 mm
  • ISBN-10: 1932266658
  • Publisher Date: 10 May 2004
  • Binding: Hardback
  • Language: English
  • Returnable: N
  • Spine Width: 33 mm
  • Weight: 750 gr


Similar Products

How would you rate your experience shopping for books on Bookswagon?

Add Photo
Add Photo

Customer Reviews

REVIEWS           
Click Here To Be The First to Review this Product
Hacking the Code: Auditor's Guide to Writing Secure Code for the Web
Syngress Media,U.S. -
Hacking the Code: Auditor's Guide to Writing Secure Code for the Web
Writing guidlines
We want to publish your review, so please:
  • keep your review on the product. Review's that defame author's character will be rejected.
  • Keep your review focused on the product.
  • Avoid writing about customer service. contact us instead if you have issue requiring immediate attention.
  • Refrain from mentioning competitors or the specific price you paid for the product.
  • Do not include any personally identifiable information, such as full names.

Hacking the Code: Auditor's Guide to Writing Secure Code for the Web

Required fields are marked with *

Review Title*
Review
    Add Photo Add up to 6 photos
    Would you recommend this product to a friend?
    Tag this Book
    Read more
    Does your review contain spoilers?
    What type of reader best describes you?
    I agree to the terms & conditions
    You may receive emails regarding this submission. Any emails will include the ability to opt-out of future communications.

    CUSTOMER RATINGS AND REVIEWS AND QUESTIONS AND ANSWERS TERMS OF USE

    These Terms of Use govern your conduct associated with the Customer Ratings and Reviews and/or Questions and Answers service offered by Bookswagon (the "CRR Service").


    By submitting any content to Bookswagon, you guarantee that:
    • You are the sole author and owner of the intellectual property rights in the content;
    • All "moral rights" that you may have in such content have been voluntarily waived by you;
    • All content that you post is accurate;
    • You are at least 13 years old;
    • Use of the content you supply does not violate these Terms of Use and will not cause injury to any person or entity.
    You further agree that you may not submit any content:
    • That is known by you to be false, inaccurate or misleading;
    • That infringes any third party's copyright, patent, trademark, trade secret or other proprietary rights or rights of publicity or privacy;
    • That violates any law, statute, ordinance or regulation (including, but not limited to, those governing, consumer protection, unfair competition, anti-discrimination or false advertising);
    • That is, or may reasonably be considered to be, defamatory, libelous, hateful, racially or religiously biased or offensive, unlawfully threatening or unlawfully harassing to any individual, partnership or corporation;
    • For which you were compensated or granted any consideration by any unapproved third party;
    • That includes any information that references other websites, addresses, email addresses, contact information or phone numbers;
    • That contains any computer viruses, worms or other potentially damaging computer programs or files.
    You agree to indemnify and hold Bookswagon (and its officers, directors, agents, subsidiaries, joint ventures, employees and third-party service providers, including but not limited to Bazaarvoice, Inc.), harmless from all claims, demands, and damages (actual and consequential) of every kind and nature, known and unknown including reasonable attorneys' fees, arising out of a breach of your representations and warranties set forth above, or your violation of any law or the rights of a third party.


    For any content that you submit, you grant Bookswagon a perpetual, irrevocable, royalty-free, transferable right and license to use, copy, modify, delete in its entirety, adapt, publish, translate, create derivative works from and/or sell, transfer, and/or distribute such content and/or incorporate such content into any form, medium or technology throughout the world without compensation to you. Additionally,  Bookswagon may transfer or share any personal information that you submit with its third-party service providers, including but not limited to Bazaarvoice, Inc. in accordance with  Privacy Policy


    All content that you submit may be used at Bookswagon's sole discretion. Bookswagon reserves the right to change, condense, withhold publication, remove or delete any content on Bookswagon's website that Bookswagon deems, in its sole discretion, to violate the content guidelines or any other provision of these Terms of Use.  Bookswagon does not guarantee that you will have any recourse through Bookswagon to edit or delete any content you have submitted. Ratings and written comments are generally posted within two to four business days. However, Bookswagon reserves the right to remove or to refuse to post any submission to the extent authorized by law. You acknowledge that you, not Bookswagon, are responsible for the contents of your submission. None of the content that you submit shall be subject to any obligation of confidence on the part of Bookswagon, its agents, subsidiaries, affiliates, partners or third party service providers (including but not limited to Bazaarvoice, Inc.)and their respective directors, officers and employees.

    Accept

    New Arrivals


    Inspired by your browsing history


    Your review has been submitted!

    You've already reviewed this product!
    ASK VIDYA