Shop big deals on refurbished tech
Enjoy fast, free delivery, exclusive deals, and award-winning movies & TV shows.
Buy New
$89.83
FREE delivery Monday, October 12
Ships from: Amazon
Sold by: Addas LLC
$89.83
FREE delivery Monday, October 12
Or Prime members get FREE delivery Friday, October 9. Order within 13 hrs 54 mins. Join Prime
Only 1 left in stock - order soon.
$$89.83 () Includes selected options. Includes initial monthly payment and selected options. Details
Price
Subtotal
$$89.83
Subtotal
Initial payment breakdown
Shipping cost, delivery date, and order total (including tax) shown at checkout.
Ships from
Amazon
Amazon
Ships from
Amazon
Returns
FREE 30-day refund/replacement
FREE 30-day refund/replacement
Quick refund
Usually issued within 24 hours. See exceptions
FREE return
At least one free return option available.
Convenient dropoff
At any of our 50,000 US locations.
See return policy
Gift options
Available at checkout
Available at checkout This item is a gift. Change
At checkout, you can add a custom message, a gift receipt for easy returns and have the item gift-wrapped
Payment
Secure transaction
Your transaction is secure
We work hard to protect your security and privacy. Our payment security system encrypts your information during transmission. We don’t share your credit card details with third-party sellers, and we don’t sell your information to others. Learn more
$19.98
FREE Returns
Shipped within 24 hours. Clean, undamaged book with no damage to pages and minimal wear to the cover. Spine still tight, in very good condition. Remember if you are not happy, you are covered by our 100% money back guarantee. Shipped within 24 hours. Clean, undamaged book with no damage to pages and minimal wear to the cover. Spine still tight, in very good condition. Remember if you are not happy, you are covered by our 100% money back guarantee. See less
FREE delivery October 20 - 23. Details
In stock
$$89.83 () Includes selected options. Includes initial monthly payment and selected options. Details
Price
Subtotal
$$89.83
Subtotal
Initial payment breakdown
Shipping cost, delivery date, and order total (including tax) shown at checkout.
Access codes and supplements are not guaranteed with used items.
Ships from and sold by Bahamut Media.
Added to

Sorry, there was a problem.

There was an error retrieving your Wish Lists. Please try again.

Sorry, there was a problem.

List unavailable.
Kindle app logo image

Download the free Kindle app and start reading Kindle books instantly on your smartphone, tablet, or computer - no Kindle device required.

Read instantly on your browser with Kindle for Web.

Using your mobile phone camera - scan the code below and download the Kindle app.

QR code to download the Kindle App

  • Web Application Security: Exploitation and Countermeasures for Modern Web Applications

Follow the author

Follow authors for new release and deal updates, plus improved recommendations. See updates from all followed authors in Your Books.
Something went wrong. Please try your request again later.

Web Application Security: Exploitation and Countermeasures for Modern Web Applications

4.3 out of 5 stars (145)

{"desktop_buybox_group_1":[{"displayPrice":"$89.83","priceAmount":89.83,"currencySymbol":"$","integerValue":"89","decimalSeparator":".","fractionalValue":"83","symbolPosition":"left","hasSpace":false,"showFractionalPartIfEmpty":true,"offerListingId":"xmyprd%2FlOk8%2FqV65PjjCaNYKkoZjNljCecATen6VyiBhocPYkIH78LPxm3V3Y%2FOfJN5OAZPBmU0zSirOAx4Q0bB2%2F0vS4m3JHRWIMDMC35r0UxrGNjmOoc49A6w7p5OUTb5nIhOTUrRRLJssTZ1KbGSBcKs5MpO%2BSIEAcVW8yWtS1IsobrXTmw%3D%3D","locale":"en-US","buyingOptionType":"NEW","aapiBuyingOptionIndex":0}, {"displayPrice":"$19.98","priceAmount":19.98,"currencySymbol":"$","integerValue":"19","decimalSeparator":".","fractionalValue":"98","symbolPosition":"left","hasSpace":false,"showFractionalPartIfEmpty":true,"offerListingId":"xmyprd%2FlOk8%2FqV65PjjCaNYKkoZjNljCUXnx3kAyS8Y04mJ44JqRF2y4ezv51voy3HxVwIx11go5tZlh%2BMqLvaTGOlqlfjp0333YcGIAFXqtp4LjCk%2FfZC6sZx9CJ4QK%2BaJONyBMu2u4vxJTgY05uhP3Ju5BDFDImRb%2FmbVuIo%2BRZfqh9%2FWN1g%3D%3D","locale":"en-US","buyingOptionType":"USED","aapiBuyingOptionIndex":1}]}

Purchase options and add-ons

While many resources for network and IT security are available, detailed knowledge regarding modern web application security has been lacking, until now. This practical guide provides both offensive and defensive security concepts that software engineers can easily learn and apply.

Andrew Hoffman, a senior security engineer at Salesforce, introduces three pillars of web application security: recon, offense, and defense. You'll learn methods for effectively researching and analyzing modern web applications, including those you don't have direct access to. You'll also learn how to break into web applications using the latest hacking techniques. Finally, you'l learn how to develop mitigations for use in your own web applications to protect against hackers.

  • Explore common vulnerabilities plaguing today's web applications
  • Learn essential hacking techniques attackers use to exploit applications
  • Map and document web applications for which you don't have direct access
  • Develop and deploy customized exploits that can bypass common defenses
  • Develop and deploy mitigations to protect your applications against hackers
  • Integrate secure coding best practices into your development lifecycle
  • Get practical tips to help you improve the overall security of your web applications

There is a newer edition of this item:

Customers also bought or read

Loading...

From the Publisher

Web Application Security

From the Preface

Web Application Security walks you through a number of techniques used by talented hackers and bug bounty hunters to break into applications, then teaches you the techniques and processes you can implement in your own software to protect against such hackers.

This book is designed to be read from cover to cover, but can also be used as an on-demand reference for particular types of recon techniques, attacks, and defenses against attacks. Ultimately, this book is written to aid the reader in becoming better at web application security in a way that is practical, hands-on, and follows a logical progression such that no significant prior security experience is required.

Prerequisite Knowledge and Learning Goals

This is a book that will not only aid you in learning how to defend your web application against hackers, but will also walk you through the steps hackers take in order to investigate and break into a web application. Throughout this book we will discuss many techniques that hackers are using today to break into web applications hosted by corporations, governments, and occasionally even hobbyists. Following sufficient investigation into the previously mentioned techniques, we begin a discussion on how to secure web applications against these hackers.

In doing so you will discover brand new ways of thinking about application architecture. You will also learn how to integrate security best practices into an engineering organization. Finally, we will evaluate a number of techniques for defending against the most common and dangerous types of attacks that occur against web applications today.

After completing Web Application Security you will have the required knowledge to perform recon techniques against applications you do not have code-level access to. You will also be able to identify threat vectors and vulnerabilities in web applications, and craft payloads designed to compromise application data, interrupt flow, or interfere with the intended function of a web application. With these skills in hand, and the knowledge gained from the final section on securing web applications, you will be able to identify risky areas of a web application’s codebase and understand how to write code to defend against attacks that would otherwise leave your application and its users at risk.

Suggested Background

The potential audience for this book is quite broad, but the style in which the book is written and how the examples are structured should make it ideal for anyone with an intermediary-level background in software engineering.

Minimum Required Skills

In this book, an “intermediary-level background in software engineering” implies the following:

  • You can write basic CRUD (create, read, update, delete) programs in at least one programming language.
  • You can write code that runs on a server somewhere (such as backend code).
  • You can write at least some code that runs in a browser (frontend code, usually JavaScript).
  • You know what HTTP is, and can make, or at least read, GET/POST calls over HTTP in some language or framework.
  • You can write, or at least read and understand, applications that make use of both server-side and client-side code, and communicate between the two over HTTP.
  • You are familiar with at least one popular database (MySql, MongoDB, etc.).

These skills represent the minimum criteria for successfully following the examples in this book. Any experience you have beyond these bullet points is a plus and will make this book that much easier for you to consume and derive educational value from.

Editorial Reviews

About the Author

Andrew Hoffman is a product security lead at Salesforce.com, where he is responsible for the security of multiple JavaScript, NodeJS, and OSS teams. His expertise is in deep DOM and JavaScript security vulnerabilities. He has worked with every major browser vendor, as well as with TC39 and WHATWG ? the organizations responsible for the upcoming version of JavaScript and the browser DOM spec.

Prior to this role, Andrew was a software security engineer working on Locker Service, the world's first JavaScript namespace isolation library that operates from the interpreter level up. In parallel, Andrew also contributed to the upcoming JavaScript language security feature "Realms," which provides language level namespace isolation to JavaScript.

Product details

  • Publisher ‏ : ‎ O'Reilly Media
  • Publication date ‏ : ‎ April 7, 2020
  • Edition ‏ : ‎ 1st
  • Language ‏ : ‎ English
  • Print length ‏ : ‎ 327 pages
  • ISBN-10 ‏ : ‎ 1492053112
  • ISBN-13 ‏ : ‎ 978-1492053118
  • Item Weight ‏ : ‎ 1.15 pounds
  • Dimensions ‏ : ‎ 7 x 0.75 x 9 inches
  • Best Sellers Rank: #2,838,959 in Books (See Top 100 in Books)
  • Customer Reviews:
    4.3 out of 5 stars (145)

About the author

Follow authors for new release and deal updates, plus improved recommendations. See updates from all followed authors in Your Books.
Andrew Hoffman
Brief content visible, double tap to read full content.
Full content visible, double tap to read brief content.

Andrew Hoffman is a Senior Staff Security Engineer at Ripple. He has a unique skill-set which is composed of both software engineering and application security. His primary security interests are client-side attacks, threat modeling and security automation.

He has worked and consulted with a variety of fortune 500 software companies and startups alike, assisting in the development of security programs, threat modeling, secure application architecture and mitigation design for critical risk or high complexity vulnerabilities.

He has also worked with every major browser vendor, including TC39 and the Web Hypertext Application Technology Working Group (WHATWG)—organizations responsible for the upcoming version of JavaScript and the browser DOM spec.

Customer reviews

4.3 out of 5 stars
145 global ratings
Sign in to see customer reviews.