0
نام کتاب
Bug Bounty Bootcamp

The Guide to Finding and Reporting Web Vulnerabilities

Vickie Li

Paperback418 Pages
PublisherNo Starch Press
Edition1
LanguageEnglish
Year2021
ISBN9781718501546
10
7K
A70
انتخاب نوع چاپ:
جلد سخت
1,113,000ت
0
جلد نرم
983,000ت
0
طلق پاپکو و فنر
1,003,000ت
0
مجموع:
0تومان
کیفیت متن:اورجینال انتشارات
قطع:B5
رنگ صفحات:سیاه و سفید
پشتیبانی در روزهای تعطیل!
ارسال به سراسر کشور

#Bug_Bounty

#Hack

#Hacker

#Hacking

#Security

#Web_applications

#Bounty

#Hunting

#Bug

#Cybersecurity

توضیحات

🧠 کتاب Bug Bounty Bootcamp بهت یاد میده چطور وب اپلیکیشن‌ها رو هک کنی. تو یاد می‌گیری چطور روی یک هدف شناسایی (reconnaissance) انجام بدی، چطور آسیب‌پذیری‌ها رو تشخیص بدی و چطور ازشون بهره‌برداری (exploit) کنی. همچنین یاد می‌گیری چطور در برنامه‌های باگ بانتی که توسط شرکت‌ها برای پاداش دادن به متخصصان امنیتی در ازای پیدا کردن باگ‌ها طراحی شدن، حرکت کنی.


🧩 برنامه‌های باگ بانتی برنامه‌هایی هستن که توسط شرکت‌ها حمایت میشن و از محقق‌ها دعوت می‌کنن روی اپلیکیشن‌هاشون دنبال آسیب‌پذیری بگردن و در ازای یافته‌هاشون پاداش بگیرن. این کتاب طراحی شده تا به افراد مبتدی که تجربه امنیتی کمی دارن یا اصلاً ندارن کمک کنه هک وب رو یاد بگیرن، باگ پیدا کنن و در این صنعت رو به رشد و پردرآمد رقابتی باقی بمونن.


🚀 تو مسیر کتاب، اول یاد می‌گیری چطور یک برنامه رو انتخاب کنی، چطور گزارش‌های باگ باکیفیت بنویسی و چطور روابط حرفه‌ای در این صنعت رو حفظ کنی. بعدش یاد می‌گیری چطور یک لابراتوار هک وب راه‌اندازی کنی و با استفاده از پروکسی ترافیک رو ضبط کنی. در بخش سوم کتاب، مکانیزم آسیب‌پذیری‌های رایج وب مثل XSS، تزریق SQL و template injection رو بررسی می‌کنی و یاد می‌گیری چطور پیداشون کنی و از محافظت‌های رایج عبور کنی. همچنین یاد می‌گیری چطور چند باگ رو با هم زنجیره کنی تا تأثیر آسیب‌پذیری‌هات بیشتر بشه.


🧪 در نهایت، کتاب به سراغ تکنیک‌های پیشرفته‌ای میره که معمولاً در کتاب‌های مقدماتی کمتر پوشش داده می‌شن اما برای هک وب اپلیکیشن‌ها ضروری هستن. یاد می‌گیری چطور اپلیکیشن‌های موبایل رو هک کنی، کد سورس یک اپلیکیشن رو برای مشکلات امنیتی بررسی کنی، در APIها آسیب‌پذیری پیدا کنی و فرآیند هک رو خودکار (automate) کنی. در پایان کتاب، ابزارها و تکنیک‌های لازم برای تبدیل شدن به یک هکر وب توانمند و پیدا کردن باگ در برنامه‌های باگ بانتی رو به دست میاری.


📚 فهرست مطالب

🧭 بخش اول: صنعت (THE INDUSTRY)

فصل 1: انتخاب برنامه باگ بانتی

فصل 2: حفظ و ادامه موفقیت در مسیر


🧭 بخش دوم: شروع کار (GETTING STARTED)

فصل 3: اینترنت چگونه کار می‌کند

فصل 4: راه‌اندازی محیط کار و رهگیری ترافیک (Traffic Interception)

فصل 5: شناسایی و Recon در هک وب


🧭 بخش سوم: آسیب‌پذیری‌های وب (WEB VULNERABILITIES)

فصل 6: اسکریپت‌نویسی متقاطع (Cross-Site Scripting - XSS)

فصل 7: ریدایرکت باز (Open Redirects)

فصل 8: کلیک‌جکینگ (Clickjacking)

فصل 9: جعل درخواست بین‌سایتی (Cross-Site Request Forgery - CSRF)

فصل 10: ارجاع مستقیم ناامن به اشیاء (Insecure Direct Object References - IDOR)

فصل 11: تزریق SQL (SQL Injection)

فصل 12: شرایط رقابتی (Race Conditions)

فصل 13: جعل درخواست سمت سرور (Server-Side Request Forgery - SSRF)

فصل 14: عدم امن‌سازی در سریال‌سازی (Insecure Deserialization)

فصل 15: موجودیت خارجی XML (XML External Entity - XXE)

فصل 16: تزریق قالب (Template Injection)

فصل 17: خطاهای منطق اپلیکیشن و کنترل دسترسی شکسته

فصل 18: اجرای کد از راه دور (Remote Code Execution - RCE)

فصل 19: آسیب‌پذیری‌های سیاست مبدأ یکسان (Same-Origin Policy)

فصل 20: مشکلات امنیتی ورود یکپارچه (Single Sign-On - SSO)

فصل 21: افشای اطلاعات (Information Disclosure)


🧭 بخش چهارم: تکنیک‌های حرفه‌ای (EXPERT TECHNIQUES)

فصل 22: بازبینی کد (Code Review)

فصل 23: هک اپلیکیشن‌های اندروید

فصل 24: هک API

فصل 25: کشف خودکار آسیب‌پذیری با فازرها (Fuzzers)



🗣️ نظرات (Review)

💬 «این یک کتاب واقعاً خوب برای شروع در باگ بانتیه، در زمانی منتشر شده که همچین منبعی واقعاً لازم بود. می‌تونی هرچقدر دوره هک اخلاقی ببینی، اما وقتی به باگ بانتی می‌رسی، اطلاعات و ابزارها اونقدر زیاد می‌شن که شروع کار سخت می‌شه. این کتاب باید اولین کتابی باشه که هر کسی می‌خونه که می‌خواد وارد باگ بانتی بشه.»

— الکس/مولدویچ، The Security Noob


💬 «Bug Bounty Bootcamp باید روی میز هر هکری باشه. ویکِی لی به یک سؤال مهم جواب می‌ده: بعد از پیدا کردن اولین آسیب‌پذیری چی کار کنی؟ با توضیح نوشتن گزارش باگ و تعامل با مشتری، یک راهنمای عالی برای شروع مسیر امنیتی ارائه می‌ده.»

— اندرو اور، ویراستار The Mac Observer


💬 «این کتاب برای مبتدی‌های باگ بانتی خیلی خوبه. درباره آسیب‌پذیری‌های وب، پلتفرم‌های باگ بانتی، نحوه کار اینترنت و حتی کسب درآمد از امن‌تر کردن وب توضیح می‌ده.»

— The Digital Empress


💬 «کتاب خیلی شفاف و قدم‌به‌قدم توضیح داده که چطور باگ پیدا کنیم و گزارش بدیم. حتی وقتی داشتم می‌خوندم وسوسه شدم خودم شروع کنم.»

— سینتیا برامفیلد، Google Security Engineer


💬 «این کتاب فقط بخش فنی رو آموزش نمی‌ده، بلکه متدولوژی کار و ادامه مسیر تست رو هم یاد می‌ده. توضیحات از پایه تا پیشرفته خیلی واضح هستن.»

— دیوید توماشچیک، Google Security Engineer


💬 «واقعاً پیشنهاد می‌کنم این کتاب رو بخونید.»

— @HolyBugx


💬 «واقعاً یک گوهر ناب بود. خیلی چیزها ازش یاد گرفتم.»

— آکاش چودری


💬 «عالی نوشته شده، واضح، خلاصه و کاربردی. برای همه سطح‌ها نکته‌های ارزشمند داره.»

— داگلاس کمپبل


💬 «این کتاب دقیقاً راهنمای شروع باگ بانتیه.»

— متاکیوریتی


💬 «بهترین منبع برای شروع هک وب. مفاهیم پیچیده رو ساده توضیح داده و قدم‌به‌قدم جلو می‌ره.»

— AntiRuse


💬 «حتماً پیشنهادش می‌کنم.»

— Michael


💬 «این کتاب فقط برای باگ بانتی نیست، برای همه متخصصان IT مفیده. از XSS تا API هک و Fuzzerها رو پوشش می‌ده.»

— Jess Vachon


💬 «من از هیچ به پیدا کردن اولین باگ رسیدم. توضیح گزارش‌دهی و ارتباط با شرکت‌ها خیلی مفید بود.»

— Anthony Ware


💬 «برای یادگیری امنیت وب خیلی خوبه و مسیر درستی برای شروع می‌ده.»

— Riley A.


💬 «یک راهنمای قدم‌به‌قدم برای رسیدن به اولین باگ بانتی.»

— Jessica W.


💬 «بعد از The Web Application Hacker’s Handbook مدت‌ها بود همچین منبع جامعی ندیده بودم.»

— Bug Bounty Reports Explained


💬 «یک همراه عالی برای کتاب قبلی نویسنده و باید در کتابخانه هر کسی باشه.»

— jub0bs


💬 «یک راهنمای خوب برای ورود به هک API.»

— Dana Epp


👩‍💻 درباره نویسنده

🧾 ویکی لی یک توسعه‌دهنده و محقق امنیتیه که تجربه زیادی در پیدا کردن و بهره‌برداری از آسیب‌پذیری‌های وب اپلیکیشن‌ها داره. او آسیب‌پذیری‌هایی رو برای شرکت‌هایی مثل Facebook، Yelp و Starbucks گزارش کرده و در چندین برنامه آموزشی آنلاین و وبلاگ فنی مشارکت داشته است.


Bug Bounty Bootcampteaches you how to hack web applications. You will learn how to perform reconnaissance on a target, how to identify vulnerabilities, and how to exploit them. You'll also learn how to navigate bug bounty programs set up by companies to reward security professionals for finding bugs in their web applications.


Bug bounty programs are company-sponsored programs that invite researchers to search for vulnerabilities on their applications and reward them for their findings. This book is designed to help beginners with little to no security experience learn web hacking, find bugs, and stay competitive in this booming and lucrative industry. 

 

You'll start by learning how to choose a program, write quality bug reports, and maintain professional relationships in the industry. Then you'll learn how to set up a web hacking lab and use a proxy to capture traffic. In Part 3 of the book, you'll explore the mechanisms of common web vulnerabilities, like XSS, SQL injection, and template injection, and receive detailed advice on how to find them and bypass common protections. You'll also learn how to chain multiple bugs to maximize the impact of your vulnerabilities.

 

Finally, the book touches on advanced techniques rarely covered in introductory hacking books but that are crucial to understand to hack web applications. You'll learn how to hack mobile apps, review an application's source code for security issues, find vulnerabilities in APIs, and automate your hacking process. By the end of the book, you'll have learned the tools and techniques necessary to be a competent web hacker and find bugs on a bug bounty program.


Contents

PART I: THE INDUSTRY

Chapter 1: Picking a Bug Bounty Program

Chapter 2: Sustaining Your Success


PART II: GETTING STARTED

Chapter 3: How the Internet Works

Chapter 4: Environmental Setup and Traffic Interception

Chapter 5: Web Hacking Reconnaissance


PART III: WEB VULNERABILITIES

Chapter 6: Cross-Site Scripting

Chapter 7: Open Redirects

Chapter 8: Clickjacking

Chapter 9: Cross-Site Request Forgery

Chapter 10: Insecure Direct Object References

Chapter 11: SQL Injection

Chapter 12: Race Conditions

Chapter 13: Server-Side Request Forgery

Chapter 14: Insecure Deserialization

Chapter 15: XML External Entity

Chapter 16: Template Injection

Chapter 17: Application Logic Errors and Broken Access Control

Chapter 18: Remote Code Execution

Chapter 19: Same-Origin Policy Vulnerabilities

Chapter 20: Single-Sign-On Security Issues

Chapter 21: Information Disclosure


PART IV: EXPERT TECHNIQUES

Chapter 22: Conducting Code Reviews

Chapter 23: Hacking Android Apps

Chapter 24: API Hacking

Chapter 25: Automatic Vulnerability Discovery Using Fuzzers


Review

"A really good book for getting started in Bug Bounty, out at a time when something like this was really needed. You can take as many ethical hacking courses as you want, but when it comes to bug bounty, there is so much information and tools it can be imitating to start . . . This really should be the first book read by ANYONE looking to start in the bug bounty game."

—Alex/Muldwych, The Security Noob


"Bug Bounty Bootcamp should be on every hacker's shelf. Vickie Li answers an important question: 'So you found your first flaw, what's next?' By explaining how to write a bug report and interact with clients, she presents a wonderful guide on starting your security career."

—Andrew Orr, Associate Editor, The Mac Observer


"I have enjoyed Bug Bounty Bootcamp over the past few weeks and this is great for bug bounty beginners like myself. Anyone who is interested in learning more about different web vulnerabilities, bug bounty platforms, how the internet works, and how to make money making the web safer this is the book for you. Thanks to Vickie for writing such a great book!"

—The Digital Empress, YouTuber and Blogger


"Bug Bounty Bootcamp by Vickie Li is a thorough and masterful explanation for how to find bugs and responsibly report them. It is written so clearly, and provides such useful step-by-step instructions that as I was reading it, I was tempted to start hunting for bugs myself."

—Cynthia Brumfield, President, DCT-Associates


"Bug Bounty Bootcamp is a great resource for those who want to participate in Bug Bounties because it not only teaches you about the technical aspects, but helps you develop a methodology and sustain your testing. Some technology knowledge is assumed, but it does a solid job of describing the relevant vulnerability types from first principles, so it can be a strong resource for those new to the security space. The writing style is clear and to the point."

—David Tomaschik, Security Engineer at Google, Blogger at System Overlord


"I highly suggest reading Bug Bounty Bootcamp."

—@HolyBugx


"Pure GEM. Learned a lot of things from her book."

—Aakash Choudhary, @LearnerHunter


"Loved the book. Well written, clear, concise, and easy to follow. Everyone from the beginner bug hunter to the seasoned pro will find a nugget, some nuggets or just pure nuggets of amazing information, tips and advice."

—Douglas Campbell, Advanced Reviewer


"The only book you need to get started in bug bounty is @vickieli7's book coming out from @nostarch, Bug Bounty Bootcamp. It's a detailed how-to with lots of technical how-to steps."

—Metacurity, Top Infosec News Destination, @Metacurity


"The new go-to resource for a beginner in web app hacking . . . I recommend this book before anything else for a beginner trying to learn web security. Vickie provides an excellent delivery of breaking down complex concepts that makes it easy to comprehend. Also, the step by step guidance of exploiting a vulnerability is fantastic to refer back to . . . If you are a complete beginner and feel confused or lost in all of the information out there then stop, grab this book, read through it once, then use it as your guide."

—AntiRuse, @AntiRuse, Blogger


"Definitely recommend it!"

—Michael, @DoAbarrel_Troll


"Bug Bounty Bootcamp is *the* book for everyone in Information Technology, not just those interested in bug bounties . . . This easy-to-read guide breaks down complicated topics into a simple progression through technical concepts. From a foundational overview of the industry and how to get started, the reader progresses from Cross Site Scripting all the way through to API hacking and use of Fuzzers. Vickie Li has done a tremendous service to information security by sharing her expert understanding of bug hunting in a highly accessible way. Recommended reading for all IT professionals, new or veteran."

—Jess Vachon, Advanced Reviewer


"Vicki Li’s book took me from knowing nothing about bug bounties, to finding my first bug. Li goes over the process of bug bounties, writing reports, and how to make relationships with companies. Li also has expert techniques that will help your automate your hacking experience and even hacking android apps."

—Anthony Ware, Advanced Reviewer


"For anyone interested in bug detection of web services, this book is for you. It takes an approach that is enjoyable for all levels. It covers the essentials for understanding web servers and why the assortment of vulnerabilities exists with steps in what to look for in approaching those security risks. It’s not going to make you an expert overnight, but it will set you on the path towards success, bypassing the common mistakes where others have fallen."

—Riley A., Advanced Reviewer


"Step-by-step instructions to achieve your first bug bounty and a great book to reference as a security professional. This book will give insight to how bug bounty programs operate and provide resources to learn programming, security tools, and breakdown OWASP top 10 vulnerabilities."

—Jessica W., Advanced Reviewer


"Since reading The Web Application Hacker's Handbook a few years ago, I haven't seen that much web security knowledge organized in one place as in Bug Bounty Bootcamp. Vickie did a fantastic job of covering many different vulnerability classes that are important for offensively testing web applications. Explanations are made so that beginners would understand them but I was also able to find some inspirations each time I looked at the book when testing a specific vulnerability class. I highly recommend Bug Bounty Bootcamp for everyone who wants to learn about web security."

—Bug Bounty Reports Explained, YouTuber and Advanced Reviewer


"A great companion to @yaworsk's earlier book, Real-World Bounty Hunting (also by

@nostarch), and deserves a place on your bookshelf."

—@jub0bs


"An informative and well-written guide that should be of interest to anyone considering a career in API hacking through bug bounty hunting."

—Dana Epp, Security Boulevard


About the Author

Vickie Li is a developer and security researcher experienced in finding and exploiting vulnerabilities in web applications. She has reported vulnerabilities to firms such as Facebook, Yelp and Starbucks and contributes to a number of online training programs and technical blogs. 

دیدگاه خود را بنویسید
نظرات کاربران (1 دیدگاه)
علیرضا میرقربانی
2024-01-22

این کتاب فوق العادست

کتاب های مشابه
هک و امنیت
1,101
Antivirus Bypass Techniques
588,000 تومان
هک و امنیت
763
Practical Security for Agile and DevOps
580,000 تومان
هک و امنیت
1,492
Cloud Penetration Testing for Red Teamers
677,000 تومان
هک و امنیت
978
CRISC Certified in Risk and Information Systems Control
636,000 تومان
هک و امنیت
3,534
The Web Application Hacker's Handbook
1,863,000 تومان
هک و امنیت
1,956
Web Hacking Arsenal
1,441,000 تومان
هک و امنیت
476
Hands-On Ethical Hacking Tactics
943,000 تومان
Network
553
Network Forensics
1,319,000 تومان
هک و امنیت
1,652
Learning Malware Analysis
1,100,000 تومان
هک و امنیت
995
Phishing and Communication Channels
568,000 تومان
قیمت
منصفانه
ارسال به
سراسر کشور
تضمین
کیفیت
پشتیبانی در
روزهای تعطیل
خرید امن
و آسان
آرشیو بزرگ
کتاب‌های تخصصی
هـر روز با بهتــرین و جــدیــدتـرین
کتاب های روز دنیا با ما همراه باشید
آدرس
پشتیبانی
مدیریت
ساعات پاسخگویی
درباره اسکای بوک
دسترسی های سریع
  • راهنمای خرید
  • راهنمای ارسال
  • سوالات متداول
  • قوانین و مقررات
  • وبلاگ
  • درباره ما
چاپ دیجیتال اسکای بوک. 2024-2022 ©