نام کتاب
Hands-On Bug Hunting for Penetration Testers

A practical guide to help ethical hackers discover web application security flaws

Joseph Marshall

Paperback240 Pages
PublisherPackt
Edition1
LanguageEnglish
Year2018
ISBN9781789344202
1K
A2307
انتخاب نوع چاپ:
جلد سخت
532,000ت
0
جلد نرم
472,000ت
0
طلق پاپکو و فنر
482,000ت
0
مجموع:
0تومان
کیفیت متن:اورجینال انتشارات
قطع:B5
رنگ صفحات:رنگی با کادر / تصویر
پشتیبانی در روزهای تعطیل!
ارسال به سراسر کشور

#Bug_Hunting

#Penetration_Testers

#SQli

#NoSQLi

#XSS

#XXE

#CSRF

#PoC

#HTML

توضیحات

Detailed walkthroughs of how to discover, test, and document common web application vulnerabilities.


Key Features

  • Learn how to test for common bugs
  • Discover tools and methods for hacking ethically
  • Practice working through pentesting engagements step-by-step


Book Description

Bug bounties have quickly become a critical part of the security economy. This book shows you how technical professionals with an interest in security can begin productively―and profitably―participating in bug bounty programs.

You will learn about SQli, NoSQLi, XSS, XXE, and other forms of code injection. You'll see how to create CSRF PoC HTML snippets, how to discover hidden content (and what to do with it once it's found), and how to create the tools for automated pentesting workflows.

Then, you'll format all of this information within the context of a bug report that will have the greatest chance of earning you cash.

With detailed walkthroughs that cover discovering, testing, and reporting vulnerabilities, this book is ideal for aspiring security professionals. You should come away from this work with the skills you need to not only find the bugs you're looking for, but also the best bug bounty programs to participate in, and how to grow your skills moving forward in freelance security research.


What you will learn

  • Choose what bug bounty programs to engage in
  • Understand how to minimize your legal liability and hunt for bugs ethically
  • See how to take notes that will make compiling your submission report easier
  • Know how to take an XSS vulnerability from discovery to verification, and report submission
  • Automate CSRF PoC generation with Python
  • Leverage Burp Suite for CSRF detection
  • Use WP Scan and other tools to find vulnerabilities in WordPress, Django, and Ruby on Rails applications
  • Write your report in a way that will earn you the maximum amount of money


Who this book is for

This book is written for developers, hobbyists, pentesters, and anyone with an interest (and a little experience) in web application security.


Table of Contents

  1. Joining the Hunt
  2. Choosing Your Hunting Ground
  3. Preparing for an Engagement
  4. Unsanitized Data; An XSS Case Study
  5. SQL, Code Injection, and Scanners
  6. CSRF and Insecure Session Authentication
  7. Detecting XML External Entities
  8. Access Control and Security Through Obscurity
  9. Framework and Application-Specific Vulnerabilities
  10. Formatting Your Report
  11. Other Tools
  12. Other (Out of Scope) Vulnerabilities
  13. Going Further
  14. Assessment


About the Author

Joe Marshall is a web application developer and freelance writer, with credits from The Atlantic, Kirkus Review, and the SXSW film blog. He also enjoys moonlighting as a freelance security researcher, working with third-party vulnerability marketplaces such as Bugcrowd and Hackerone. His background and education include expertise in development, nonfiction writing, linguistics, and instruction/teaching. He lives in Austin, TX.

دیدگاه خود را بنویسید
نظرات کاربران (0 دیدگاه)
نظری وجود ندارد.
کتاب های مشابه
هک و امنیت
991
Hacking and Securing iOS Applications
552,000 تومان
هک و امنیت
1,117
The Art of Memory Forensics
1,326,000 تومان
هک و امنیت
505
Pentesting APIs
537,000 تومان
هک و امنیت
903
Dynamically Enabled Cyber Defense
588,000 تومان
Kubernetes
1,121
Learn Kubernetes Security
525,000 تومان
هک و امنیت
978
AWS Certified Security Study Guide
687,000 تومان
لینوکس
909
RHCSA Red Hat Enterprise Linux 9 Certification Study Guide
1,006,000 تومان
هک و امنیت
580
Computer Security
2,063,000 تومان
Cloud
4,850
Hybrid Cloud Security Patterns
438,000 تومان
هک و امنیت
1,056
Beginning Ethical Hacking with Kali Linux
714,000 تومان
قیمت
منصفانه
ارسال به
سراسر کشور
تضمین
کیفیت
پشتیبانی در
روزهای تعطیل
خرید امن
و آسان
آرشیو بزرگ
کتاب‌های تخصصی
هـر روز با بهتــرین و جــدیــدتـرین
کتاب های روز دنیا با ما همراه باشید
آدرس
پشتیبانی
مدیریت
ساعات پاسخگویی
درباره اسکای بوک
دسترسی های سریع
  • راهنمای خرید
  • راهنمای ارسال
  • سوالات متداول
  • قوانین و مقررات
  • وبلاگ
  • درباره ما
چاپ دیجیتال اسکای بوک. 2024-2022 ©