官术网_书友最值得收藏!

Introduction to Penetration Testing and Web Applications

A web application uses the HTTP protocol for client-server communication and requires a web browser as the client interface. It is probably the most ubiquitous type of application in modern companies, from Human Resources' organizational climate surveys to IT technical services for a company's website. Even thick and mobile applications and many Internet of Things (IoT) devices make use of web components through web services and the web interfaces that are embedded into them.

Not long ago, it was thought that security was necessary only at the organization's perimeter and only at network level, so companies spent considerable amount of money on physical and network security. With that, however, came a somewhat false sense of security because of their reliance on web technologies both inside and outside of the organization. In recent years and months, we have seen news of spectacular data leaks and breaches of millions of records including information such as credit card numbers, health histories, home addresses, and the Social Security Numbers (SSNs) of people from all over the world. Many of these attacks were started by exploiting a web vulnerability or design failure.

Modern organizations acknowledge that they depend on web applications and web technologies, and that they are as prone to attack as their network and operating systems—if not more so. This has resulted in an increase in the number of companies who provide protection or defense services against web attacks, as well as the appearance or growth of technologies such as Web Application Firewall (WAF), Runtime Application Self-Protection (RASP), web vulnerability scanners, and source code scanners. Also, there has been an increase in the number of organizations that find it valuable to test the security of their applications before releasing them to end users, providing an opportunity for talented hackers and security professionals to use their skills to find flaws and provide advice on how to fix them, thereby helping companies, hospitals, schools, and governments to have more secure applications and increasingly improved software development practices.

主站蜘蛛池模板: 区。| 双鸭山市| 文水县| 扎赉特旗| 卢湾区| 郯城县| 吉首市| 越西县| 东乌珠穆沁旗| 凤庆县| 石泉县| 玉屏| 土默特右旗| 鲁山县| 霍邱县| 金门县| 景洪市| 遂川县| 张家港市| 大安市| 营口市| 泾川县| 汶川县| 榆社县| 沙湾县| 兴宁市| 汪清县| 云龙县| 通许县| 甘孜| 九台市| 虎林市| 昌宁县| 桐庐县| 利津县| 麻阳| 远安县| 罗平县| 淮安市| 镇平县| 大方县|