官术网_书友最值得收藏!

Introduction to Penetration Testing and Web Applications

A web application uses the HTTP protocol for client-server communication and requires a web browser as the client interface. It is probably the most ubiquitous type of application in modern companies, from Human Resources' organizational climate surveys to IT technical services for a company's website. Even thick and mobile applications and many Internet of Things (IoT) devices make use of web components through web services and the web interfaces that are embedded into them.

Not long ago, it was thought that security was necessary only at the organization's perimeter and only at network level, so companies spent considerable amount of money on physical and network security. With that, however, came a somewhat false sense of security because of their reliance on web technologies both inside and outside of the organization. In recent years and months, we have seen news of spectacular data leaks and breaches of millions of records including information such as credit card numbers, health histories, home addresses, and the Social Security Numbers (SSNs) of people from all over the world. Many of these attacks were started by exploiting a web vulnerability or design failure.

Modern organizations acknowledge that they depend on web applications and web technologies, and that they are as prone to attack as their network and operating systems—if not more so. This has resulted in an increase in the number of companies who provide protection or defense services against web attacks, as well as the appearance or growth of technologies such as Web Application Firewall (WAF), Runtime Application Self-Protection (RASP), web vulnerability scanners, and source code scanners. Also, there has been an increase in the number of organizations that find it valuable to test the security of their applications before releasing them to end users, providing an opportunity for talented hackers and security professionals to use their skills to find flaws and provide advice on how to fix them, thereby helping companies, hospitals, schools, and governments to have more secure applications and increasingly improved software development practices.

主站蜘蛛池模板: 邓州市| 汉寿县| 石门县| 海伦市| 河津市| 钟祥市| 镇赉县| 雷州市| 江达县| 金平| 南平市| 双流县| 视频| 海宁市| 内江市| 贵德县| 林口县| 克山县| 锡林浩特市| 晴隆县| 亚东县| 舟曲县| 晋州市| 若羌县| 临夏县| 苍溪县| 西峡县| 克东县| 百色市| 中山市| 上饶县| 化德县| 嘉黎县| 双流县| 榆社县| 毕节市| 海宁市| 射洪县| 时尚| 弋阳县| 宜良县|