- Web Penetration Testing with Kali Linux(Third Edition)
- Gilberto Najera Gutierrez Juned Ahmed Ansari
- 343字
- 2021-06-24 18:44:48
Introduction to Penetration Testing and Web Applications
A web application uses the HTTP protocol for client-server communication and requires a web browser as the client interface. It is probably the most ubiquitous type of application in modern companies, from Human Resources' organizational climate surveys to IT technical services for a company's website. Even thick and mobile applications and many Internet of Things (IoT) devices make use of web components through web services and the web interfaces that are embedded into them.
Not long ago, it was thought that security was necessary only at the organization's perimeter and only at network level, so companies spent considerable amount of money on physical and network security. With that, however, came a somewhat false sense of security because of their reliance on web technologies both inside and outside of the organization. In recent years and months, we have seen news of spectacular data leaks and breaches of millions of records including information such as credit card numbers, health histories, home addresses, and the Social Security Numbers (SSNs) of people from all over the world. Many of these attacks were started by exploiting a web vulnerability or design failure.
Modern organizations acknowledge that they depend on web applications and web technologies, and that they are as prone to attack as their network and operating systems—if not more so. This has resulted in an increase in the number of companies who provide protection or defense services against web attacks, as well as the appearance or growth of technologies such as Web Application Firewall (WAF), Runtime Application Self-Protection (RASP), web vulnerability scanners, and source code scanners. Also, there has been an increase in the number of organizations that find it valuable to test the security of their applications before releasing them to end users, providing an opportunity for talented hackers and security professionals to use their skills to find flaws and provide advice on how to fix them, thereby helping companies, hospitals, schools, and governments to have more secure applications and increasingly improved software development practices.
- 30天自制操作系統
- Getting Started with oVirt 3.3
- Learning Windows Server Containers
- 無蘋果不生活 OS X Mountain Lion隨身寶典
- 嵌入式Linux系統開發:基于Yocto Project
- Instant Handlebars.js
- 嵌入式應用程序設計綜合教程(微課版)
- Instant Optimizing Embedded Systems using Busybox
- VMware NSX Cookbook
- 從實踐中學習Kali Linux無線網絡滲透測試
- iOS 8開發指南
- VMware Horizon View Essentials
- OpenStack Essentials(Second Edition)
- Linux內核修煉之道
- Linux內核分析及應用