- Web Penetration Testing with Kali Linux(Third Edition)
- Gilberto Najera Gutierrez Juned Ahmed Ansari
- 343字
- 2021-06-24 18:44:48
Introduction to Penetration Testing and Web Applications
A web application uses the HTTP protocol for client-server communication and requires a web browser as the client interface. It is probably the most ubiquitous type of application in modern companies, from Human Resources' organizational climate surveys to IT technical services for a company's website. Even thick and mobile applications and many Internet of Things (IoT) devices make use of web components through web services and the web interfaces that are embedded into them.
Not long ago, it was thought that security was necessary only at the organization's perimeter and only at network level, so companies spent considerable amount of money on physical and network security. With that, however, came a somewhat false sense of security because of their reliance on web technologies both inside and outside of the organization. In recent years and months, we have seen news of spectacular data leaks and breaches of millions of records including information such as credit card numbers, health histories, home addresses, and the Social Security Numbers (SSNs) of people from all over the world. Many of these attacks were started by exploiting a web vulnerability or design failure.
Modern organizations acknowledge that they depend on web applications and web technologies, and that they are as prone to attack as their network and operating systems—if not more so. This has resulted in an increase in the number of companies who provide protection or defense services against web attacks, as well as the appearance or growth of technologies such as Web Application Firewall (WAF), Runtime Application Self-Protection (RASP), web vulnerability scanners, and source code scanners. Also, there has been an increase in the number of organizations that find it valuable to test the security of their applications before releasing them to end users, providing an opportunity for talented hackers and security professionals to use their skills to find flaws and provide advice on how to fix them, thereby helping companies, hospitals, schools, and governments to have more secure applications and increasingly improved software development practices.
- Linux設備驅動開發詳解(第2版)
- 從零開始寫Linux內核:一書學透核心原理與實現
- 嵌入式Linux系統開發:基于Yocto Project
- 巧學活用Windows 7
- 網絡操作系統教程:Windows Server 2016管理與配置
- 計算機系統:基于x86+Linux平臺
- 云原生落地:產品、架構與商業模式
- 操作系統分析
- iOS 8開發指南
- 計算機應用基礎(Windows 7+Office 2016)
- INSTANT Galleria Howto
- Distributed Computing with Go
- Hands-On GPU Programming with Python and CUDA
- Windows 10從新手到高手
- 電腦辦公(Windows 7 + Office 2013)入門與提高