Contents:-
Web server hacking
Surveying the application
Attacking authentication
Attacking authorization
Attacking session state management
Input validation attacks
Attacking Web datastores
Attacking XML Web Services
Attacking Web application management
Hacking Web clients
Case studies
This book is divided into three parts:-
I: Reconnaissance
Casing the establishment in preparation for the big heist, and how to deny your
adversaries useful information at every turn.
II: The Attack
Leveraging the information gathered so far, we will orchestrate a carefully
calculated fusillade of attempts to gain unauthorized access to Web applications.
III: Appendixes
A collection of references, including a Web application security checklist
(Appendix A); a cribsheet of Web hacking tools and techniques (Appendix B); a
tutorial and sample scripts describing the use of the HTTP-hacking tool
libwhisker (Appendix C); step-by-step instructions on how to deploy the robust
IIS security filter UrlScan (Appendix D); and a brief word about the companion

No comments:
Post a Comment