HACKING EXPOSED WEB APPLICATIONS, 3rd Edition

17:54 |



HACKING EXPOSED WEB APPLICATIONS, 3rd Edition

HACKING EXPOSED WEB APPLICATIONS, 3rd Edition
Joel Scambray | McGraw-Hill Osborne Media | 2011-10-07 | 482 pages | English | PDF

The latest Web app attacks and countermeasures from world-renowned practitioners

Protect your Web applications from malicious attacks by mastering the weapons and thought processes of today's hacker. Written by recognized security practitioners and thought leaders, Hacking Exposed Web Applications, Third Edition is fully updated to cover new infiltration methods and countermeasures. Find out how to reinforce authentication and authorization, plug holes in Firefox and IE, reinforce against injection attacks, and secure Web 2.0 features. Integrating security into the Web development lifecycle (SDL) and into the broader enterprise information security program is also covered in this comprehensive resource.




  • Get full details on the hacker's footprinting, scanning, and profiling tools, including SHODAN, Maltego, and OWASP DirBuster
  • See new exploits of popular platforms like Sun Java System Web Server and Oracle WebLogic in operation
  • Understand how attackers defeat commonly used Web authentication technologies
  • See how real-world session attacks leak sensitive data and how to fortify your applications
  • Learn the most devastating methods used in today's hacks, including SQL injection, XSS, XSRF, phishing, and XML injection techniques
  • Find and fix vulnerabilities in ASP.NET, PHP, and J2EE execution environments
  • Safety deploy XML, social networking, cloud computing, and Web 2.0 services
  • Defend against RIA, Ajax, UGC, and browser-based, client-side exploits
  • Implement scalable threat modeling, code review, application scanning, fuzzing, and security testing procedures


Download here:




Read more…

Google Hacking for Penetration Testers, Volume 2

22:02 |
Google Hacking for Penetration Testers, Volume 1



Product Description

Google, the most popular search engine worldwide, provides web surfers with an easy-to-use guide to the Internet, with web and image searches, language translation, and a range of features that make web navigation simple enough for even the novice user. What many users don't realize is that the deceptively simple components that make Google so easy to use are the same features that generously unlock security flaws for the malicious hacker. Vulnerabilities in website security can be discovered through Google hacking, techniques applied to the search engine by computer criminals, identity thieves, and even terrorists to uncover secure information. This book beats Google hackers to the punch, equipping web administrators with penetration testing applications to ensure their site is invulnerable to a hacker's search. 




Penetration Testing with Google Hacks explores the explosive growth of a technique known as "Google Hacking." When the modern security landscape includes such heady topics as "blind SQL injection" and "integer overflows," it's refreshing to see such a deceptively simple tool bent to achieve such amazing results; this is hacking in the purest sense of the word. Readers will learn how to torque Google to detect SQL injection points and login portals, execute port scans and CGI scans, fingerprint web servers, locate incredible information caches such as firewall and IDS logs, password databases, SQL dumps and much more - all without sending a single packet to the target! Borrowing the techniques pioneered by malicious "Google hackers," this talk aims to show security practitioners how to properly protect clients from this often overlooked and dangerous form of information leakage.



*First book about Google targeting IT professionals and security leaks through web browsing.



*Author Johnny Long, the authority on Google hacking, will be speaking about "Google Hacking" at the Black

Hat 2004 Briefing. His presentation on penetrating security flaws with Google is expected to create a lot of buzz and exposure for the topic.



*Johnny Long's Web site hosts the largest repository of Google security exposures and is the most popular destination for security professionals who want to learn about the dark side of Google.

About the Author

Johnny Long is a Christian by grace, a professional hacker by trade, a pirate by blood, a ninja in training, a security researcher and author. He can be found lurking at his website (http://johnny.ihackstuff.com). He is the founder of Hackers For Charity(http://ihackcharities.org), an organization that provides hackers with job experience while leveraging their skills for charities that need those skills.


Download here:




Read more…

Web Security, Privacy and Commerce, 2nd Edition

05:44 |
Web Security, Privacy and Commerce, 2nd Edition

Product Description

Since the first edition of this classic reference was published, World Wide Web use has exploded and e-commerce has become a daily part of business and personal life. As Web use has grown, so have the threats to our security and privacy--from credit card fraud to routine invasions of privacy by marketers to web site defacements to attacks that shut down popular web sites.
Web Security, Privacy & Commerce goes behind the headlines, examines the major security risks facing us today, and explains how we can minimize them. It describes risks for Windows and Unix, Microsoft Internet Explorer and Netscape Navigator, and a wide range of current programs and products. In vast detail, the book covers:

  • Web technology--The technological underpinnings of the modern Internet and the cryptographic foundations of e-commerce are discussed, along with SSL (the Secure Sockets Layer), the significance of the PKI (Public Key Infrastructure), and digital identification, including passwords, digital signatures, and biometrics.
  • Web privacy and security for users--Learn the real risks to user privacy, including cookies, log files, identity theft, spam, web logs, and web bugs, and the most common risk, users' own willingness to provide e-commerce sites with personal information. Hostile mobile code in plug-ins, ActiveX controls, Java applets, and JavaScript, Flash, and Shockwave programs are also covered.
  • Web server security--Administrators and service providers discover how to secure their systems and web services. Topics include CGI, PHP, SSL certificates, law enforcement issues, and more.
  • Web content security--Zero in on web publishing issues for content providers, including intellectual property, copyright and trademark issues, P3P and privacy policies, digital payments, client-side digital signatures, code signing, pornography filtering and PICS, and other controls on web content.
Nearly double the size of the first edition, this completely updated volume is destined to be the definitive reference on Web security risks and the techniques and technologies you can use to protect your privacy, your organization, your system, and your network.

About the Author

Simson Garfinkel, CISSP, is a journalist, entrepreneur, and international authority on computer security. Garfinkel is chief technology officer at Sandstorm Enterprises, a Boston-based firm that develops state-of-the-art computer security tools. Garfinkel is also a columnist for Technology Review Magazine and has written for more than 50 publications, including Computerworld, Forbes, and The New York Times. He is also the author of Database Nation; Web Security, Privacy, and Commerce; PGP: Pretty Good Privacy; and seven other books. Garfinkel earned a master's degree in journalism at Columbia University in 1988 and holds three undergraduate degrees from MIT. He is currently working on his doctorate at MIT's Laboratory for Computer Science.


Gene Spafford, Ph.D., CISSP, is an internationally renowned scientist and educator who has been working in information security, policy, cybercrime, and software engineering for nearly two decades. He is a professor at Purdue University and is the director of CERIAS, the world's premier multidisciplinary academic center for information security and assurance. Professor Spafford and his students have pioneered a number of technologies and concepts well-known in security today, including the COPS and Tripwire tools, two-stage firewalls, and vulnerability databases. Spaf, as he is widely known, has achieved numerous professional honors recognizing his teaching, his research, and his professional service. These include being named a fellow of the AAAS, the ACM, and the IEEE; receiving the National Computer Systems Security Award; receiving the William Hugh Murray Medal of the NCISSE; election to the ISSA Hall of Fame; and receiving the Charles Murphy Award at Purdue. He was named a CISSP, honoris causa in 2000. In addition to over 100 technical reports and articles on his research, Spaf is also the coauthor of Web Security, Privacy, and Commerce, and was the consulting editor for Computer Crime: A Crimefighters Handbook (both from O'Reilly).

Download here:


Read more…

Ajax Security

17:40 |
Ajax Security



Product Description

The Hands-On, Practical Guide to Preventing Ajax-Related Security Vulnerabilities


More and more Web sites are being rewritten as Ajax applications; even traditional desktop software is rapidly moving to the Web via Ajax. But, all too often, this transition is being made with reckless disregard for security. If Ajax applications aren’t designed and coded properly, they can be susceptible to far more dangerous security vulnerabilities than conventional Web or desktop software. Ajax developers desperately need guidance on securing their applications: knowledge that’s been virtually impossible to find, until now.
            Ajax Security systematically debunks today’s most dangerous myths about Ajax security, illustrating key points with detailed case studies of actual exploited Ajax vulnerabilities, ranging from MySpace’s Samy worm to MacWorld’s conference code validator. Even more important, it delivers specific, up-to-the-minute recommendations for securing Ajax applications in each major Web programming language and environment, including .NET, Java, PHP, and even Ruby on Rails. You’ll learn how to:




·        Mitigate unique risks associated with Ajax, including overly granular Web services, application control flow tampering, and manipulation of program logic
·        Write new Ajax code more safely—and identify and fix flaws in existing code
·        Prevent emerging Ajax-specific attacks, including JavaScript hijacking and persistent storage theft
·        Avoid attacks based on XSS and SQL Injection—including a dangerous SQL Injection variant that can extract an entire backend database with just two requests
·        Leverage security built into Ajax frameworks like Prototype, Dojo, and ASP.NET AJAX Extensions—and recognize what you still must implement on your own
·        Create more secure “mashup” applications


Ajax Security will be an indispensable resource for developers coding or maintaining Ajax applications; architects and development managers planning or designing new Ajax software, and all software security professionals, from QA specialists to penetration testers.

About the Author

Billy Hoffman is the lead researcher for HP Security Labs of HP Software. At HP, Billy focuses on JavaScript source code analysis, automated discovery of Web application vulnerabilities, and Web crawling technologies. He has worked in the security space since 2001 after he wrote an article on cracking software for 2600, “The Hacker Quarterly,” and learned that people would pay him to be curious. Over the years Billy has worked a variety of projects including reverse engineering file formats, micro-controllers, JavaScript malware, and magstripes. He is the creator of Stripe Snoop, a suite of research tools that captures, modifies, validates, generates, analyzes, and shares data from magstripes. Billy’s work has been featured in WiredMake magazine, Slashdot, G4TechTV, and in various other journals and Web sites. Billy is a regular presenter at hacker conferences including Toorcon, Shmoocon, Phreaknic, Summercon, and Outerz0ne and is active in the South East hacking scene. Occasionally the suits make him take off the black t-shirt and he speaks at more mainstream security events including RSA, Infosec, AJAXWorld, and Black Hat. Billy graduated from the Georgia Institute of Technology in 2005 with a BS in Computer Science with specializations in networking and embedded systems. He lives in Atlanta with his wife and two tubby and very spoiled cats.



Bryan Sullivan is a software development manager for the Application Security Center division of HP Software. He has been a professional software developer and development manager for over 12 years, with the last five years focused on the Internet security software industry. Prior to HP, Bryan was a security researcher for SPI Dynamics, a leading Web application security company acquired by HP in August 2007.While at SPI, he created the DevInspect product, which analyzes Web applications for security vulnerabilities during development. Bryan is a frequent speaker at industry events, most recently AjaxWorld, Black Hat, and RSA. He was involved in the creation of the Application Vulnerability Description Language (AVDL) and has three patents on security assessment and remediation methodologies pending review. He is a graduate of the Georgia Institute of Technology
with a BS in Applied Mathematics. When he’s not trying to break the Internet, Bryan spends as much time as he can on the golf links. If any Augusta National members are reading this, Bryan would be exceedingly happy to tell you everything he knows about Ajax security over a round or two.


Download here:




Read more…

Professional Pen Testing for Web Applications (Hack ebook)

20:44 |
Professional Pen Testing for Web Applications (Programmer to Programmer)



Product Description

There is no such thing as "perfect security" when it comes to keeping all systems intact and functioning properly. Good penetration (pen) testing creates a balance that allows a system to be secure while simultaneously being fully functional. With this book, you'll learn how to become an effective penetrator (i.e., a white hat or ethical hacker) in order to circumvent the security features of a Web application so that those features can be accurately evaluated and adequate security precautions can be put in place.




After a review of the basics of web applications, you'll be introduced to web application hacking concepts and techniques such as vulnerability analysis, attack simulation, results analysis, manuals, source code, and circuit diagrams. These web application hacking concepts and techniques will prove useful information for ultimately securing the resources that need your protection.



What you will learn from this book

* Surveillance techniques that an attacker uses when targeting a system for a strike

* Various types of issues that exist within the modern day web application space

* How to audit web services in order to assess areas of risk and exposure

* How to analyze your results and translate them into documentation that is useful for remediation

* Techniques for pen-testing trials to practice before a live project



Who this book is for



This book is for programmers, developers, and information security professionals who want to become familiar with web application security and how to audit it.



Wrox Professional guides are planned and written by working programmers to meet the real-world needs of programmers, developers, and IT professionals. Focused and relevant, they address the issues technology professionals face every day. They provide examples, practical solutions, and expert education in new technologies, all designed to help programmers do a better job.

From the Back Cover

There is no such thing as "perfect security" when it comes to keeping all systems intact and functioning properly. Good penetration (pen) testing creates a balance that allows a system to be secure while simultaneously being fully functional. With this book, you'll learn how to become an effective penetrator (i.e., a white hat or ethical hacker) in order to circumvent the security features of a Web application so that those features can be accurately evaluated and adequate security precautions can be put in place.

After a review of the basics of web applications, you'll be introduced to web application hacking concepts and techniques such as vulnerability analysis, attack simulation, results analysis, manuals, source code, and circuit diagrams. These web application hacking concepts and techniques will prove useful information for ultimately securing the resources that need your protection.

What you will learn from this book


  • Surveillance techniques that an attacker uses when targeting a system for a strike
  • Various types of issues that exist within the modern day web application space
  • How to audit web services in order to assess areas of risk and exposure
  • How to analyze your results and translate them into documentation that is useful for remediation
  • Techniques for pen-testing trials to practice before a live project
Who this book is for

This book is for programmers, developers, and information security professionals who want to become familiar with web application security and how to audit it.

Wrox Professional guides are planned and written by working programmers to meet the real-world needs of programmers, developers, and IT professionals. Focused and relevant, they address the issues technology professionals face every day. They provide examples, practical solutions, and expert education in new technologies, all designed to help programmers do a better job.


Download here:




Read more…

HackNotes Web Security Pocket Reference

20:33 |
































Introduction



Web applications security and Web security in general are some of the most hottest topics in the InfoSec community. The rise of both vulnerabilities and security products in this IS sector clearly shows the importance of having the Web part of our lives secure. The book I'm taking a look at today is a part of Hack Notes series that carry on with the Hacking Exposed fame.





About the author



Mike Shema is a principle consultant and trainer for Foundstone, Inc. He is co-author of Hacking Exposed Web Application and Anti Hacker Tool Kit. In his professional line of duty, he has performed security assessments of a number of networks and Web applications.



Inside the book



The book is divided into three thematical parts, each containing a large portion of both theoretical, as well as practical web security situations. The first part incorporates introduction into web hacking and penetration methodologies. The topics covered within these chapters are mainly related to reconnaissance testing of applications and web services. Afterwards, in a chapter effectively titled "Critical hacks and defenses", the author traverses trough well known types of attacks including cross site scripting, SQL injection, session attacks and provides information on issues such as input validation, token analysis and XML services. What comes very valuable to the reader, are those numerous tables containing easily browsable info on stuff like Perl Regex, common input validation tests, SQL injections strings and common database defaults.



The second part of the book strives to provide the administrator all the things he/she should be aware while working in a Web environment. For the start, the author covers methods of vulnerability assessment and guides the reader through all the popular web security tools. Three vulnerability scanners (Whisker,Nikto and Nessus) and three assessment tools (Achilles, WebProxy and Curl) are featured in this section. Each of these tools is covered on a couple of pages accompanied with the appropriate screenshots. From the hardening point of view, readers are presented with couple of very useful checklists that focus on the two most popular Web servers around - Apache and Microsoft IIS.



Because of its importance, besides the checklists I mentioned above, Web server security is covered more thoroughly early in the third part of this Hack Notes title. Author shares some more tips on checking the log files and using proxies and load balancers.



Web security consists of two major parts - security of web servers and web applications. The importance of writing secure code can be seen on almost every page of this book, so it was expected that the book's "official content" (the book also hosts two more appendixes and one preview chapter from Hack Notes Network Security) is finished with tips on secure coding.



As with all the books from these series, Hack Notes Web Security also incorporates a satisfactory 30 page reference center located in the center of the book. It includes such topics like input validation tests, HTTP protocol notes, application assessment checklists and search terms that will make Google a valuable addition in the attacker's arsenal :)



I mentioned earlier that there are two appendixes to the book. The first is a 7-bit ASCII reference (containing character, description, decimal, hexadecimal tabs) and the other one is a nice essay on WebGoat. This geeky titled product was created by OWASP (Open Source Web Application Security Project) and provides an easy, hands-on approach for better understanding the security issues related to web applications.



To share my thoughts



If you've read my review of "HackNotes Linux and Unix Security", I should warn you that I'll probably repeat some of my final thoughts on this book. Being a part of Hack Notes series, you'll either love it, or hate it. I'm personally a big fan of these kind of publications as they provide so much valuable information squeezed into a compact reference guide.



Before recommending the book to different type of readers, I would stress out the importance of writing secure code. While checking BugTraq and other security mailing lists, we are mostly stunned in how many web applications are vulnerable to the attacks mentioned in thios book. Even stranger is to see that some very popular products (hint: content management systems) are struck with new vulnerability reports on a monthly basis. I would highly recommend this book to all those programmers who should consider security very seriously. Even if you are familiar with the usual web application security problems, you'll surely be surprised in how many extras this book incorporates. You'll probably find a plenty of new ideas from the quantity of author's practical knowledge on these topics.



The book is written in a way that follows Hack Notes schemes - it covers possible security issues, methods of exploiting them, as well suggestions and hints on the things to do to make the attacker's life as complicated as possible.



To finish the review - the author managed to crawl through almost every web application security corner on the Internet and summarized a great quantity of examples, tips and ideas into an very useful web security reference.
Download here:




Read more…

Hack Proofing Your Web Applications

20:32 |
Hack Proofing Your Web Applications



Product Description

From the authors of the bestselling Hack Proofing Your Network!



OPEC, Amazon, Yahoo! and E-bay: If these large, well-established and security-conscious web sites have problems, how can anyone be safe? How can any programmer expect to develop web applications that are secure?




Hack Proofing Your Web Applications is the only book specifically written for application developers and webmasters who write programs that are used on web sites. It covers Java applications, XML, ColdFusion, and other database applications. Most hacking books focus on catching the hackers once they've entered the site; this one shows programmers how to design tight code that will deter hackers from the word go.



Comes with up-to-the-minute web based support and a CD-ROM containing source codes and sample testing programs

Unique approach: Unlike most hacking books this one is written for the application developer to help them build less vulnerable programs

About the Author

Julie Traxler is a Senior Software Tester for an Internet software company. During her career, Julie has worked for such organizations as DecisionOne, EXE Technologies, and TV Guide. She has held several positions including Project Manager, Business Analyst, and Technical Writer and has specialized in software systems analysis and design. During her tenure at several organizations, Julie has worked to provide a starting point for software quality assurance and has helped to build QA teams and implement testing processes and strategies. The testing plans she has developed include testing for functionality, usability, requirements, acceptance, release, regression, security, integrity, and performance.Jeff Forristal is the Lead Security Developer for Neohapsis, a Chicago-based security solution/consulting firm. Apart from assisting in network security assessments and application security reviews (including source code review), Jeff is the driving force behind Security Alert Consensus, a joint security alert newsletter published on a weekly basis by Neohapsis, Network Computing, and the SANS Institute.

Kevin Ziese is a Computer Scientist at Cisco Systems, Inc. Prior to joining Cisco he was a Senior Scientist and Founder of the Wheelgroup Corporation, which was acquired by Cisco Systems in April of 1998. Prior to starting the Wheelgroup Corporation, he was Chief of the Advanced Countermeasures Cell at the Air Force Information Warfare Center.


Download here:




Read more…

Web Application Vulnerabilities

16:49 |


Web Application Vulnerabilities: Detect, Exploit, Prevent /by Steven Palmer (Author). In this book, we aim to describe how to make a computer bend to your will by finding and exploiting vulnerabilities specifically in Web applications. We will describe common security issues in Web applications, tell you how to find them, describe how to exploit them, and then tell you how to fix them. 


We will also cover how and why some hackers (the bad guys) will try to exploit these vulnerabilities to achieve their own end. We will also try to explain how to detect if hackers are actively trying to exploit vulnerabilities in your own Web applications.
* Learn to defend Web-based applications developed with AJAX, SOAP, XMLPRC, and more.
* See why Cross Site Scripting attacks can be so devastating.
Download working code from the companion Web site.


Download here:




Read more…

Joomla! Web Security

05:19 |
Joomla! Web Security



Product Description

In Detail

Joomla! is one of the most powerful open-source content management systems used to build websites and other powerful online applications. While Joomla! itself is inherently safe, misconfigurations, vulnerable components, poorly configured hosts, and weak passwords can all contribute to the downfall of your site. So, you need to know how to secure your website from security threats.



Today every website needs to take security into consideration. Using the knowledge here, your Joomla! site can be ahead of the security threats so prevalent today.

This book will take you all the way from the most basic steps of preparation to the nuts and bolts of actual protection. It is packed full of relevant and real-world topics such as security tools, configuration suggestions, setting up your test and development environment, reading and interpreting log files, and techniques used by bad hackers on the Internet. In addition to this you will learn how to respond to a site emergency should one occur and how to collect the evidence needed to pursue law enforcement action. The book provides a concise overview of all the parts needed to construct a defence-in-depth strategy for your Joomla! site.

At the end of the book you will have a solid security foundation to take your Joomla! website to a higher level of security than the basic site setup.

What you will learn from this book?

This book covers:


  • Implementing steps for successful Joomla! website architecture
  • Setting up metrics to measure security
  • Exploring the test and development environment; developing your test plan to make sure everything will work as planned
  • Utilizing your test and development site for disaster recovery
  • Measuring the performance of your software development projects using a software development management system
  • Exploring several tools to help protect your website
  • Diving into security vulnerabilities: why they exist; some typical counter measures
  • Exploring SQL Injections - how they can hurt you and how to prevent them
  • Mastering the two important security layers - php.ini and .htaccess
  • Reading and analyzing logs relevant to protecting your Joomla! site
  • Handling Security Incidents in a professional manner
  • Blocking nuisance IP addresses
Approach

This book will give you a strong, hands-on approach to security. It starts out with the most basic of considerations such as choosing the right hosting sites then moves quickly into securing the Joomla! site and servers. This is a security handbook for Joomla! sites. It is an easy-to-use guide that will take you step by step into the world of secured websites.

Who this book is written for?

This book is a must-read for anyone seriously using Joomla! for any kind of business, ranging from small retailers to larger businesses. With this book they will be able to secure their sites, understand the attackers, and more, without the drudging task of looking up in forums, only to be flamed, or not even find the answers.

Prior knowledge of Joomla! is expected but no prior knowledge of securing websites is needed for this book. The reader will gain a moderate to strong level of knowledge on strengthening their sites against hackers.

About the Author

Tom Canavan

A twenty-three year veteran of the Computer Business, and a Data Center Technology Consultant to Fortune-1000 Companies, Tom Canavan is a Certified Ethical Hacker and has a degree in Robotics and Numerical Control. He is author of the book Dodging the Bullets - A Disaster Preparation Guide for Joomla! Based Websites.


Download here:




Read more…

Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions

05:02 |
Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions



Product Description

Lock down next-generation Web services

"This book concisely identifies the types of attacks which are faced daily by Web 2.0 sites, and the authors give solid, practical advice on how to identify and mitigate these threats." --Max Kelly, CISSP, CIPP, CFCE, Senior Director of Security, Facebook

Protect your Web 2.0 architecture against the latest wave of cybercrime using expert tactics from Internet security professionals. Hacking Exposed Web 2.0 shows how hackers perform reconnaissance, choose their entry point, and attack Web 2.0-based services, and reveals detailed countermeasures and defense techniques. You'll learn how to avoid injection and buffer overflow attacks, fix browser and plug-in flaws, and secure AJAX, Flash, and XML-driven applications. Real-world case studies illustrate social networking site weaknesses, cross-site attack methods, migration vulnerabilities, and IE7 shortcomings.



  • Plug security holes in Web 2.0 implementations the proven Hacking Exposed way
  • Learn how hackers target and abuse vulnerable Web 2.0 applications, browsers, plug-ins, online databases, user inputs, and HTML forms
  • Prevent Web 2.0-based SQL, XPath, XQuery, LDAP, and command injection attacks
  • Circumvent XXE, directory traversal, and buffer overflow exploits
  • Learn XSS and Cross-Site Request Forgery methods attackers use to bypass browser security controls
  • Fix vulnerabilities in Outlook Express and Acrobat Reader add-ons
  • Use input validators and XML classes to reinforce ASP and .NET security
  • Eliminate unintentional exposures in ASP.NET AJAX (Atlas), Direct Web Remoting, Sajax, and GWT Web applications
  • Mitigate ActiveX security exposures using SiteLock, code signing, and secure controls
  • Find and fix Adobe Flash vulnerabilities and DNS rebinding attacks

About the Author

Rich Cannings is a senior information security engineer at Google.

Himanshu Dwivedi is a founding partner of iSEC Partners, an information security organization, and the author of several security books.

Zane Lackey is a senior security consultant with iSEC Partners.


Download here:




Read more…