Note: Supplemental materials are not guaranteed with Rental or Used book purchases.
Purchase Benefits
Marcus Pinto is a Principal Security Consultant at Next Generation Security Software, where he leads the database competency development team, and has lead the development of NGS’ primary training courses. He has eight years’ experience in security consulting and specializes in penetration testing of web applications and supporting architectures.
Marcus has worked with numerous banks, retailers, and other enterprises to help secure their web applications, and has provided security consulting to the development projects of several security-critical applications. He has worked extensively with large-scale web application deployments in the financial services industry.
Marcus has developed and presented database and web application training courses at the Black Hat and other security conferences around the world. Marcus holds a master’s degree in physics from the University of Cambridge.
Acknowledgments | |
Introduction | |
Web Application (In)security | |
Core Defense Mechanisms | |
Web Application Technologies | |
Mapping the Application | |
Bypassing Client-Side Controls | |
Attacking Authentication | |
Attacking Session Management | |
Attacking Access Controls | |
Injecting Code | |
Exploiting Path Traversal | |
Attacking Application Logic | |
Attacking Other Users | |
Automating Bespoke Attacks | |
Exploiting Information Disclosure | |
Attacking Compiled Applications | |
Attacking Application Architecture | |
Attacking the Web Server | |
Finding Vulnerabilities in Source Code | |
A Web Application Hacker's Toolkit | |
A Web Application Hacker's Methodology | |
Index | |
Table of Contents provided by Publisher. All Rights Reserved. |
The New copy of this book will include any supplemental materials advertised. Please check the title of the book to determine if it should include any access cards, study guides, lab manuals, CDs, etc.
The Used, Rental and eBook copies of this book are not guaranteed to include any supplemental materials. Typically, only the book itself is included. This is true even if the title states it includes any access cards, study guides, lab manuals, CDs, etc.