作者:[美] Billy Hoffman
出版社:Addison-Wesley Professional publisher
出版年:2007
评分:0.0
ISBN:9780321491930
所属分类:网络科技
The Hands-On, Practical Guide to Preventing Ajax-Related Security Vulnerabilities More and more Web sites are being rewritten as Ajax applications; even traditional desktop software is rapidly moving to the Web via Ajax. But, all too often, this transition is being made with reckless disregard for security. If Ajax applications aren’t designed and coded properly, they can be susceptible to far more dangerous security vulnerabilities than conventional Web or desktop software. Ajax developers desperately need guidance on securing their applications: knowledge that’s been virtually impossible to find, until now . Ajax Security systematically debunks today’s most dangerous myths about Ajax security, illustrating key points with detailed case studies of actual exploited Ajax vulnerabilities, ranging from MySpace’s Samy worm to MacWorld’s conference code validator. Even more important, it delivers specific, up-to-the-minute recommendations for securing Ajax applications in each major Web programming language and environment, including .NET, Java, PHP, and even Ruby on Rails. You’ll learn how to: · Mitigate unique risks associated with Ajax, including overly granular Web services, application control flow tampering, and manipulation of program logic · Write new Ajax code more safely—and identify and fix flaws in existing code · Prevent emerging Ajax-specific attacks, including JavaScript hijacking and persistent storage theft · Avoid attacks based on XSS and SQL Injection—including a dangerous SQL Injection variant that can extract an entire backend database with just two requests · Leverage security built into Ajax frameworks like Prototype, Dojo, and ASP.NET AJAX Extensions—and recognize what you still must implement on your own · Create more secure “mashup” applications Ajax Security will be an indispensable resource for developers coding or maintaining Ajax applications; architects and development managers planning or designing new Ajax software, and all software security professionals, from QA specialists to penetration testers.
《Spark GraphX 实战》内容简介:本书是一本Spark GraphX入门书籍。前5章为基础内容,即使读者对Spark、GraphX、Scala不熟悉,...
插画师是绘制广泛用于各种场合的图画的专业绘画人员。有时,插画师会碰到一些从未想过,从来接触过,也没有任何经验的插画委托。
五所权威德国设计学院:柏林艺术大学(UdkBerlin)杜塞尔多夫高等专业学院(FHD)莱比锡书籍设计及平面设计学院(HGBLeipzig)奥
《浪花礼赞:汪氏现当代名人录》内容简介:本书主要辑录了现当代为国家建功立业而呕心沥血、殚精竭虑、鞠躬尽瘁、忠心耿耿、赤胆忠
Thispracticalguideprovidesmorethan150recipestohelpyougeneratehigh-qualitygraphsq...
计算机组成原理(第二版)(附光盘) 内容简介 本书是普通高等教育“十一五”国家级规划教材。本书第1版被列为“ 面向21世纪课...
Areyoustilldesigningwebsiteslikeits1999?Ifso,youreinforasurprise.Sincethelastedi...
客觀的結構式臨床測驗(ObjectiveStructuredClinicalExamination,OSCE)是評估臨床能力的方式,藉由模擬臨床情境配合臨床檢驗...
《XML完全探索》是完全根据读者的需要而设计的,书中有大量实际的XML场景。是一本尽可能深入地阐述XML的书籍,与其他XML书籍不同
内容简介本书主要介绍了现代通信领域的最新技术,并对它们作了客观的比较。主要包括以下内容:TI/EI系统、X.25、B-ISDN、SS7、
《数字与模拟通信系统》(第7版)在前六版的基础上改编而成,系统地介绍了现代通信系统的基本理论和最新发展技术。全书共分8章,内
《亲子关系:决定孩子一生幸福的密码》内容简介:本书主要分为“好的亲子关系是家庭教育成功的基石”、“父母心中的亲子关系困惑”
《差错控制编码》围绕信道编码理论、技术及其应用,对各种编码方法的工程应用背景及发展前景作了详尽系统的介绍。全书共分9章,主
Web GIS原理与方法 内容简介 本书将全面、系统地论述WebGIS的基本原理、技术方法、*新的理论与发展趋势,以及在我国各个行业的应用实例。书中所涉及各方面...
《当我们走进心理咨询室》内容简介:为什么在亲密关系中,一些人总是扮演“受害者”的角色?为什么一些人总是习惯讨好别人,对所有
《思维迷宫(爱智书系)》内容简介:哲学不仅帮助人认识世界、认识自我,还能够认识我们的“认识”,看看我们是怎样思维的,我们的
《梁启超修身三书:德育鉴》内容简介:二十世纪初,梁启超(任公)先后编纂了三种关于传统的修身方面的书。此三书既是梁启超本人用
中文版Windows7 从入门到精通 本书特色 《从入门到精通系列:中文版windows 7从入门到精通》特点一本图书 三本价值1本书=入门十提高十精通=3本书...
《分布式系统架构》内容简介:资深分布式系统研发工程师、构架师多年工作经验总结,从原理、应用和实践3个维度展开从前端到后端,从
Thisisyourmust-haveresourcetothetheoreticalandpracticalconceptsofmobileUX.Youlll...