作者:[美] Billy Hoffman
出版社:Addison-Wesley Professional publisher
出版年:2007
评分:0.0
ISBN:9780321491930
所属分类:网络科技
The Hands-On, Practical Guide to Preventing Ajax-Related Security Vulnerabilities More and more Web sites are being rewritten as Ajax applications; even traditional desktop software is rapidly moving to the Web via Ajax. But, all too often, this transition is being made with reckless disregard for security. If Ajax applications aren’t designed and coded properly, they can be susceptible to far more dangerous security vulnerabilities than conventional Web or desktop software. Ajax developers desperately need guidance on securing their applications: knowledge that’s been virtually impossible to find, until now . Ajax Security systematically debunks today’s most dangerous myths about Ajax security, illustrating key points with detailed case studies of actual exploited Ajax vulnerabilities, ranging from MySpace’s Samy worm to MacWorld’s conference code validator. Even more important, it delivers specific, up-to-the-minute recommendations for securing Ajax applications in each major Web programming language and environment, including .NET, Java, PHP, and even Ruby on Rails. You’ll learn how to: · Mitigate unique risks associated with Ajax, including overly granular Web services, application control flow tampering, and manipulation of program logic · Write new Ajax code more safely—and identify and fix flaws in existing code · Prevent emerging Ajax-specific attacks, including JavaScript hijacking and persistent storage theft · Avoid attacks based on XSS and SQL Injection—including a dangerous SQL Injection variant that can extract an entire backend database with just two requests · Leverage security built into Ajax frameworks like Prototype, Dojo, and ASP.NET AJAX Extensions—and recognize what you still must implement on your own · Create more secure “mashup” applications Ajax Security will be an indispensable resource for developers coding or maintaining Ajax applications; architects and development managers planning or designing new Ajax software, and all software security professionals, from QA specialists to penetration testers.
Perl编程核心技术5 内容简介 Perl是一门功能强大、易于使用、容易移植的程序设计语言。Perl用途广泛,可用于Unix或Windows NT系统管理,We...
《世界是我们的课堂》内容简介:少年商学院创始人张华集10年研究与实践写成的一本“未来之书”,就如何培养孩子面向未来的8大能力与
《蔬果岁时记》内容简介:青葱、竹笋、苦瓜、南瓜、青梅、文旦、甘蔗、橙子……这些绿色蔬果,天然代表了健康和环保,体现了中华美
单片机实验与实践教程-(二)(第2版) 内容简介 本书为《单片机系列教程》之一,较之第1版,增删了部分内容。保留了第1版中循序渐进、汇编语言与高级语言并重、串并...
《Arduino项目开发:智能生活》内容简介:本书系统论述了Arduino开源硬件的架构、原理和开发方法,并具体阐述了19个完整的项目设计
Probabilisticroboticsisanewandgrowingareainrobotics,concernedwithperceptionandco...
创意城市:如何打造都市创意生活圈,ISBN:9787302210047,作者:(英)兰德利著,杨幼兰译目录 中文版序《创意城市》的缘起与未
《游园》内容简介:本书是“悦读日本”书系之一,从日本庭园的三大形态谈到各类庭园,包括佛家庭园、武家庭园、宫廷庭园、神社庭园
《人间草木:汪曾祺写北京》内容简介:本书主要收录了作者在北京时创作的作品。他墨写出了草木山川、花鸟虫鱼的人味,写出了乡情民
《雨夜短文》内容简介:《雨夜短文》余秋雨散文新作,篇幅短小,意境至美。上辑“万里入心”不仅是苦旅足迹遍布四海的余秋雨在空间
腾讯Android自动化测试实战 本书特色 本书聚集于Android自动化测试的理论、方案与案例实施,基本涵盖了Android平台上所有的自动化测试技术,并对移...
Linux 驱动程序开发实例-第2版 本书特色 Linux设备驱动程序是高级应用程序与硬件设备之间的桥梁。驱动程序开发是软硬件相互结合的技术。本书是一本专门介绍...
""HowtoThinkLikeaComputerScientist""isanintroductiontoprogrammingusingPython,one...
《CP.IP详解(卷3):CP事务协议.HP.P和UIX域协议》是“TCP/IP详解系列”的延续。主要内容包括:TCP事务协议,即T/TCP,这是对TCP的
诠释价值万亿的商业生活新事实顺势重构既有的造富大趋势★“一带一路”、亚投行、丝路基金等重磅战略无一例外地指向中国西边,全
Whenyoureunderpressuretoproduceawelldesigned,easy-to-navigatemobileapp,theresnot...
《寻找古诗之美(套装全三册)》内容简介:本书共三册,第一册60首,适合6—8岁孩子,第二册70首,适合8—10岁孩子,第三册82首,适
《超越谷歌:全球网脑新商机》主要内容简介:全球金融危机人人关注。金融危机证明了亚当•斯密提出的“看不见的手”已经失灵,人类
晶体结构精修-晶体学者的SHELXL软件指南-光盘 本书特色 《晶体结构精修:晶体学者的SHELXL软件指南》:SHELXL是目前国际上使用*广泛的结构精修程序...
StevenJohnMetsker是DominionDigital公司的管理顾问,该公司负责信息技术与商业过程的重新设计。Steven擅长运用面向对象技术构建