作者:[美] Billy Hoffman
出版社:Addison-Wesley Professional publisher
出版年:2007
评分:0.0
ISBN:9780321491930
所属分类:网络科技
The Hands-On, Practical Guide to Preventing Ajax-Related Security Vulnerabilities More and more Web sites are being rewritten as Ajax applications; even traditional desktop software is rapidly moving to the Web via Ajax. But, all too often, this transition is being made with reckless disregard for security. If Ajax applications aren’t designed and coded properly, they can be susceptible to far more dangerous security vulnerabilities than conventional Web or desktop software. Ajax developers desperately need guidance on securing their applications: knowledge that’s been virtually impossible to find, until now . Ajax Security systematically debunks today’s most dangerous myths about Ajax security, illustrating key points with detailed case studies of actual exploited Ajax vulnerabilities, ranging from MySpace’s Samy worm to MacWorld’s conference code validator. Even more important, it delivers specific, up-to-the-minute recommendations for securing Ajax applications in each major Web programming language and environment, including .NET, Java, PHP, and even Ruby on Rails. You’ll learn how to: · Mitigate unique risks associated with Ajax, including overly granular Web services, application control flow tampering, and manipulation of program logic · Write new Ajax code more safely—and identify and fix flaws in existing code · Prevent emerging Ajax-specific attacks, including JavaScript hijacking and persistent storage theft · Avoid attacks based on XSS and SQL Injection—including a dangerous SQL Injection variant that can extract an entire backend database with just two requests · Leverage security built into Ajax frameworks like Prototype, Dojo, and ASP.NET AJAX Extensions—and recognize what you still must implement on your own · Create more secure “mashup” applications Ajax Security will be an indispensable resource for developers coding or maintaining Ajax applications; architects and development managers planning or designing new Ajax software, and all software security professionals, from QA specialists to penetration testers.
我们从哪里来?我们为什么存在?我们与地球上的生命应该如何共存?人类从诞生之初起就在一直苦苦追寻这些问题的答案。如今面对环
2天学会电脑组装.系统安装.日常维护与故障排除-(附赠光盘) 本书特色 本书完全从“读者自学”角度出发,结合课堂教学实录,力求...
汇编语言-(第2版) 内容简介 汇编语言是各种CPU提供的机器指令的助记符的集合,人们可以用汇编语言直接控制硬件系统进行工作。汇编语言是很多相关课程(如数据结构...
内容简介本书全面系统地论述了信号与系统分析的基本理论和方法。全书共11章,内容包括:信号与系统、线性时不变系统,周期信号的
《古城卫士:阮仪三传》内容简介:沧桑平遥、风情丽江、烟雨周庄、古雅苏州、水墨乌镇……都是因为一位老人的守护,其最初样貌与生
LINGO 软件及应用 本书特色 本书在深入浅出地介绍LINGO基本用法和LINGO与各种文件和数据库之间的数据传递和处理方法的基础上,分两个层次介绍了LING...
在《首饰的秘密》中,女人们向我们讲述她们的首饰——她们何时并如何得到,怎么佩戴,而它们又代表着什么——我们事实上在邀请她
本书是朱利安•阿桑奇目前为止唯一的一部著作,甚至可称为“半部自传”。它是一部见证互联网改变人类历史的伟大纪实文学作品,讲述
《JavaEE6权威指南:基础篇(第4版)》是任务导向、示例驱动的JavaEE6基础教程,讲述如何开发企业应用,并作为第4版加入了很多新内容
CCNA学习指南 本书特色 本学习指南帮你准备*新的ccna考试:cisco网络权威todd lammle编写的这本*畅销的学习指南能帮助你仔细的准备,信心十足...
鲁思沃(SiegfriedRusswurm)教授是西门子公司董事会成员和工业部的首席执行官(CEO)。在完成其制造工程学的大学学习后,鲁思沃
《灵魂应是可以随时飞起的鸟》内容简介:一切的驱动力,其实都是来自他那颗拳头大小的心——它微不足道,但是足够炽热,跳动有力,
Flash二维动画制作基础教程 本书特色 本书是中等职业教育电子信息类专业“双证课程”培养方案配套教材,同时也是“CEAC国家信息化计算机教育认证”的指定教材,...
《创新经济学》内容简介:本书在系统梳理经典创新经济理论的基础上,阐述新发展理念中的“创新是引领发展的*动力”的科学内涵,并从
《Python3.6从入门到精通(视频教学版)》内容简介:本书用于Python编程快速入门,注重实战操作,帮助读者循序渐进地掌握Python3.6
《岩石与彩虹》内容简介:本书系上海交通大学传记中心“现代传记文库”之三。著名学者杨正润先生在学术势头正旺之时,将大部分的精
不同于以往任何时期,如今我们进入了大数据的信息时代。利用合适的工具,我们可以探索数据的价值和意义,挖掘数据背后的模式及其
《社会主义核心价值观融入大学生思想政治教育的创新机制研究》内容简介:本书着眼于社会主义核心价值观和大学生思想政治教育的融合
比尔•盖茨曾说过:“21世纪要么电子商务,要么无商可务。”在这个一切皆电子商务的时代,人类数千年来的商业行为被颠覆,人们的购
《C++GUIQt4编程》(第2版)详细讲述了用最新的Qt版本进行图形用户界面应用程序开发的各个方面。前5章主要涉及Qt基础知识,后两个部