作者:[美] Billy Hoffman
出版社:Addison-Wesley Professional publisher
出版年:2007
评分:0.0
ISBN:9780321491930
所属分类:网络科技
The Hands-On, Practical Guide to Preventing Ajax-Related Security Vulnerabilities More and more Web sites are being rewritten as Ajax applications; even traditional desktop software is rapidly moving to the Web via Ajax. But, all too often, this transition is being made with reckless disregard for security. If Ajax applications aren’t designed and coded properly, they can be susceptible to far more dangerous security vulnerabilities than conventional Web or desktop software. Ajax developers desperately need guidance on securing their applications: knowledge that’s been virtually impossible to find, until now . Ajax Security systematically debunks today’s most dangerous myths about Ajax security, illustrating key points with detailed case studies of actual exploited Ajax vulnerabilities, ranging from MySpace’s Samy worm to MacWorld’s conference code validator. Even more important, it delivers specific, up-to-the-minute recommendations for securing Ajax applications in each major Web programming language and environment, including .NET, Java, PHP, and even Ruby on Rails. You’ll learn how to: · Mitigate unique risks associated with Ajax, including overly granular Web services, application control flow tampering, and manipulation of program logic · Write new Ajax code more safely—and identify and fix flaws in existing code · Prevent emerging Ajax-specific attacks, including JavaScript hijacking and persistent storage theft · Avoid attacks based on XSS and SQL Injection—including a dangerous SQL Injection variant that can extract an entire backend database with just two requests · Leverage security built into Ajax frameworks like Prototype, Dojo, and ASP.NET AJAX Extensions—and recognize what you still must implement on your own · Create more secure “mashup” applications Ajax Security will be an indispensable resource for developers coding or maintaining Ajax applications; architects and development managers planning or designing new Ajax software, and all software security professionals, from QA specialists to penetration testers.
FPGA设计实战演练(高级技巧篇) 本书特色现代fpga的结构越来越复杂,多时钟域的设计现在已是常态。对于功能电路来说,复位结构都必不可少。在同步逻辑设计中如何...
《如何用保险保障你的一生》内容简介:本书是知乎保险类大V李元霸写给普通大众的保险科普书。本书获得《小狗钱钱》策划人汤小明作序
《企业文化管理(第四版)》内容简介:本书在吸收国内外有关企业文化研究最新成果的基础上,完整地阐述了企业文化的基本内涵、体系
系统集成项目管理工程师掌中宝 本书特色 全书采用32开本,书藉可装入您的口袋,便于随身携带;正文全用小五号字体,版式精美,印刷清晰;书中知识点全,覆盖整个考试大...
本书综合商业专业知识和数据挖掘模型开发于一体,系统地介绍了数据挖掘商业环境、数据挖掘技术及其在商业中的应用。在注重对数据
《网页设计全书:PhotoshopCS4+FireworksCS4+DreamweaverCS4+FlashCS4+设计工具》如同书名,是一本完整的网页设计全书...
《人工智能:商业化落地实战》内容简介:人工智能的发展已经成为趋势。在这一时代背景下,本书选取最具代表性的AI科技与AI产品进行
《网红经济思维模式》内容简介:如果你想赚钱,可以入驻电商平台,拥抱互联网。如果你想出名,可以开通自媒体,打通宣传路。如果你
这是一本非常棒的书,主要讲解如何用Photoshop处理图片和做商业设计。《抠图+修图+调色+合成+特效Photoshop核心应用5项修炼》以案
《Android Jetpack开发》内容简介:随着移动领域的飞速发展,越来越多的工程师开始追求更高效率、更便捷的开发模式。而各种框架层出
BrandsAtoZ:是一套讲述富于独立性和创造性的品牌故事的丛书.本书详细探寻了每一个被选择品牌的历史,反映了其公司文化,并展示了其
支付结算系统作为支付体系的核心,在银行业具有十分重要的地位。计算机技术、网络技术和通信技术在支付体系中的广泛应用,便出现
《快速成型技术与应用》内容简介:本书对当今快速成型技术与应用的新信息进行了系统、全面的更新介绍,详细介绍了目前常用快速成型
《ESP32-C3物联网工程开发实战》内容简介:ESP32-C3是搭载了开源指令集RISC-V的32位低功耗、低成本、安全的物联网芯片,本书也是该
Fanswillgetbentoutofshapeiftheymissthefirstbooktocovercircuit-bending-bending,fo...
《个人理财理论与实务(第二版)》内容简介:本教材突破以往同名教材编写侧重于金融企业理财或理财师代客理财的视角,本教材从个人
Pro/Engineer Wildfire2.0特征与三维实体建模 内容简介 本书分为Pro/Engineer Wildfire 2.0概览、草图绘图、基准特征...
Inthisinnovativebook,ProfessorRobertHarperoffersafreshperspectiveonthefundamenta...
随着宽带业务需求的发展和潜在的巨额利润,宽带城域网正成为当前建设的热点。《宽带城域网实用手册》从内容的实用性和技术的先进
本书所展示的大量示例网站都是难得一见的佳作,这些网站时而浓墨重彩,时而简洁素雅,为读者带来一场丰富的视觉盛宴。读者可以从