Dominant Systems - Michigan Network Solutions Provider Dominant Systems - Michigan Network Solutions Provider
Dominant Systems - Michigan Network Solutions Provider Dominant Systems - Michigan Network Solutions Provider
ARCSPIDER SEARCH
Enter Keywords:

Powered by Arc Spider - Smart Product Search Services 
Privacy Statement
PARTNER LINKS

Buy.com Coupons

Sony VAIO PC Special Offers

The Hottest Notebook Deals Are Here!


XSS Attacks: Cross Site Scripting Exploits and Defense
Home > Computer/ Network Books > Cisco PIX Firewalls > Item 4
View Previous Product in Cisco PIX Firewalls View Next Product in Cisco PIX Firewalls

Click here to buy XSS Attacks: Cross Site Scripting Exploits and Defense by  Seth Fogie, Jeremiah Grossman, Robert Hansen, and Anton Rager. XSS Attacks: Cross Site Scripting Exploits and Defense
by Seth Fogie, Jeremiah Grossman, Robert Hansen, and Anton Rager
Sales Rank: 235968
List Price: $59.95
$46.22
At Amazon
Get More Info On XSS Attacks: Cross Site Scripting Exploits and Defense! Buy XSS Attacks: Cross Site Scripting Exploits and Defense Now!

  • Paperback: 480 pages
  • Publisher: Syngress May 15, 2007
  • Language: English
  • ISBN-10: 1597491543
  • ISBN-13: 978-1597491549
  • Product Dimensions: 9.1 x 7.5 x 1.3 inches
  • Shipping Weight: 1.8 pounds

    Book Description
    Learn to defend your Web site against cross site scripting attacks (the #1 software vulnerability) written by the worlds foremost, undisputed experts!

    Product Description
    Cross Site Scripting Attacks starts by defining the terms and laying out the ground work. It assumes that the reader is familiar with basic web programming (HTML) and JavaScript. First it discusses the concepts, methodology, and technology that makes XSS a valid concern. It then moves into the various types of XSS attacks, how they are implemented, used, and abused. After XSS is thoroughly explored, the next part provides examples of XSS malware and demonstrates real cases where XSS is a dangerous risk that exposes internet users to remote access, sensitive data theft, and monetary losses. Finally, the book closes by examining the ways developers can avoid XSS vulnerabilities in their web applications, and how users can avoid becoming a victim. The audience is web developers, security practitioners, and managers.

    *XSS Vulnerabilities exist in 8 out of 10 Web sites
    *The authors of this book are the undisputed industry leading authorities
    *Contains independent, bleeding edge research, code listings and exploits that can not be found anywhere else

    Customer Reviews & Comments
    XSS Attacks earns 4 stars for being the first book devoted to Cross Site Scripting and for rounding up multiple experts on the topic. The authors are synonymous with attacking Web applications and regularly share their vast expertise via their blogs and tools. However, XSS Attacks suffers the same problems found whenever Syngress rushes a book to print -- nonexistent editing and uneven content. I found XSS Attacks to be highly enlightening, but I expect a few other books on the topic arriving later this year could be better. First, as Tadaka mentioned, ch 3 is the best written part of the book. In fact, the author of ch 3 should have written the entire book. There is a difference between an author of a tool, an author of a blog, and an author of a book. The author of ch 3 clearly knows how to make a clear argument over the course of a long stretch of pages (over 90) and carry the reader. Lucky for non-book-buyers, Syngress posted ch 3 for free on their Web site. You'll get a great foundation on XSS, and learn about CSRF and backdooring Flash and Quicktime. In terms of readability, ch 2 wasn't bad. I liked trying out various Firefox extensions and the author's examples were good. I think ch 1 should be completely dropped. It mentions terms not defined until ch 2. The language is exceptionally rough, indicating zero editing was done. The DNS pinning examples in ch 5 were confusing; it doesn't help novice readers to discuss [...] and then use [...]. (I think that's an error.) I really didn't get as much from the book past ch 3 as I did from ch 3. The major take-away from XSS Attacks is that one should never trust clients. Furthermore, far too many vulnerable capabilities exist in applications most people would never dream of fearing, like those that render .pdf or .swf. I really liked the point that browsers constantly interpret and "fix" broken HTML, sometimes to the detriment of the security world. I also liked reading how users can be duped by attacks against the integrity of data, such as adding or removing details of Web sites. Right now, if you want to learn more about recent XSS attacks in printed form, this book is your main option. Last year I favorably reviewed Lance James' book, Phishing Exposed, which includes some of these techniques. Later this year one of the other book reviewers, Dafydd Stuttard, should be publishing The Web Application Hackers Handbook: Discovering and Exploiting Security Flaws. Syngress claims to be publishing Web Application Vulnerabilities: Detect, Exploit, Prevent by Steven Palmer in the fall. Hacking Exposed Web 2.0 by Himanshu Dwivedi is another option, but I find his security books to be poorly written. I highly recommend visiting the authors' blogs, since they cover a lot of the information in XSS Attacks. Comment | Permalink | (Report this)

  • XSS Attacks: Cross Site Scripting Exploits and Defense
    List Price: $59.95
    Available from Amazon
    Price: $46.22
    Get More Info On XSS Attacks: Cross Site Scripting Exploits and Defense! Buy XSS Attacks: Cross Site Scripting Exploits and Defense Now!
    Home |  About Us |  Network Services |  Security Services |  Testimonials |  Case Studies
    Tips & Tools |  Press Room |  Newsletters |  Employment |  Contact Us

    Copyright © 2008, Dominant Systems Corporation

    Dominant Systems Corporation