|
 |
|
 |
 |
Programmer's Ultimate Security DeskRef
|
by James C. Foster and Steven C. Foster
|
List Price: $19.98
$19.98
At Amazon

|
|
Do you have the free reader for this item?
|
Format: Adobe Reader PDFPrintable: Yes. This title is printableMac OS Compatible: OS 9.x or laterWindows Compatible: YesHandheld Compatible: Yes. Adobe Reader is available for PalmOS, Pocket PC, and Symbian OS.
File Size: 9043 KB
Digital: 609 pages
Publisher: SYNGRESS; 1 edition October 18, 2004
In-Print Editions:
Kindle Edition
Kindle Book
Paperback
1
Product Description
While there are many books starting to address the broad subject of security best practices within the software development lifecycle, none has yet to address the overarching technical problems of incorrect function usage. Most books fail to draw the line from covering best practices security principles to actual code implementation. This book bridges that gap and covers the most popular programming languages such as Java, Perl, C++, C#, and Visual Basic.
About The Author
James C. Foster, Fellow, is the Deputy Director of Global Security Solution Development for Computer Sciences Corporation where he is responsible for the vision and development of physical, personnel, and data security solutions. Preceding CSC, Foster was the Director of Research and Development for Foundstone Inc. and was responsible for all aspects of product, consulting, and corporate R&D initiatives. Prior to joining Foundstone, Foster was an Executive Advisor and Research Scientist with Guardent Inc. and an adjunct author at Information Security Magazine, subsequent to working as Security Research Specialist for the Department of Defense. Foster is also a well published author with multiple commercial and educational papers; and has authored, contributed, or edited for major publications to include Snort 2.1 Intrusion Detection (Syngress, ISBN: 1-931836-04-3), Hacking Exposed, Fourth Edition, Anti-Hacker Toolkit, Second Edition, Advanced Intrusion Detection, Hacking the Code: ASP.NET Web Application Security (Syngress, ISBN: 1-932266-65-8), Anti-Spam Toolkit, Google Hacking for Penetration Techniques (Syngress, ISBN: 1-931836-36-1), and Sockets, Shellcode, Porting and Coding (Syngress ISBN: 1-597490-05-9).
--This text refers to the
Paperback
edition.
Customer Reviews & Comments
This review is from: Programmer's Ultimate Security DeskRef (Paperback)
Don't look to this book to really teach you anything about secure programming. It's merely a limited command reference for a handful of languages (oddly including Lisp but excluding Java) with very brief notes on the security implications of each. It was very strange to flip through this book and find literally NO text or introductions anywhere; I really think a few pages should have been added to give some background on each language including any general guidance with regard to security. At least an introduction to language-independent secure programming concepts should have been included at the beginning--this book basically relies on the back outside cover to clue the reader in to what it's about and why it's important. On top of the fact that a lot of content seems to be missing, I found many of the commands covered to be extraneous, having little to no significant security relevance. In some cases the advice is vague bordering on naive--a few places in the JavaScript section say things like "always use SSL" or "when in doubt, use SSL" which really isn't a very big-picture way to look at security and risk management. In several places common vulnerabilities are mentioned but not defined or explained--sidebars would have been appropriate. Further lowering the book's value are its large print and extremely thin, rough, cheap-feeling pages (which seems to be typical of current Syngress releases), and lack of an index. Unless you're already familiar with secure programming practices and just need a pure reference to point out selected "harmful" commands in the covered languages, I don't think this book is worth buying. There's a lot more to secure programming than what this book provides and, in fact, it may mislead developers into thinking that secure programming is merely about proper use of certain unsafe functions and methods.
Comment | Permalink |
(Report this)
|
Programmer's Ultimate Security DeskRef
List Price: $19.98
Available from Amazon
Price: $19.98

| |
|
|
|
|