Join Books.org — it's free

Computer Programming, Networking & Telecommunications, Computers - General & Miscellaneous
Hunting Security Bugs by Bryan Jeffries — book cover

Hunting Security Bugs

by Bryan Jeffries, Lawrence Landauer
Write a review
Log in to track your reading progress.

Overview

Learn how to think like an attacker—and identify potential security issues in your software. In this essential guide, security testing experts offer practical, hands-on guidance and code samples to help you find, classify, and assess security bugs before your software is released.

Discover how to:

  • Identify high-risk entry points and create test cases
  • Test clients and servers for malicious request/response bugs
  • Use black box and white box approaches to help reveal security vulnerabilities
  • Uncover spoofing issues, including identity and user interface spoofing
  • Detect bugs that can take advantage of your program’s logic, such as SQL injection
  • Test for XML, SOAP, and Web services vulnerabilities
  • Recognize information disclosure and weak permissions issues
  • Identify where attackers can directly manipulate memory
  • Test with alternate data representations to uncover canonicalization issues
  • Expose COM and ActiveX repurposing attacks

PLUS—Get code samples and debugging tools on the Web

Synopsis

In this essential guide, security testing experts offer practical, hands-on guidance and code samples to help find, classify, and assess security bugs before software is released.

About the Author, Bryan Jeffries

Tom Gallagher is the lead of the Microsoft® Office Security Test team, where he focuses on penetration testing, writing security testing tools, and providing security education.

Bryan Jeffries is a software engineer responsible for driving security testing on Microsoft® SharePoint® Products and Technologies.

Lawrence Landauer is a software engineer at Microsoft® where he works on coding, testing, and training projects related to security, personal productivity, and deployment.

Reviews

There are no reviews yet. Log in to write one.

Book Details

Published
August 1, 2006
Publisher
Microsoft Press
Pages
590
Format
Paperback
ISBN
9780735621879

Similar books