The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
Web applications are everywhere, and they're insecure. Banks, retailers, and others have deployed millions of applications that are full of holes, allowing attackers to steal personal data, carry out fraud, and compromise other systems. This innovative book shows you how they do it.
This is hands-on stuff. The authors, recognized experts in security testing...more
+ Technical just like the way I like books
+ Explains many methods you couldn't possible imagine before.
+ Step by Step explanation
+ New ideas and exploitation methods
- Labs cost 7$ / Hr ---> Not much practice; however you can find many free practice labs (e.g. pentesterlab.com)
- Focuses on Burp Proxy only -- there are many other tools
- a bit outdated ! <- many of v ...more
It's fairly well edited with just a few simple mistakes. The exercises are interesting, though they feel a little laborious by the end.
I enjoyed reading it and would recomme ...more
I remember waking up everyday for ~2-3 weeks and reading this for 1 hour straight at 5:30-6am, just to finish the toughest thing first thing in the day haha. Very hard to read, looking back I have no idea how I did it :)
well , i consider it as the web app pentesting bible xD
totally worth 5 stars , but took off one because it depend a lot on the paid online labs which cant be afford for long time
waiting for the 3rd edition
Overall, there was a lot of information. I hated the constant use burp suite for this and that. SHUT UP ABOUT BURP SUITE!!! Also, all over the book are links to highly expensive pay by the hour labs that do not even include an answer key. These are used as examples, also. Another thing I dis liked was the last couple of chapters. They barley fit within the book's title.
Goodreads is hiring!
Learn more »