Jump to ratings and reviews
Rate this book

The Art of Software Security Assessment 1st (first) edition Text Only

Rate this book
The definitive insider's guide to auditing software security is penned by leading security consultants who have personally uncovered vulnerabilities in applications ranging from "sendmail" to Microsoft Exchange, Check Point VPN to Internet Explorer. Drawing on their extraordinary experience, they introduce a start-to-finish methodology for "ripping apart" applications to reveal even the most subtle and well-hidden security flaws.

Unknown Binding

First published November 30, 2006

34 people are currently reading
793 people want to read

About the author

Mark Dowd

9 books5 followers

Ratings & Reviews

What do you think?
Rate this book

Friends & Following

Create a free account to discover what your friends think of this book!

Community Reviews

5 stars
104 (61%)
4 stars
41 (24%)
3 stars
19 (11%)
2 stars
5 (2%)
1 star
1 (<1%)
Displaying 1 - 12 of 12 reviews
Profile Image for Vasil Kolev.
1,134 reviews197 followers
March 21, 2013
It's somewhat like a horror story, except that instead of looking for monsters under the bed, every 20-30 pages you leave the book and go look for something in your code.

The book is a comprehensive reference for most of the issues and techniques needed to do security audits of source code. It's probably the best (and I think only) introductory and complete text you can find, is well written and systematical. The last chapter seems rushed, and I think there's more to be said about some of the web problems (notably it seems to be missing cross-site request forging), but the rest of the book was very good, especially the chapter on C.
Profile Image for Justy.
2 reviews8 followers
November 28, 2016
Great higher-level overview of application security and while it cannot get into all of the nitty-gritty, it gives enough that the reader would be able to identify and know how to seek out more detailed information on specific vulnerabilities.

This book is more focused on application security rather than network. You should definitely have a programming background but it's not a difficult read, moves at a nice pace and ramps well. I read the entire book in a couple of months and while it is 10 years old, it is general enough that I keep it as a reference.
Profile Image for Rob.
150 reviews1 follower
Currently reading
January 3, 2023
Re-reading
Profile Image for Jason Copenhaver.
166 reviews4 followers
April 22, 2013
A comprehensive discussion of Software Security Assessment. While there are new things it doesn't cover the fundamentals are all there. The suggested tracks are a big help as well if you don't want to try and tackle the whole book at once.
Profile Image for Long Nguyen.
8 reviews1 follower
March 16, 2013
there are many different techniques & strategies to write good codes, to test codes, or to review other people code. the book explains concepts & definitions very clear & easy to understand. it's definitely help me a lot.
7 reviews2 followers
July 8, 2008
One of the best security books out there.
Profile Image for Tyler.
63 reviews3 followers
December 21, 2011
Seems to be great! Moving over to reference material.
Profile Image for Rex.
52 reviews6 followers
May 6, 2016
This is a great book about security assurance and worth reading over and over again.
Displaying 1 - 12 of 12 reviews

Can't find what you're looking for?

Get help and learn more about the design.