The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws - Paperback >
/ The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws - Paperback

The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws - Paperback

Regular price$52.00
/
(Tax included. Shipping calculated at checkout.)
✔ Authenticity Guaranteed — Verified Designer Goods
✔ 100% Money-Back Guarantee on Eligible Items
✔ Prices Displayed in Your Local Currency
✔ Final Price = No Surprise Import Fees
✔ Complimentary Insured Worldwide Shipping on Qualifying Orders
✔ Select Collector & Specialty Pieces May Require Secured Delivery Handling
Our authentication process ensures every item meets strict luxury verification standards. Learn more
Complimentary worldwide shipping on qualifying orders

by Dafydd Stuttard (Author), Marcus Pinto (Author)

The highly successful security book returns with a new edition, completely updated

Web applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of ever-evolving web applications. You'll explore the various new technologies employed in web applications that have appeared since the first edition and review the new attack techniques that have been developed, particularly in relation to the client side.

  • Reveals how to overcome the new technologies and techniques aimed at defending web applications against attacks that have appeared since the previous edition
  • Discusses new remoting frameworks, HTML5, cross-domain integration techniques, UI redress, framebusting, HTTP parameter pollution, hybrid file attacks, and more
  • Features a companion web site hosted by the authors that allows readers to try out the attacks described, gives answers to the questions that are posed at the end of each chapter, and provides a summarized methodology and checklist of tasks

Focusing on the areas of web application security where things have changed in recent years, this book is the most current resource on the critical topic of discovering, exploiting, and preventing web application security flaws.


Back Jacket

New technologies. New attack techniques. Start hacking.

Web applications are everywhere, and they're insecure. Banks, retailers, and others have deployed millions of applications that are full of holes, allowing attackers to steal personal data, carry out fraud, and compromise other systems. This book shows you how they do it.

This fully updated edition contains the very latest attack techniques and countermeasures, showing you how to break into today's complex and highly functional applications. Roll up your sleeves and dig in.

  • Discover how cloud architectures and social networking have added exploitable attack surfaces to applications

  • Leverage the latest HTML features to deliver powerful cross-site scripting attacks

  • Deliver new injection exploits, including XML external entity and HTTP parameter pollution attacks

  • Learn how to break encrypted session tokens and other sensitive data found in cloud services

  • Discover how technologies like HTML5, REST, CSS and JSON can be exploited to attack applications and compromise users

  • Learn new techniques for automating attacksand dealing with CAPTCHAs and cross-site request forgery tokens

  • Steal sensitive data across domains using seemingly harmless application functions and new browser features

Find help and resources at http: //mdsec.net/wahh

  • Source code for some of the scripts in the book

  • Links to tools and other resources

  • A checklist of tasks involved in most attacks

  • Answers to the questions posed in each chapter

  • Hundreds of interactive vulnerability labs

Author Biography

DAFYDD STUTTARD is an independent security consultant, author, and software developer specializing in penetration testing of web applications and compiled software. Under the alias PortSwigger, Dafydd created the popular Burp Suite of hacking tools.

MARCUS PINTO delivers security consultancy and training on web application attack and defense to leading global organizations in the financial, government, telecom, gaming, and retail sectors.
The authors cofounded MDSec, a consulting company that provides training in attack and defense-based security.

Number of Pages: 912
Dimensions: 1.95 x 9.23 x 7.4 IN
Publication Date: September 27, 2011
  • In stock, ready to ship
  • Backordered, shipping soon
Shop with Confidence
  • ✔ Authenticity Guaranteed — Verified Designer Goods
  • ✔ Sourced from Authorized European/U.S. Luxury Distributors
  • ✔ Secure Checkout — SSL Encrypted Payments
  • ✔ Fast Global Delivery — 3–11 Business Days
  • ✔ Easy Returns on Eligible Items
  • ✔ 100% Money-Back Guarantee — Full Refund if Not Satisfied
Verified Trust Rating: 91/100
Amazon American Express Apple Pay Bancontact Diners Club Discover Google Pay Mastercard PayPal Shop Pay USDC Visa SSL Secure
Amazon Pay Logo Fast checkout with Amazon Pay. Use your Amazon account to skip entering shipping or card info.
Trusted by discerning buyers worldwide — secure, verified luxury sourcing

AUTHENTICITY GUARANTEED

Reserved for you — complete your purchase to secure this piece.

Authorized Designer Inventory Secure & Encrypted Checkout Tracked & Insured Delivery

OFFICIALLY AUTHORIZED RESELLER

Discover Officially Authorized Authentic Items at STORE7994.com - Certificates Available on Request!

Independently verified for store quality and customer safety.
Trust score: 91/100

All designer items offered by STORE 7994 are sourced from trusted luxury distributors and verified through independent authentication services.

Learn how STORE 7994 authenticates luxury items

Guaranteed Authentic — Includes Brand Documentation & Third-Party Verification Options.

Shipping information

  • Free Shipping* on all orders over $300 USD to most countries* Estimated delivery: 2-5 business days Mon-Sat to U.S., CA, EU etc.
  • Tracking available: DHL Express
  • Store 7994 Shipping policy
  • Global delivery in 3–9 business days (location dependent).
  • Free Worldwide Shipping $300+. International duties & VAT are calculated by destination country and may be collected upon delivery. UK orders are subject to 20% import VAT upon delivery.

Our innovation isn’t just in the brands we carry — it’s in the way we connect them. From our automation engine that keeps collections globally updated to our commitment to authenticity-first presentation, STORE 7994 exists where timeless design meets modern precision.

Every product we offer is:
Elevated · Intentional · Exclusive · Authentic

STORE 7994 is an authorized reseller of luxury fashion houses. Certificates and proof of authenticity are available to brand owners and partners upon request.

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.

Returns & Refunds

We want you to shop with confidence at STORE 7994. If your purchase does not meet expectations, eligible items may be returned under the conditions below.

Return Eligibility
Items must be unused, unworn, and in original condition with all tags, packaging, and accessories included. Items showing any signs of wear or damage will not be accepted.

Return Window
Return requests must be made within 14 days of delivery.

Return Shipping
Customers are responsible for return shipping costs unless the item is defective, damaged, or incorrect.

Luxury Items
Items valued over $1,000 may be subject to a 7% restocking fee upon approved return.

Non-Returnable Items
For hygiene and product integrity reasons, the following items are final sale once opened or used:

• Underwear
• Fragrances
• Any worn or used items

Made-to-Order Items
Custom-designed products, including STORE 7994 hoodies, are made exclusively for each customer and are final sale. These items are not eligible for return or exchange unless defective or incorrect.

If you receive a defective or incorrect item, please contact us and we will make it right.

International Shipping & Duties
Many of our products ship directly from trusted international partners. Any applicable customs duties or import taxes are calculated at checkout and are non-refundable, even if the item is returned.

Returns & Associated Fees
All approved returns are subject to a $24 return processing fee. For international orders, duties, taxes, and return fees will be deducted from the original payment.

Shipping Policy
Complimentary shipping is offered on orders over $300. Orders below this threshold are subject to standard shipping rates at checkout.