|
Testing Web Security
* Covers security basics and guides reader through the process of testing a Web site.
* Explains how to analyze results and design specialized follow-up tests that focus on potential security gaps.
* Teaches the process of discovery, scanning, analyzing, verifying results of specialized
tests, and fixing vulnerabilities.
CONTENTS:
Acknowledgments.
Foreword.
Preface.
PART ONE: AN INTRODUCTION TO THE BOOK.
Introduction.
PART TWO: PLANNING THE TESTING EFFORT.
Test Planning.
PART THREE: TEST DESIGN.
Network Security.
System Software Security.
Client-Side Application Security.
Server-Side Application Security.
Sneak Attacks: Guarding Against the Less-Thought-of Security Threats.
Intruder Confusion, Detection, and Response.
PART FOUR: TEST IMPLEMENTATION.
Assessment and Penetration Options.
Risk Analysis.
Epilogue.
PART FIVE: APPENDIXES.
Appendix A: An Overview of Network Protocols, Addresses, and Devices.
Appendix B: SANS Institute Top 20 Critical Internet Security Vulnerabilities.
Appendix C: Test-Deliverable Templates.
Additional Rsources.
Index.
|