
The Software Vulnerability Guide
Herbert H. Thompson, Scott G. Chase - Collection Programming Series
Résumé
The Software Security Reference that Every Developer Needs!
In today's market, secure software is a must for consumers. Many developers, however, are not familiar with the techniques needed to produce secure code or detect existing vulnerabilities. The Software Vulnerability Guide helps developers and testers better understand the underlying security flaws in software and provides an easy-to-use reference for security bugs. Most of these bugs (and the viruses, worms, and exploits that derive from them) start out as programmer mistakes. With this guide, professional programmers and testers will learn how to find, fix, and prevent these vulnerabilities before their software reaches the market. Detailed explanations and examples are provided for each of the vulnerabilities, as well as a summary sheet that can be referenced quickly. Tools that make it easier to recognize and prevent vulnerabilities are also explored, and source code snippets, commentary, and techniques are provided in easy-to-read sidebars. This guide is a must have for today's software developers.
KEY FEATURES
- Includes coding examples in a variety of languages, including C, C++, Java, VB.NET, scripting languages, and more
- Features a detailed discussion and examples for each vulnerability, along with a summary sheet that can be referenced quickly and easily
- Includes tips for uncovering vulnerabilities in a diverse array of systems, including what it might look like in code, and how the offending code can be fixed
- Covers vulnerabilities such as dynamic linking and loading, buffer overflows, creating temporary files, forceful browsing, spoofing, and SQL injection
- Includes a CD-ROM with source code and many of the tools discussed in the book
ON THE CD
(See Appendix A for more details)
- COMPANION TOOLS - Includes the Libnet API, Ethreal network protocol analyzer, Ettercap, John The Ripper password cracker, Nemesis network packet and injection utility, Nessus vulnerability scanner, Nikto vulnerability scanner, Nmap security scanner, RATS auditing tool, SATAN, and Tcpdump network sniffer/analyzer
- SOURCE EXAMPLES - Contains the source code examples and project files included in each of the chapters
- FIGURES - All the images used in the book
L'auteur - Herbert H. Thompson
Dr. Herbert H. Thompson is an internationally renowned speaker and expert on software security. He is the co-author of the first book on software security testing, "How to Break Software Security" (Addison Wesley 2003) ISBN: 0321194330. In addition, he writes frequently for magazines like Dr. Dobbs, ACM Queue, IEEE S&P and many others and frequently speaks and gives keynotes at conferences like RSA, Gartner, and SD Expo. Herbert holds a Ph.D. in applied mathematics but has worked in the area of computer security his entire career. He is currently Director of Security Technology for Security Innovation where he leads teams of security penetration testers on contracts from the U.S. Department of Defense. He is also Principal Investigator on many U.S. DoD grants to find new techniques to penetrate software.
L'auteur - Scott G. Chase
Scott Chase (Melbourne, FL) is Security Architect at SI Government Solutions, where he manages key research projects for the US government. He has also worked as a university researcher in information security and as a software tester in industry.
Sommaire
- Acknowledgments
- Introduction
- System-Level Attacks
- Data Parsing
- Information Disclosure
- On the Wire
- Web Sites
- Conclusion
- Appendix A: About the CD-ROM
- Appendix B: Open Source Software Licenses
- Index
Caractéristiques techniques
PAPIER | |
Éditeur(s) | Charles River Media |
Auteur(s) | Herbert H. Thompson, Scott G. Chase |
Collection | Programming Series |
Parution | 16/08/2005 |
Nb. de pages | 354 |
Format | 18,5 x 23,5 |
Couverture | Broché |
Poids | 770g |
Intérieur | Noir et Blanc |
EAN13 | 9781584503583 |
ISBN13 | 978-1-58-450358-3 |
Avantages Eyrolles.com
Nos clients ont également acheté
Consultez aussi
- Les meilleures ventes en Graphisme & Photo
- Les meilleures ventes en Informatique
- Les meilleures ventes en Construction
- Les meilleures ventes en Entreprise & Droit
- Les meilleures ventes en Sciences
- Les meilleures ventes en Littérature
- Les meilleures ventes en Arts & Loisirs
- Les meilleures ventes en Vie pratique
- Les meilleures ventes en Voyage et Tourisme
- Les meilleures ventes en BD et Jeunesse