The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
M**S
Accessible, informative and relevant despite the age
Other reviewers have said that this book is best used as a reference, they say not to read this ~700 page book cover-to-cover. I read this cover to cover.While on a first read-through it was not possible to take everything in, I found this to be highly accessible for a technical book. The writing style was quite casual. Examples are made from an informed perspective and relevant background for every exploit was presented in an understandable way.This is not a "cook-book" of ready to use exploits, but more an explanation of the mind-set required to develop your own exploits and a presentation of the background to specific circumstances that allow such exploits.I have to say that this is an old book considering the pace of technological advancement and reference is made to deprecated technologies such as Flash and Silverlight, but as a primer, a historical snapshot and an introduction to the mind-set required to effectively use exploits in general, this was a very good read.Don't expect to sit down and have an easy time, this is a technical book and I found it challenging in this respect, but I am extremely glad I decided to purchase this book and read it cover-to-cover.I would say this book is best read while dividing time with more current resources such as the Portswigger Academy, labs provided by sites such as TryHackMe, etc.Dafydd Stuttard, one of the authors, is the core developer of BurpSuite (by Portswigger), and reading this summary of the web hacking landscape has given me a new perspective on this world-leading application.I would strongly recommend this to anyone interested in web hacking specifically, but also hacking in general.
M**H
Much more than SQL Injection and XSS
I read this book in preparation for the Live Course which was presented by Marcus.While reading the book i found it was quite dry because i was not doing the practical excersises available online. As you have to pay for them i wasn't sure if it would be worth it. With hindsight after doing the course i would highly recommend using them. It will make the content a lot more interesting but also teach a key skill which the book doesn't:The key to most pen testing and vulnerability research is persistence and logical thinking. It is very well to think you know how a certain bug works but it can still be quite a challenge to actually implement it.I feel very lucky to have been able to attend the live course for hands on help from the authors but you can definitely get all the information and practice you need purely from the book and the website. Its a shame that there isn't a couple of hours of practical time included when you buy the book.It is very well written and covers all the areas you would expect. A lot of the old school web bugs explained such as SQL injection and less common now because of better programming practices and interfaces. Later chapters in the book such as the methodologies and logic flaw errors are timeless.The book also provides real world solutions and mitigation's for the attacks described so this is highly recommended for anyone who develops web applications swell as people who carry out penetration testing on them.While this may not be the best book ever written i think it definitively describes the topic therefore i have given it 5 stars.
K**U
Satisfactory
Satisfactory
C**S
A good reference
I find this book to be a good reference. As a beginner pen-tester, i'm learning the ropes and this book makes sense in some parts and doesn't make sense in others. It's probably because it's huge - with so many pages, it's aiming to take care of so many topics and cover subject matter for both newbie pen-testers and experienced pen-testers.I think as time goes on, the book will become even more useful for me. For the price and the staggering amount of detail and information, it's a no-brainer. This is basically a fantastic reference book and knowledge-base for anyone who is serious about digital security.
U**R
A timeless and definitive guide on web application security
This is the definitive guide on attacking and defending web applications. Anyone looking to enter the field of security consulting can't do much better than reading this book cover to cover. It is, admittedly, a long read at over 900 pages, and not one that I think people could or should sit down and push through quickly. Although the book is a few years old now, most of the content is still very much relevant to today's web applications and it is absolutely recommended for anyone looking to get a better idea of web application security, particularly those who haven't had a background in the security field.
J**Y
Old but gold
Old book but information still relevant
A**R
Highly recommend!!
Obviously web applications are not exactly the same as when the book was written but the principles and the logic of hacking them are still the same. Have learned tons already and I'm only 100 pages in
I**7
Perfect book
Book came within a couple of days and in perfect condition. Has all of the information needed for my chosen field.
Trustpilot
2 months ago
1 day ago