Ajax Security

版权声明:原创作品,允许转载,转载时请务必以超链接形式标明文章原始出版、作者信息和本声明。否则将追究法律责任。 http://blog.csdn.net/topmvp - topmvp
The Hands-On, Practical Guide to Preventing Ajax-Related Security Vulnerabilities

More and more Web sites are being rewritten as Ajax applications; even traditional desktop software is rapidly moving to the Web via Ajax. But, all too often, this transition is being made with reckless disregard for security. If Ajax applications arent designed and coded properly, they can be susceptible to far more dangerous security vulnerabilities than conventional Web or desktop software. Ajax developers desperately need guidance on securing their applications: knowledge thats been virtually impossible to find, until now.

Ajax Security systematically debunks todays most dangerous myths about Ajax security, illustrating key points with detailed case studies of actual exploited Ajax vulnerabilities, ranging from MySpaces Samy worm to MacWorlds conference code validator. Even more important, it delivers specific, up-to-the-minute recommendations for securing Ajax applications in each major Web programming language and environment, including .NET, Java, PHP, and even Ruby on Rails. Youll learn how to:

*Mitigate unique risks associated with Ajax, including overly granular Web services, application control flow tampering, and manipulation of program logic
*Write new Ajax code more safelyand identify and fix flaws in existing code
*Prevent emerging Ajax-specific attacks, including JavaScript hijacking and persistent storage theft
*Avoid attacks based on XSS and SQL Injectionincluding a dangerous SQL Injection variant that can extract an entire backend database with just two requests
*Leverage security built into Ajax frameworks like Prototype, Dojo, and ASP.NET AJAX Extensionsand recognize what you still must implement on your own
*Create more secure mashup applications

Ajax Security will be an indispensable resource for developers coding or maintaining Ajax applications; architects and development managers planning or designing new Ajax software, and all software security professionals, from QA specialists to penetration testers.


http://rapidshare.com/files/98616958/0321491939.zip
http://depositfiles.com/files/4050134
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值