& FREE Delivery Details
In stock.
Ships from and sold by Amazon AU.
The Web Application Hacke... has been added to your Cart
Other Sellers on Amazon
Add to Cart
+ FREE Delivery
Sold by: Book Depository UK
Add to Cart
+ FREE Delivery
Sold by: Ria_Christie_Collections
Flip to back Flip to front
Listen Playing... Paused   You're listening to a sample of the Audible audio edition.
Learn more
See all 3 images

The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws 2E Paperback – 9 Sep 2011

ISBN-13: 978-1118026472 ISBN-10: 1118026470 Edition: 2nd Edition

See all 3 formats and editions Hide other formats and editions
Amazon Price
New from Used from

Browse our most popular books based on sales
Find your next great read. Shop best selling books
click to open popover

Frequently bought together

  • The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws 2E
  • +
  • Penetration Testing
  • +
  • The Hacker Playbook 3: Practical Guide to Penetration Testing
Total Price: $165.75
Buy the selected items together

Browse our most popular books based on sales
Find your next great read. Shop best selling books

Product details

  • Paperback: 912 pages
  • Publisher: John Wiley & Sons Inc; 2nd Edition edition (9 September 2011)
  • Language: English
  • ISBN-10: 1118026470
  • ISBN-13: 978-1118026472
  • Product Dimensions: 18.8 x 5.8 x 23.4 cm
  • Boxed-product Weight: 1.2 Kg
  • Average Customer Review: Be the first to review this item
  • Amazon Bestsellers Rank: 32,329 in Books (See Top 100 in Books)

Product description

From the Back Cover

New technologies. New attack techniques. Start hacking.

Web applications are everywhere, and they're insecure. Banks, retailers, and others have deployed millions of applications that are full of holes, allowing attackers to steal personal data, carry out fraud, and compromise other systems. This book shows you how they do it.

This fully updated edition contains the very latest attack techniques and countermeasures, showing you how to break into today's complex and highly functional applications. Roll up your sleeves and dig in.

  • Discover how cloud architectures and social networking have added exploitable attack surfaces to applications

  • Leverage the latest HTML features to deliver powerful cross-site scripting attacks

  • Deliver new injection exploits, including XML external entity and HTTP parameter pollution attacks

  • Learn how to break encrypted session tokens and other sensitive data found in cloud services

  • Discover how technologies like HTML5, REST, CSS and JSON can be exploited to attack applications and compromise users

  • Learn new techniques for automating attacksand dealing with CAPTCHAs and cross-site request forgery tokens

  • Steal sensitive data across domains using seemingly harmless application functions and new browser features

Find help and resources at http://mdsec.net/wahh

  • Source code for some of the scripts in the book

  • Links to tools and other resources

  • A checklist of tasks involved in most attacks

  • Answers to the questions posed in each chapter

  • Hundreds of interactive vulnerability labs

About the Author

DAFYDD STUTTARD is an independent security consultant, author, and software developer specializing in penetration testing of web applications and compiled software. Under the alias PortSwigger, Dafydd created the popular Burp Suite of hacking tools.

MARCUS PINTO delivers security consultancy and training on web application attack and defense to leading global organizations in the financial, government, telecom, gaming, and retail sectors.
The authors cofounded MDSec, a consulting company that provides training in attack and defense-based security.

No customer reviews

Review this product

Share your thoughts with other customers

Most helpful customer reviews on Amazon.com

Amazon.com: 4.3 out of 5 stars 87 reviews
3.0 out of 5 starsGood but not so ethical
5 September 2014 - Published on Amazon.com
Verified Purchase
66 people found this helpful.
3.0 out of 5 starsIt is one of the best books for web application hacking but no answer key for labs.
19 March 2014 - Published on Amazon.com
Verified Purchase
37 people found this helpful.
Marco & Stacie
5.0 out of 5 starsBest. Book. Ever.
30 November 2018 - Published on Amazon.com
Verified Purchase
5 people found this helpful.
Craig T. Bennett II
3.0 out of 5 starsSkip this if you already taken classes in cyber security. But this is worth while if you want to know the mind set of it
2 January 2018 - Published on Amazon.com
Verified Purchase
9 people found this helpful.