{"product_id":"a-beginners-guide-to-web-application-penetration-testing-paperback-softback-9781394295593","title":"A Beginner's Guide To Web Application Penetration Testing (Paperback \/ softback) 9781394295593","description":"\u003cfont face=\"Georgia\"\u003e\r\n\u003cp\u003e\u003cfont size=\"6\"\u003eA Beginner's Guide To Web Application Penetration Testing\u003c\/font\u003e\u003cbr\u003e\r\n\r\n\r\n\r\n\r\n\r\n\u003c\/p\u003e\n\u003cp\u003e\u003cfont size=\"4\"\u003eAli Abdollahi (Author)\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003e9781394295593, Wiley\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003ePaperback \/ softback, published 11 February 2025\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003e352 pages\u003cbr\u003e23.4 x 18.5 x 2.3 cm, 0.499 kg\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\r\n\r\n\r\n\r\n\u003cp align=\"justify\"\u003e\u003cstrong\u003e\u003cfont size=\"3\"\u003e\u003cp\u003e\u003cb\u003eA hands-on, beginner-friendly intro to web application pentesting\u003c\/b\u003e \u003c\/p\u003e\n\u003cp\u003eIn \u003ci\u003eA Beginner's Guide to Web Application Penetration Testing,\u003c\/i\u003e seasoned cybersecurity veteran Ali Abdollahi delivers a startlingly insightful and up-to-date exploration of web app pentesting. In the book, Ali takes a dual approach—emphasizing both theory and practical skills—equipping you to jumpstart a new career in web application security. \u003c\/p\u003e\n\u003cp\u003eYou'll learn about common vulnerabilities and how to perform a variety of effective attacks on web applications. Consistent with the approach publicized by the Open Web Application Security Project (OWASP), the book explains how to find, exploit and combat the ten most common security vulnerability categories, including broken access controls, cryptographic failures, code injection, security misconfigurations, and more. \u003c\/p\u003e\n\u003cp\u003e\u003ci\u003eA Beginner's Guide to Web Application Penetration Testing\u003c\/i\u003e walks you through the five main stages of a comprehensive penetration test: scoping and reconnaissance, scanning, gaining and maintaining access, analysis, and reporting. You'll also discover how to use several popular security tools and techniques—like as well as: \u003c\/p\u003e\n\u003cul\u003e \u003cli\u003eDemonstrations of the performance of various penetration testing techniques, including subdomain enumeration with Sublist3r and Subfinder, and port scanning with Nmap\u003c\/li\u003e \u003cli\u003eStrategies for analyzing and improving the security of web applications against common attacks, including\u003c\/li\u003e \u003cli\u003eExplanations of the increasing importance of web application security, and how to use techniques like input validation, disabling external entities to maintain security\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003ePerfect for software engineers new to cybersecurity, security analysts, web developers, and other IT professionals, \u003ci\u003eA Beginner's Guide to Web Application Penetration Testing\u003c\/i\u003e will also earn a prominent place in the libraries of cybersecurity students and anyone else with an interest in web application security.\u003c\/p\u003e\u003c\/font\u003e\u003c\/strong\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003e\u003cp\u003eForeword xvii\u003c\/p\u003e \u003cp\u003eIntroduction xix\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 1 Introduction to Web Application Penetration Testing 1\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eThe Importance of Web Application Security 3\u003c\/p\u003e \u003cp\u003eOverview of Web Application Penetration Testing 6\u003c\/p\u003e \u003cp\u003eThe Penetration Testing Process 8\u003c\/p\u003e \u003cp\u003eMethodologies 12\u003c\/p\u003e \u003cp\u003eTools and Techniques 14\u003c\/p\u003e \u003cp\u003eReporting 16\u003c\/p\u003e \u003cp\u003eTypes of Web Application Vulnerabilities 17\u003c\/p\u003e \u003cp\u003eKey Takeaways 25\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 2 Setting Up Your Penetration Testing Environment 27\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eSetting Up Virtual Machines 28\u003c\/p\u003e \u003cp\u003eContainer Option 29\u003c\/p\u003e \u003cp\u003eKali Linux Installation 30\u003c\/p\u003e \u003cp\u003ePentestBox 34\u003c\/p\u003e \u003cp\u003eInstalling DVWA 35\u003c\/p\u003e \u003cp\u003eOWASP Juice Shop 40\u003c\/p\u003e \u003cp\u003eBurp Suite 41\u003c\/p\u003e \u003cp\u003eOWASP ZED Attack Proxy 46\u003c\/p\u003e \u003cp\u003eWILEY Preconfigured Environment 49\u003c\/p\u003e \u003cp\u003eKey Takeaways 49\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 3 Reconnaissance and Information Gathering 51\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003ePassive Information Gathering 52\u003c\/p\u003e \u003cp\u003eAutomating Subdomain Enumeration 61\u003c\/p\u003e \u003cp\u003eActive Information Gathering 64\u003c\/p\u003e \u003cp\u003eOpen-Source Intelligence Gathering 77\u003c\/p\u003e \u003cp\u003eKey Takeaways 88\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 4 Cross-Site Scripting 89\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eXSS Categories 90\u003c\/p\u003e \u003cp\u003eReflected XSS 91\u003c\/p\u003e \u003cp\u003eStored XSS 93\u003c\/p\u003e \u003cp\u003eAutomatic User Session Hijacking 94\u003c\/p\u003e \u003cp\u003eWebsite Defacement Using XSS 96\u003c\/p\u003e \u003cp\u003eDOM-Based XSS 97\u003c\/p\u003e \u003cp\u003eSelf-XSS 98\u003c\/p\u003e \u003cp\u003eBrowser Exploitation Framework 100\u003c\/p\u003e \u003cp\u003eXSS Payloads and Bypasses 102\u003c\/p\u003e \u003cp\u003eXSS Mitigation Techniques 105\u003c\/p\u003e \u003cp\u003eReflected XSS Bypass Techniques 107\u003c\/p\u003e \u003cp\u003eStored XSS Bypass Technique 110\u003c\/p\u003e \u003cp\u003eKey Takeaways 112\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 5 SQL Injection 113\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eWhat Is SQL Injection? 113\u003c\/p\u003e \u003cp\u003eTypes of SQL Injection 114\u003c\/p\u003e \u003cp\u003eError-Based SQL Injection 117\u003c\/p\u003e \u003cp\u003eUnion-Based SQL Injection 117\u003c\/p\u003e \u003cp\u003eBlind SQL Injection 123\u003c\/p\u003e \u003cp\u003eSQLMap 126\u003c\/p\u003e \u003cp\u003eSQL Injection Payloads with ChatGPT 140\u003c\/p\u003e \u003cp\u003eSQL Injection Prevention 142\u003c\/p\u003e \u003cp\u003eKey Takeaways 145\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 6 Cross-Site Request Forgery 147\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eHunting CSRF Vulnerability 149\u003c\/p\u003e \u003cp\u003eCSRF Exploitation 149\u003c\/p\u003e \u003cp\u003eXSS and CSRF 151\u003c\/p\u003e \u003cp\u003eClickjacking 152\u003c\/p\u003e \u003cp\u003eGenerating an Effective Proof of Concept Using ChatGPT 154\u003c\/p\u003e \u003cp\u003eTips for Developers 157\u003c\/p\u003e \u003cp\u003eKey Takeaways 158\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 7 Server-Side Attacks and Open Redirects 159\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eServer-Side Request Forgery 159\u003c\/p\u003e \u003cp\u003eSSRF in Action 160\u003c\/p\u003e \u003cp\u003eSSRF Vulnerability 162\u003c\/p\u003e \u003cp\u003eBlind SSRF 164\u003c\/p\u003e \u003cp\u003eLocal File Inclusion 166\u003c\/p\u003e \u003cp\u003eRemote File Inclusion 170\u003c\/p\u003e \u003cp\u003eOpen Redirect 173\u003c\/p\u003e \u003cp\u003eServer-Side Attacks Differences 177\u003c\/p\u003e \u003cp\u003eSecurity Mitigations 178\u003c\/p\u003e \u003cp\u003eKey Takeaways 181\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 8 XML-Based Attacks 183\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eXML Fundamentals 183\u003c\/p\u003e \u003cp\u003eXXE Exploitation 185\u003c\/p\u003e \u003cp\u003eHunting XML Entry Points 187\u003c\/p\u003e \u003cp\u003eSSRF Using XXE 192\u003c\/p\u003e \u003cp\u003eDoS Using XXE 193\u003c\/p\u003e \u003cp\u003eXXE Payload and Exploitation with ChatGPT 195\u003c\/p\u003e \u003cp\u003eXML-Based Attacks Countermeasures 196\u003c\/p\u003e \u003cp\u003eKey Takeaways 198\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 9 Authentication and Authorization 201\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003ePassword Cracking and Brute-Force Attacks 205\u003c\/p\u003e \u003cp\u003eCredential Stuffing Attack 211\u003c\/p\u003e \u003cp\u003ePassword Spraying 213\u003c\/p\u003e \u003cp\u003ePassword Spraying Using Burp Suite Intruder 214\u003c\/p\u003e \u003cp\u003eOther Automated Tools for Password Attacks 215\u003c\/p\u003e \u003cp\u003eJSON Web Token 223\u003c\/p\u003e \u003cp\u003eKey Takeaways 225\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 10 API Attacks 227\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eOWASP API Top 10 228\u003c\/p\u003e \u003cp\u003eAPI Enumeration and Discovery 230\u003c\/p\u003e \u003cp\u003eAPI Discovery Using ChatGPT 231\u003c\/p\u003e \u003cp\u003eAPI Broken Object-Level Authorization Exploitation 235\u003c\/p\u003e \u003cp\u003eRate Limiting 240\u003c\/p\u003e \u003cp\u003eAPI Penetration Testing Tools 242\u003c\/p\u003e \u003cp\u003eAPI Security Tips 244\u003c\/p\u003e \u003cp\u003eKey Takeaways 245\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix A Best Practices and Standards 247\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eInformation Gathering 248\u003c\/p\u003e \u003cp\u003eConfiguration and Deployment Management Testing 251\u003c\/p\u003e \u003cp\u003eIdentity Management Testing 254\u003c\/p\u003e \u003cp\u003eAuthentication Testing 256\u003c\/p\u003e \u003cp\u003eAuthorization Testing 261\u003c\/p\u003e \u003cp\u003eSession Management Testing 265\u003c\/p\u003e \u003cp\u003eInput Validation Testing 273\u003c\/p\u003e \u003cp\u003eTesting for Error Handling 285\u003c\/p\u003e \u003cp\u003eTesting for Weak Cryptography 286\u003c\/p\u003e \u003cp\u003eBusiness Logic Testing 290\u003c\/p\u003e \u003cp\u003eClient-Side Testing 297\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix B CWE and CVSS Score 307\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eBase Score 308\u003c\/p\u003e \u003cp\u003eTemporal Score 308\u003c\/p\u003e \u003cp\u003eEnvironmental Score 309\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix c Writing Effective and Comprehensive Penetration Testing Reports 311\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eTable of Contents (ToC) 311\u003c\/p\u003e \u003cp\u003eProject History and Timeline 311\u003c\/p\u003e \u003cp\u003eScope 312\u003c\/p\u003e \u003cp\u003eTesting Approach 312\u003c\/p\u003e \u003cp\u003eExecutive Summary 312\u003c\/p\u003e \u003cp\u003eIndustry Standard 312\u003c\/p\u003e \u003cp\u003eFindings Table 312\u003c\/p\u003e \u003cp\u003eFindings Details 313\u003c\/p\u003e \u003cp\u003eKey Takeaways 315\u003c\/p\u003e \u003cp\u003eIndex 317\u003c\/p\u003e\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003eSubject Areas: Computer networking \u0026amp; communications [\u003ca title=\"See our other books on Computer networking \u0026amp; communications\" href=\"https:\/\/freshlyprintedbooks.co.uk\/search?q=%22Computer%20networking%20\u0026amp;%20communications%20%5BUT%5D%22\"\u003eUT\u003c\/a\u003e]\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\r\n\u003c\/font\u003e","brand":"Wiley","offers":[{"title":"Brand New","offer_id":52449473462552,"sku":"9781394295593","price":37.35,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0730\/2037\/5320\/files\/9781394295593.jpg?v=1785201087","url":"https:\/\/freshlyprintedbooks.co.uk\/products\/a-beginners-guide-to-web-application-penetration-testing-paperback-softback-9781394295593","provider":"Freshly Printed Books","version":"1.0","type":"link"}