VOOZH about

URL: https://www.amazon.com/dp/1118026470/ref=mes-dp

⇱ The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws: Stuttard, Dafydd, Pinto, Marcus: 8601200464443: Amazon.com: Books


πŸ‘ Image
πŸ‘ Image
Enjoy fast, free delivery, exclusive deals, and award-winning movies & TV shows.
Buy New
-34% $34.52$34.52
FREE delivery Friday, July 3 on orders shipped by Amazon over $35
Ships from: Amazon
Sold by: ayvax

Download the free Kindle app and start reading Kindle books instantly on your smartphone, tablet, or computer - no Kindle device required.

Read instantly on your browser with Kindle for Web.


Using your mobile phone camera - scan the code below and download the Kindle app.

πŸ‘ QR code to download the Kindle App


Follow the author

Get new release updates & improved recommendations
Something went wrong. Please try your request again later.

OK

The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws


{"desktop_buybox_group_1":[{"displayPrice":"$34.52","priceAmount":34.52,"currencySymbol":"$","integerValue":"34","decimalSeparator":".","fractionalValue":"52","symbolPosition":"left","hasSpace":false,"showFractionalPartIfEmpty":true,"offerListingId":"id28qXu2C7WKMyWu2Cp5jOjnoASBV0tSHRXHhx8TMqb%2BWrYyNgazoL3tUhEkqMWyvwHQaMeqFjGuU%2Fs3vH2zEyIHn0Oy%2F%2Fa1IP6tFTLuPo3it7B4o96ssY%2F9eYHesAn30TXvimY3GM4Q0WWgZsfnsoNvZbfCvTMg6xPk8aNHnQi%2FP1SlF56l4g%3D%3D","locale":"en-US","buyingOptionType":"NEW","aapiBuyingOptionIndex":0}, {"displayPrice":"$18.00","priceAmount":18.00,"currencySymbol":"$","integerValue":"18","decimalSeparator":".","fractionalValue":"00","symbolPosition":"left","hasSpace":false,"showFractionalPartIfEmpty":true,"offerListingId":"id28qXu2C7WKMyWu2Cp5jOjnoASBV0tS%2By07fNLolaIXuXLxxU6b14Rv%2FWFBt16LxAq22hTlGmcAhbDGFV5ByZO1RKCZjxTI5WI%2F46Ht%2BZgeudfg%2Bo5j2mv6qwZtaIlTjDCEwJgjgHuFxTuNUWX8o4ZKWknLeXEy9TkJkVVqsKKEMaA3rH1P2g%3D%3D","locale":"en-US","buyingOptionType":"USED","aapiBuyingOptionIndex":1}]}

Purchase options and add-ons


The highly successful security book returns with a new edition, completely updatedWeb applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of ever-evolving web applications. You'll explore the various new technologies employed in web applications that have appeared since the first edition and review the new attack techniques that have been developed, particularly in relation to the client side.
  • Reveals how to overcome the new technologies and techniques aimed at defending web applications against attacks that have appeared since the previous edition
  • Discusses new remoting frameworks, HTML5, cross-domain integration techniques, UI redress, framebusting, HTTP parameter pollution, hybrid file attacks, and more
  • Features a companion web site hosted by the authors that allows readers to try out the attacks described, gives answers to the questions that are posed at the end of each chapter, and provides a summarized methodology and checklist of tasks
Focusing on the areas of web application security where things have changed in recent years, this book is the most current resource on the critical topic of discovering, exploiting, and preventing web application security flaws..
πŸ‘ Image
Report an issue with this product or seller


Frequently bought together

This item: The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
$34.52$34.52
Get it as soon as Friday, Jul 3
In Stock
Sold by ayvax and ships from Amazon Fulfillment.
$29.35$29.35
Get it as soon as Sunday, Jul 5
Sold by Hope's Ark and ships from Amazon Fulfillment.
Total price: $00$00
To see our price, add these items to your cart.
Try again!
Details
Added to Cart
Some of these items ship sooner than the others.
Choose items to buy together.

Customers who viewed this item also viewed

Page 1 of 1 Start over

Customers also bought or read

Page 1 of 1Start over
Loading...

Editorial Reviews

Review

Review

Review

From the Author

Empty

From the Inside Flap

New technologies. New attack techniques. Start hacking.

Web applications are everywhere, and they're insecure. Banks, retailers, and others have deployed millions of applications that are full of holes, allowing attackers to steal personal data, carry out fraud, and compromise other systems. This book shows you how they do it.

This fully updated edition contains the very latest attack techniques and countermeasures, showing you how to break into today's complex and highly functional applications. Roll up your sleeves and dig in.

  • Discover how cloud architectures and social networking have added exploitable attack surfaces to applications

  • Leverage the latest HTML features to deliver powerful cross-site scripting attacks

  • Deliver new injection exploits, including XML external entity and HTTP parameter pollution attacks

  • Learn how to break encrypted session tokens and other sensitive data found in cloud services

  • Discover how technologies like HTML5, REST, CSS and JSON can be exploited to attack applications and compromise users

  • Learn new techniques for automating attacksand dealing with CAPTCHAs and cross-site request forgery tokens

  • Steal sensitive data across domains using seemingly harmless application functions and new browser features

Find help and resources at http://mdsec.net/wahh

  • Source code for some of the scripts in the book

  • Links to tools and other resources

  • A checklist of tasks involved in most attacks

  • Answers to the questions posed in each chapter

  • Hundreds of interactive vulnerability labs

From the Back Cover

New technologies. New attack techniques. Start hacking.Web applications are everywhere, and they're insecure. Banks, retailers, and others have deployed millions of applications that are full of holes, allowing attackers to steal personal data, carry out fraud, and compromise other systems. This book shows you how they do it.
This fully updated edition contains the very latest attack techniques and countermeasures, showing you how to break into today's complex and highly functional applications. Roll up your sleeves and dig in.
  • Discover how cloud architectures and social networking have added exploitable attack surfaces to applications
  • Leverage the latest HTML features to deliver powerful cross-site scripting attacks
  • Deliver new injection exploits, including XML external entity and HTTP parameter pollution attacks
  • Learn how to break encrypted session tokens and other sensitive data found in cloud services
  • Discover how technologies like HTML5, REST, CSS and JSON can be exploited to attack applications and compromise users
  • Learn new techniques for automating attacksand dealing with CAPTCHAs and cross-site request forgery tokens
  • Steal sensitive data across domains using seemingly harmless application functions and new browser features
Find help and resources at mdsec.net/wahh
  • Source code for some of the scripts in the book
  • Links to tools and other resources
  • A checklist of tasks involved in most attacks
  • Answers to the questions posed in each chapter
  • Hundreds of interactive vulnerability labs

About the Author

DAFYDD STUTTARD is an independent security consultant, author, and software developer specializing in penetration testing of web applications and compiled software. Under the alias PortSwigger, Dafydd created the popular Burp Suite of hacking tools.

MARCUS PINTO delivers security consultancy and training on web application attack and defense to leading global organizations in the financial, government, telecom, gaming, and retail sectors.
The authors cofounded MDSec, a consulting company that provides training in attack and defense-based security.


Product details

Brief content visible, double tap to read full content.
Full content visible, double tap to read brief content.

Videos

Help others learn more about this product by uploading a video!
Upload your video

About the author

Follow authors to get new release updates, plus improved recommendations.
Brief content visible, double tap to read full content.
Full content visible, double tap to read brief content.

Discover more of the author’s books, see similar authors, read book recommendations and more.


Customer reviews

4.7 out of 5 stars
1,119 global ratings
How customer reviews and ratings work

Customer Reviews, including Product Star Ratings help customers to learn more about the product and decide whether it is the right product for them.

To calculate the overall star rating and percentage breakdown by star, we don’t use a simple average. Instead, our system considers things like how recent a review is and if the reviewer bought the item on Amazon. It also analyzed reviews to verify trustworthiness.

Learn more how customers reviews work on Amazon



Amazon Customer
5 out of 5 stars
Best Hacking Book on the Market
I see a lot of negative review here but hold on we are talking about hacking here not making soda pop. I can understand the frustration from some of the readers but come on first concept of hacking is recon so guys you should have done your homework more thoroughly If you had done so this would have led you to the Portswigger page explaining in depth the correct use and application of the Burpsuite tools using the OWASP broken web project All examples can be done using manual or automated testing for you that done own the PRO version, once you have seen the power of this tool YOU WILL buy the PRO version The best book on the market by a mile in fact this is the standard other authors should follow
Thank you for your feedback
Sorry, there was an error
Sorry we couldn't load the review
There was a problem filtering reviews. Please reload the page.

Top reviews from the United States

  • William P Ross
    5 out of 5 stars
    Comprehensive Look At Website Security
    Reviewed in the United States on October 23, 2016
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    This book offers tons of techniques and strategies for attacking and defending web applications. The beginning chapters discuss the major components of websites and their vulnerabilites.

    The middle of the book gets much more specific showing "Hack Steps" for different components like the client side, sessions, databases, and authentication.

    Sections about custom code development show how you can develop your own solution to probe a web app. There were code examples in different languages such as JavaScript, C++, Java, and ASP.NET. The authors highlight many kinds of tools you can use to learn more about a website, including a product they developed themselves called Burp Suite.

    For readers interested in the testing the techniques there is a website offered by the book but it costs $7 an hour to play around on the site. This fee is for keeping the website running apparently, but I thought it would make more sense to have a monthly fee. I did not subscribe to this site myself though because I was more interested in getting a broad overview of website security.

    The book is showing its 2011 publication date in some places. For example, IE and Firefox are said to be the dominant browsers while Chrome is a minor player. Additionally, Flash and Silverlight are spoken of as being components of many websites. One issue was I was not really sure where techniques might be outdated and others are still relevant.

    I would definitely be interested in a 3rd edition for this book. The authors presented a solid foundation for learning about website security.

    19 people found this helpful
    Sending feedback...
    Thank you for your feedback.
    Sorry, we failed to record your vote. Please try again
    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
  • 5 out of 5 stars
    Bottom line: buy it
    Reviewed in the United States on April 8, 2013
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    Reading this book up to around page 600 made me seriously question how anyone could give it less than 5 stars. The amount of knowledge it gave me for a mere $25 is absolutely astounding. I was eagerly waiting to finish it so I could come review it.

    Then I finished it, and I understood some of the criticisms. It starts to feel like it's repeating itself after a while, and the product placement for Burp start to become a bit more annoying.

    Still, the rest of the book is chock full of great, detailed information. If you're like me and had a basic understanding of how SQL injection worked, but wanted to get a deeper look, this book is perfect. If you chopped off the last 200 pages you would have a book that was STILL worth well over $25. It's hard for me to give it less than 5 stars when my major complaint is that it gives too much information.

    Bottom line: if you're a beginner or intermediate to web application security and you're wondering whether you should buy this, just do it. You won't be disappointed.

    34 people found this helpful
    Sending feedback...
    Thank you for your feedback.
    Sorry, we failed to record your vote. Please try again
    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
  • Jason Haddix
    5 out of 5 stars
    The Book That Keeps on Giving...
    Reviewed in the United States on October 14, 2011
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    There's a running joke we have on our assessment team about the Web Application Hackers Handbook. Every time we see a new technology, or have to deal with a one-off situation, we start doing research online only to find it was already referenced in WAHH somewhere. We've all read this book several times too, it's like Dafydd and Marcus sneak into our houses at night and add content...

    Joking aside though, there is no other reference for web hacking as thorough or complete as WAHH.

    With WAHH2 the authors added a significant amount content and rehashed existing chapters that were already deeply technical. The bonus in WAHH2 is its associated labs. Dafydd and Marcus have been giving a live WAHH training for years and have now moved the stellar CTF like challenges to the cloud. You can buy credits ($7 for 1hr) and move right along as you read the book (MDSec.net). When I say the labs are stellar, I mean it. The labs come almost straight from the class and start trivial and then get crazy. The injection labs were by far my favorite, housing 30-40 different injection types/variants each between XSS/SQLi. The CTF in the class (which i'll mention again is where the MDSec.com labs are based from) gets ridiculous toward the end. Even seasoned web testers fall around questions 14-16. But i digress...

    WAHH2 is now the defacto buy for any pentest/QA/Audit team. Its usage will surpass any other book on your bookshelf if you are doing practical testing.

    5 stars, i'd give it 10 if I could.

    77 people found this helpful
    Sending feedback...
    Thank you for your feedback.
    Sorry, we failed to record your vote. Please try again
    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
  • 4 out of 5 stars
    A Must-Read for Aspiring and Experienced Web Security Professionals
    Reviewed in the United States on January 23, 2025
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    Don't let the age of this book fool you. While its not exactly a new book, the foundational principles of web security are in here. This book starts with the foundational principles of web technologies and then moves on to advanced attack methodologies like SQLi, XSS, CSRF and more complex business logic attacks. the book is well written, highly detailed,. and offers practical techniques. The only down side is that the links in the book no longer work.

    4 people found this helpful
    Sending feedback...
    Thank you for your feedback.
    Sorry, we failed to record your vote. Please try again
    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
  • 5 out of 5 stars
    Best. Book. Ever.
    Reviewed in the United States on November 30, 2018
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    I can't even tell you how many times I find myself referencing this book. Despite what some have suggested you don't need to have Burp Suite or do any labs. It's so full of insightful knowledge that it can replace a whole reference library all by itself. It doesn't just show you "how-tos" but helps you THINK differently - better - methodical. One little example is how the authors present the idea of overcoming filtering deployed by a WAF or web server. "<script>" might get filtered but what would happen if you passed "<scr<script>ipt>"? Now run with it and get creative! Can't thank the authors enough for their contribution. This is right up there with Homer's Odyssey, Shakespeare's Romeo and Juliet and quite frankly, The Bible. Ok, maybe that's pushing it but you get the idea.

    41 people found this helpful
    Sending feedback...
    Thank you for your feedback.
    Sorry, we failed to record your vote. Please try again
    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
  • 5 out of 5 stars
    Great tutorial and reference
    Reviewed in the United States on July 15, 2012
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    This book is worth every penny, no matter how many pennies are spent. Much like the Shellcoder's Handbook and their other books, this one is written with the same professional quality and technical detail. It's incredibly accurate, and starts on a very low level of understanding. Even if you are an experienced web hacker, it's useful to see new angles on things or get a few ideas for more advanced ideas of your own creation. The tool JAttack it takes you through making is a superb tool to build off of later. It waits to take you to the tool-building until after its built your foundation with techniques, as well, which is perfect progression.

    All in all, this book will take beginners and pros alike and serve as an excellent reference and lesson to bump you to whatever level of web application hacker you can be.

    4 people found this helpful
    Sending feedback...
    Thank you for your feedback.
    Sorry, we failed to record your vote. Please try again
    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
  • 5 out of 5 stars
    Gr at book
    Reviewed in the United States on August 20, 2025
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    Delivery intime and in perfect state

    Sending feedback...
    Thank you for your feedback.
    Sorry, we failed to record your vote. Please try again
    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
  • R. Christian Lyne
    5 out of 5 stars
    Still relevant in 2025
    Reviewed in the United States on May 31, 2025
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    The techniques and methodologies in this book are still relevant in 2025.

    3 people found this helpful
    Sending feedback...
    Thank you for your feedback.
    Sorry, we failed to record your vote. Please try again
    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again

Top reviews from other countries

    Translated by Amazon
    See original
  • 5 out of 5 stars
    SI quereis aprender seguridad web desde 0
    Reviewed in Spain on February 20, 2013
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    SI quereis aprender seguridad web desde 0, es mejor pista para comenzar, va desde bases hasta cosas muy avanzadas. y facil de leer! Asi que recomendable

    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
    Sorry, we couldn't translate the review
    Translated from Spanish by Amazon
    See original
  • 5 out of 5 stars
    impec'
    Reviewed in France on July 19, 2017
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    il m'aura fallu du temps pour le finir mais le contenu vaut le prix sans soucis :)

    un bon bouquin interessant et relativement complet.

    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
    Sorry, we couldn't translate the review
    Translated from French by Amazon
    See original
  • Maria Ines Parnisari
    5 out of 5 stars
    Still relevant!
    Reviewed in Canada on July 6, 2023
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    This book took me months to finish, but it's worth it. Some of the hacking tools mentioned don't exist anymore and you cannot test the vulnerabilities on the WAHH website because it doesn't exist. All the vulnerabilities mentioned are still relevant, except for a few related to Flash and Silverlight which I promptly skipped. The summary and questions at the end of each chapter are good to consolidate knowledge.

    Chapter 12 on cross site scripting is simultaneously the longest, most important, and most boring, in my opinion.

    It's funny that there is an entire chapter (9) devoted to SQL but only a paragraph about NoSQL which says "it's not popular enough so we won't discuss it". How times have changed!

    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
  • 5 out of 5 stars
    Good condition book
    Reviewed in the United Arab Emirates on January 30, 2021
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    Very good condition book

    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
  • ALΔ° BAYKARA
    5 out of 5 stars
    Portswigger web academy
    Reviewed in Turkey on November 9, 2024
    Brief content visible, double tap to read full content.
    Full content visible, double tap to read brief content.

    Portswigger web academy lablarΔ± yardΔ±mcΔ± olmasΔ± iΓ§in aldΔ±m kesinlikle alΔ±nΔ±r

    Sending feedback...
    Thanks, we'll investigate in the next few days.
    Sorry, We failed to report this review. Please try again
    Sorry, we couldn't translate the review
    Translated from Turkish by Amazon
    See original