Burp Suite Cookbook - Second Edition: Web application security made easy with Burp Suite
暫譯: Burp Suite 食譜 - 第二版:使用 Burp Suite 簡化網路應用程式安全性
Wear, Sunny
- 出版商: Packt Publishing
- 出版日期: 2023-10-27
- 售價: $1,880
- 貴賓價: 9.5 折 $1,786
- 語言: 英文
- 頁數: 450
- 裝訂: Quality Paper - also called trade paper
- ISBN: 183508107X
- ISBN-13: 9781835081075
-
相關分類:
資訊安全
海外代購書籍(需單獨結帳)
相關主題
商品描述
Find and fix security vulnerabilities in your web applications with Burp Suite
Key Features:
- Set up and optimize Burp Suite to maximize its effectiveness in web application security testing
- Explore how Burp Suite can be used to execute various OWASP test cases
- Get to grips with the essential features and functionalities of Burp Suite
- Purchase of the print or Kindle book includes a free PDF eBook
Book Description:
With its many features, easy-to-use interface, and fl exibility, Burp Suite is the top choice for professionals looking to strengthen web application and API security.
This book off ers solutions to challenges related to identifying, testing, and exploiting vulnerabilities in web applications and APIs. It provides guidance on identifying security weaknesses in diverse environments by using diff erent test cases. Once you've learned how to confi gure Burp Suite, the book will demonstrate the eff ective utilization of its tools, such as Live tasks, Scanner, Intruder, Repeater, and Decoder, enabling you to evaluate the security vulnerability of target applications. Additionally, you'll explore various Burp extensions and the latest features of Burp Suite, including DOM Invader.
By the end of this book, you'll have acquired the skills needed to confi dently use Burp Suite to conduct comprehensive security assessments of web applications and APIs.
What You Will Learn:
- Perform a wide range of tests, including authentication, authorization, business logic, data validation, and client-side attacks
- Use Burp Suite to execute OWASP test cases focused on session management
- Conduct Server-Side Request Forgery (SSRF) attacks with Burp Suite
- Execute XML External Entity (XXE) attacks and perform Remote Code Execution (RCE) using Burp Suite's functionalities
- Use Burp to help determine security posture of applications using GraphQL
- Perform various attacks against JSON Web Tokens (JWTs)
Who this book is for:
If you are a beginner- or intermediate-level web security enthusiast, penetration tester, or security consultant preparing to test the security posture of your applications and APIs, this is the book for you.
商品描述(中文翻譯)
使用 Burp Suite 找出並修復您的網頁應用程式中的安全漏洞
主要特點:
- 設置和優化 Burp Suite,以最大化其在網頁應用程式安全測試中的效能
- 探索如何使用 Burp Suite 執行各種 OWASP 測試案例
- 熟悉 Burp Suite 的基本功能和特性
- 購買印刷版或 Kindle 版書籍可獲得免費 PDF 電子書
書籍描述:
憑藉其眾多功能、易於使用的介面和靈活性,Burp Suite 是希望加強網頁應用程式和 API 安全的專業人士的首選。
本書提供了解決識別、測試和利用網頁應用程式及 API 中漏洞的挑戰的方案。它通過使用不同的測試案例,指導您在多樣化環境中識別安全弱點。一旦您學會如何配置 Burp Suite,本書將展示如何有效利用其工具,如 Live tasks、Scanner、Intruder、Repeater 和 Decoder,使您能夠評估目標應用程式的安全漏洞。此外,您還將探索各種 Burp 擴展和 Burp Suite 的最新功能,包括 DOM Invader。
在本書結束時,您將掌握自信使用 Burp Suite 進行網頁應用程式和 API 的全面安全評估所需的技能。
您將學到什麼:
- 執行各種測試,包括身份驗證、授權、業務邏輯、數據驗證和客戶端攻擊
- 使用 Burp Suite 執行專注於會話管理的 OWASP 測試案例
- 使用 Burp Suite 進行伺服器端請求偽造 (SSRF) 攻擊
- 執行 XML 外部實體 (XXE) 攻擊並利用 Burp Suite 的功能進行遠端代碼執行 (RCE)
- 使用 Burp 幫助確定使用 GraphQL 的應用程式的安全狀態
- 對 JSON Web Tokens (JWTs) 執行各種攻擊
本書適合誰:
如果您是初學者或中級網頁安全愛好者、滲透測試員或安全顧問,並準備測試您的應用程式和 API 的安全狀態,那麼這本書就是為您而寫的。