Ajax security:
Gespeichert in:
Hauptverfasser: | , |
---|---|
Format: | Buch |
Sprache: | English |
Veröffentlicht: |
Upper Saddle River, NJ [u.a.]
Addison-Wesley
2007
|
Ausgabe: | 1. print. |
Schlagworte: | |
Online-Zugang: | Inhaltsverzeichnis |
Beschreibung: | XXVI, 470 S. Ill. |
ISBN: | 0321491939 9780321491930 |
Internformat
MARC
LEADER | 00000nam a2200000 c 4500 | ||
---|---|---|---|
001 | BV036754815 | ||
003 | DE-604 | ||
005 | 20110120 | ||
007 | t | ||
008 | 101103s2007 a||| |||| 00||| eng d | ||
010 | |a 2007037191 | ||
020 | |a 0321491939 |c pbk. : alk. paper |9 0-321-49193-9 | ||
020 | |a 9780321491930 |c pbk. : alk. paper |9 978-0-321-49193-0 | ||
035 | |a (OCoLC)705943494 | ||
035 | |a (DE-599)GBV54396499X | ||
040 | |a DE-604 |b ger |e aacr | ||
041 | 0 | |a eng | |
049 | |a DE-522 |a DE-92 | ||
084 | |a ST 253 |0 (DE-625)143628: |2 rvk | ||
100 | 1 | |a Hoffman, Billy |d 1980- |e Verfasser |0 (DE-588)140847677 |4 aut | |
245 | 1 | 0 | |a Ajax security |c Billy Hoffman and Bryan Sullivan |
250 | |a 1. print. | ||
264 | 1 | |a Upper Saddle River, NJ [u.a.] |b Addison-Wesley |c 2007 | |
300 | |a XXVI, 470 S. |b Ill. | ||
336 | |b txt |2 rdacontent | ||
337 | |b n |2 rdamedia | ||
338 | |b nc |2 rdacarrier | ||
650 | 0 | 7 | |a Gestaltung |0 (DE-588)4157139-3 |2 gnd |9 rswk-swf |
650 | 0 | 7 | |a Computersicherheit |0 (DE-588)4274324-2 |2 gnd |9 rswk-swf |
650 | 0 | 7 | |a Web-Seite |0 (DE-588)4356308-9 |2 gnd |9 rswk-swf |
650 | 0 | 7 | |a Ajax |g Informatik |0 (DE-588)7515401-8 |2 gnd |9 rswk-swf |
653 | |a Ajax (Web site development technology) | ||
653 | |a Computer networks |a Security measures | ||
653 | |a Computer security | ||
689 | 0 | 0 | |a Web-Seite |0 (DE-588)4356308-9 |D s |
689 | 0 | 1 | |a Gestaltung |0 (DE-588)4157139-3 |D s |
689 | 0 | 2 | |a Ajax |g Informatik |0 (DE-588)7515401-8 |D s |
689 | 0 | 3 | |a Computersicherheit |0 (DE-588)4274324-2 |D s |
689 | 0 | |5 DE-604 | |
700 | 1 | |a Sullivan, Bryan |d 1974- |e Verfasser |0 (DE-588)140847715 |4 aut | |
856 | 4 | 2 | |m GBV Datenaustausch |q application/pdf |u http://bvbr.bib-bvb.de:8991/F?func=service&doc_library=BVB01&local_base=BVB01&doc_number=020672015&sequence=000001&line_number=0001&func_code=DB_RECORDS&service_type=MEDIA |3 Inhaltsverzeichnis |
999 | |a oai:aleph.bib-bvb.de:BVB01-020672015 |
Datensatz im Suchindex
_version_ | 1804143419377844224 |
---|---|
adam_text | IMAGE 1
PREFACE
P. XVII
PREFACE (THE REAL ONE)
P. XVIX
INTRODUCTION TO AJAX SECURITY
P. 1
AN AJAX PRIMER
P. 2
WHAT IS AJAX?
P. 2
ASYNCHRONOUS
P. 3
JAVASCRIPT
P. 6
XML
P. 11
DYNAMIC HTML (DHTML)
P. 11
THE AJAX ARCHITECTURE SHIFT
P. 11
THICK-CLIENT ARCHITECTURE
P. 12
THIN-CLIENT ARCHITECTURE
P. 13
AJAX: THE GOLDILOCKS OF ARCHITECTURE
P. 15
A SECURITY PERSPECTIVE: THICK-CLIENT APPLICATIONS
P. 16
A SECURITY PERSPECTIVE: THIN-CLIENT APPLICATIONS
P. 17
A SECURITY PERSPECTIVE: AJAX APPLICATIONS
P. 18
A PERFECT STORM OF VULNERABILITIES
P. 19
INCREASED COMPLEXITY, TRANSPARENCY, AND SIZE
P. 19
SOCIOLOGICAL ISSUES
P. 22
AJAX APPLICATIONS: ATTRACTIVE AND STRATEGIC TARGETS
P. 23
CONCLUSIONS
P. 24
THE HEIST
P. 25
EVE
P. 25
HACKING HIGHTECHVACATIONS.NET
P. 26
HACKING THE COUPON SYSTEM
P. 26
ATTACKING CLIENT-SIDE DATA BINDING
P. 32
ATTACKING THE AJAX API
P. 36
A THEFT IN THE NIGHT
P. 42
WEB ATTACKS
P. 45
THE BASIC ATTACK CATEGORIES
P. 45
RESOURCE ENUMERATION
P. 46
PARAMETER MANIPULATION
P. 50
OTHER ATTACKS
P. 75
CROSS-SITE REQUEST FORGERY (CSRF)
P. 75
PHISHING
P. 76
DENIAL-OF-SERVICE (DOS)
P. 77
PROTECTING WEB APPLICATIONS FROM RESOURCE ENUMERATION AND PARAMETER
MANIPULATION
P. 77
SECURE SOCKETS LAYER
P. 78
CONCLUSIONS
P. 78
AJAX ATTACK SURFACE
P. 81
IMAGE 2
UNDERSTANDING THE ATTACK SURFACE
P. 81
TRADITIONAL WEB APPLICATION ATTACK SURFACE
P. 83
FORM INPUTS
P. 83
COOKIES
P. 84
HEADERS
P. 85
HIDDEN FORM INPUTS
P. 86
QUERY PARAMETERS
P. 86
UPLOADED FILES
P. 89
TRADITIONAL WEB APPLICATION ATTACKS: A REPORT CARD
P. 90
WEB SERVICE ATTACK SURFACE
P. 92
WEB SERVICE METHODS
P. 92
WEB SERVICE DEFINITIONS
P. 94
AJAX APPLICATION ATTACK SURFACE
P. 94
THE ORIGIN OF THE AJAX APPLICATION ATTACK SURFACE
P. 96
BEST OF BOTH WORLDS-FOR THE HACKER
P. 98
PROPER INPUT VALIDATION
P. 98
THE PROBLEM WITH BLACKLISTING AND OTHER SPECIFIC FIXES
P. 99
TABLE OF CONTENTS PROVIDED BY BLACKWELL S BOOK SERVICES AND R.R. BOWKER.
USED WITH PERMISSION.
|
any_adam_object | 1 |
author | Hoffman, Billy 1980- Sullivan, Bryan 1974- |
author_GND | (DE-588)140847677 (DE-588)140847715 |
author_facet | Hoffman, Billy 1980- Sullivan, Bryan 1974- |
author_role | aut aut |
author_sort | Hoffman, Billy 1980- |
author_variant | b h bh b s bs |
building | Verbundindex |
bvnumber | BV036754815 |
classification_rvk | ST 253 |
ctrlnum | (OCoLC)705943494 (DE-599)GBV54396499X |
discipline | Informatik |
edition | 1. print. |
format | Book |
fullrecord | <?xml version="1.0" encoding="UTF-8"?><collection xmlns="http://www.loc.gov/MARC21/slim"><record><leader>01880nam a2200469 c 4500</leader><controlfield tag="001">BV036754815</controlfield><controlfield tag="003">DE-604</controlfield><controlfield tag="005">20110120 </controlfield><controlfield tag="007">t</controlfield><controlfield tag="008">101103s2007 a||| |||| 00||| eng d</controlfield><datafield tag="010" ind1=" " ind2=" "><subfield code="a">2007037191</subfield></datafield><datafield tag="020" ind1=" " ind2=" "><subfield code="a">0321491939</subfield><subfield code="c">pbk. : alk. paper</subfield><subfield code="9">0-321-49193-9</subfield></datafield><datafield tag="020" ind1=" " ind2=" "><subfield code="a">9780321491930</subfield><subfield code="c">pbk. : alk. paper</subfield><subfield code="9">978-0-321-49193-0</subfield></datafield><datafield tag="035" ind1=" " ind2=" "><subfield code="a">(OCoLC)705943494</subfield></datafield><datafield tag="035" ind1=" " ind2=" "><subfield code="a">(DE-599)GBV54396499X</subfield></datafield><datafield tag="040" ind1=" " ind2=" "><subfield code="a">DE-604</subfield><subfield code="b">ger</subfield><subfield code="e">aacr</subfield></datafield><datafield tag="041" ind1="0" ind2=" "><subfield code="a">eng</subfield></datafield><datafield tag="049" ind1=" " ind2=" "><subfield code="a">DE-522</subfield><subfield code="a">DE-92</subfield></datafield><datafield tag="084" ind1=" " ind2=" "><subfield code="a">ST 253</subfield><subfield code="0">(DE-625)143628:</subfield><subfield code="2">rvk</subfield></datafield><datafield tag="100" ind1="1" ind2=" "><subfield code="a">Hoffman, Billy</subfield><subfield code="d">1980-</subfield><subfield code="e">Verfasser</subfield><subfield code="0">(DE-588)140847677</subfield><subfield code="4">aut</subfield></datafield><datafield tag="245" ind1="1" ind2="0"><subfield code="a">Ajax security</subfield><subfield code="c">Billy Hoffman and Bryan Sullivan</subfield></datafield><datafield tag="250" ind1=" " ind2=" "><subfield code="a">1. print.</subfield></datafield><datafield tag="264" ind1=" " ind2="1"><subfield code="a">Upper Saddle River, NJ [u.a.]</subfield><subfield code="b">Addison-Wesley</subfield><subfield code="c">2007</subfield></datafield><datafield tag="300" ind1=" " ind2=" "><subfield code="a">XXVI, 470 S.</subfield><subfield code="b">Ill.</subfield></datafield><datafield tag="336" ind1=" " ind2=" "><subfield code="b">txt</subfield><subfield code="2">rdacontent</subfield></datafield><datafield tag="337" ind1=" " ind2=" "><subfield code="b">n</subfield><subfield code="2">rdamedia</subfield></datafield><datafield tag="338" ind1=" " ind2=" "><subfield code="b">nc</subfield><subfield code="2">rdacarrier</subfield></datafield><datafield tag="650" ind1="0" ind2="7"><subfield code="a">Gestaltung</subfield><subfield code="0">(DE-588)4157139-3</subfield><subfield code="2">gnd</subfield><subfield code="9">rswk-swf</subfield></datafield><datafield tag="650" ind1="0" ind2="7"><subfield code="a">Computersicherheit</subfield><subfield code="0">(DE-588)4274324-2</subfield><subfield code="2">gnd</subfield><subfield code="9">rswk-swf</subfield></datafield><datafield tag="650" ind1="0" ind2="7"><subfield code="a">Web-Seite</subfield><subfield code="0">(DE-588)4356308-9</subfield><subfield code="2">gnd</subfield><subfield code="9">rswk-swf</subfield></datafield><datafield tag="650" ind1="0" ind2="7"><subfield code="a">Ajax</subfield><subfield code="g">Informatik</subfield><subfield code="0">(DE-588)7515401-8</subfield><subfield code="2">gnd</subfield><subfield code="9">rswk-swf</subfield></datafield><datafield tag="653" ind1=" " ind2=" "><subfield code="a">Ajax (Web site development technology)</subfield></datafield><datafield tag="653" ind1=" " ind2=" "><subfield code="a">Computer networks</subfield><subfield code="a">Security measures</subfield></datafield><datafield tag="653" ind1=" " ind2=" "><subfield code="a">Computer security</subfield></datafield><datafield tag="689" ind1="0" ind2="0"><subfield code="a">Web-Seite</subfield><subfield code="0">(DE-588)4356308-9</subfield><subfield code="D">s</subfield></datafield><datafield tag="689" ind1="0" ind2="1"><subfield code="a">Gestaltung</subfield><subfield code="0">(DE-588)4157139-3</subfield><subfield code="D">s</subfield></datafield><datafield tag="689" ind1="0" ind2="2"><subfield code="a">Ajax</subfield><subfield code="g">Informatik</subfield><subfield code="0">(DE-588)7515401-8</subfield><subfield code="D">s</subfield></datafield><datafield tag="689" ind1="0" ind2="3"><subfield code="a">Computersicherheit</subfield><subfield code="0">(DE-588)4274324-2</subfield><subfield code="D">s</subfield></datafield><datafield tag="689" ind1="0" ind2=" "><subfield code="5">DE-604</subfield></datafield><datafield tag="700" ind1="1" ind2=" "><subfield code="a">Sullivan, Bryan</subfield><subfield code="d">1974-</subfield><subfield code="e">Verfasser</subfield><subfield code="0">(DE-588)140847715</subfield><subfield code="4">aut</subfield></datafield><datafield tag="856" ind1="4" ind2="2"><subfield code="m">GBV Datenaustausch</subfield><subfield code="q">application/pdf</subfield><subfield code="u">http://bvbr.bib-bvb.de:8991/F?func=service&doc_library=BVB01&local_base=BVB01&doc_number=020672015&sequence=000001&line_number=0001&func_code=DB_RECORDS&service_type=MEDIA</subfield><subfield code="3">Inhaltsverzeichnis</subfield></datafield><datafield tag="999" ind1=" " ind2=" "><subfield code="a">oai:aleph.bib-bvb.de:BVB01-020672015</subfield></datafield></record></collection> |
id | DE-604.BV036754815 |
illustrated | Illustrated |
indexdate | 2024-07-09T22:47:22Z |
institution | BVB |
isbn | 0321491939 9780321491930 |
language | English |
lccn | 2007037191 |
oai_aleph_id | oai:aleph.bib-bvb.de:BVB01-020672015 |
oclc_num | 705943494 |
open_access_boolean | |
owner | DE-522 DE-92 |
owner_facet | DE-522 DE-92 |
physical | XXVI, 470 S. Ill. |
publishDate | 2007 |
publishDateSearch | 2007 |
publishDateSort | 2007 |
publisher | Addison-Wesley |
record_format | marc |
spelling | Hoffman, Billy 1980- Verfasser (DE-588)140847677 aut Ajax security Billy Hoffman and Bryan Sullivan 1. print. Upper Saddle River, NJ [u.a.] Addison-Wesley 2007 XXVI, 470 S. Ill. txt rdacontent n rdamedia nc rdacarrier Gestaltung (DE-588)4157139-3 gnd rswk-swf Computersicherheit (DE-588)4274324-2 gnd rswk-swf Web-Seite (DE-588)4356308-9 gnd rswk-swf Ajax Informatik (DE-588)7515401-8 gnd rswk-swf Ajax (Web site development technology) Computer networks Security measures Computer security Web-Seite (DE-588)4356308-9 s Gestaltung (DE-588)4157139-3 s Ajax Informatik (DE-588)7515401-8 s Computersicherheit (DE-588)4274324-2 s DE-604 Sullivan, Bryan 1974- Verfasser (DE-588)140847715 aut GBV Datenaustausch application/pdf http://bvbr.bib-bvb.de:8991/F?func=service&doc_library=BVB01&local_base=BVB01&doc_number=020672015&sequence=000001&line_number=0001&func_code=DB_RECORDS&service_type=MEDIA Inhaltsverzeichnis |
spellingShingle | Hoffman, Billy 1980- Sullivan, Bryan 1974- Ajax security Gestaltung (DE-588)4157139-3 gnd Computersicherheit (DE-588)4274324-2 gnd Web-Seite (DE-588)4356308-9 gnd Ajax Informatik (DE-588)7515401-8 gnd |
subject_GND | (DE-588)4157139-3 (DE-588)4274324-2 (DE-588)4356308-9 (DE-588)7515401-8 |
title | Ajax security |
title_auth | Ajax security |
title_exact_search | Ajax security |
title_full | Ajax security Billy Hoffman and Bryan Sullivan |
title_fullStr | Ajax security Billy Hoffman and Bryan Sullivan |
title_full_unstemmed | Ajax security Billy Hoffman and Bryan Sullivan |
title_short | Ajax security |
title_sort | ajax security |
topic | Gestaltung (DE-588)4157139-3 gnd Computersicherheit (DE-588)4274324-2 gnd Web-Seite (DE-588)4356308-9 gnd Ajax Informatik (DE-588)7515401-8 gnd |
topic_facet | Gestaltung Computersicherheit Web-Seite Ajax Informatik |
url | http://bvbr.bib-bvb.de:8991/F?func=service&doc_library=BVB01&local_base=BVB01&doc_number=020672015&sequence=000001&line_number=0001&func_code=DB_RECORDS&service_type=MEDIA |
work_keys_str_mv | AT hoffmanbilly ajaxsecurity AT sullivanbryan ajaxsecurity |