5 ms·
In Web Security: - The Tangled Web (http://lcamtuf.coredump.cx/tangled/ http://lcamtuf.coredump.cx/tangled/) You can look at the Web Application Hacker's Handb
by bugmen0t 8y ago
In Web Security:
- The Tangled Web (http://lcamtuf.coredump.cx/tangled/ http://lcamtuf.coredump.cx/tangled/)
You can look at the Web Application Hacker's Handbook or the Browser Hacker's Handbook, if you want. But TTW tops them all.
- brox 8y agoWould like to hear general information security recommendations as well.
- indigochill 8y agoA couple I've learned from (I've left out heavily topic-specific books like Cryptography Engineering since I assume you're asking for books about general information security): Hacking, 2nd Edition - Introduces the foundations of memory and network exploitation [Security Engineering](https://www.cl.cam.ac.uk/~rja14/book.html https://www.cl.cam.ac.uk/~rja14/book.html) - An overview of a huge array of info sec topics, from "E-policy" to nuclear command security. Advanced Penetration Testing - Focuses on simulating APT attacks, using the author's penetration testing experiences to illustrate each point.
- brox 8y agoThanks for the suggestions, folks!
- agnokapathetic 8y agoThe Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities by Mark Dow et al. https://www.amazon.com/dp/0321444426/ https://www.amazon.com/dp/0321444426/ (https://www.amazon.com/dp/0321444426/ https://www.amazon.com/dp/0321444426/) This book will give you the fundamentals of application security testing.
- tptacek 8y agoTangled and WAHH are very different books. They're not substitutes for each other. Tangled is closer to Browser Hackers.