2 ms·
This looks really great, and has some big names endorsing it. Has anyone here read the book and could provide some additional insight on what the book did for y
by mkrdouble 12y ago
This looks really great, and has some big names endorsing it. Has anyone here read the book and could provide some additional insight on what the book did for you?
- kevinastone 12y agowe're actually reading it collectively in our inaugural engineering book club. I'm about a third the way through, it's full of insights on weaknesses and exploits for web based applications.
- HeavenFox 12y agoI read a draft version of it through my employer, and I have to say it is the best book on Web security I've ever seen. It is basically an encyclopedia of attack vectors, organized by the technologies that enabled them. The author discusses both inherent problems with the protocol, as well as nuances in different implementations, which makes it extra valuable. Reading the book through was an eye-opener, and there were countless oh-crap-I-didn't-know-it-could-work-that-way moments. Two warnings about the book: first, it is really an encyclopedia, so the author skims the part on how to prevent the attacks. There's a security cheatsheet at the end of each chapter, which is helpful but a bit too succinct. You have to understand the book fully to really make use of it. If you're more into a cookbook style book, look elsewhere. Second, the browser information is not quite up-to-date and thorough. I can't blame the author, as security is an ever-changing landscape. But just standard warning: Do your experiments. Test the attack vectors in all browsers. I once shipped a vulnerability because I blindly trusted the information in the book (thankfully it was disclosed responsibly)
- wglb 12y agoI have read the book and recommend it to all my Security Awareness students. I recommend reading it earlier in the day, however, as it can lead to some uncomfortable thoughts that you don't want following you into your sleep.