官术网_书友最值得收藏!

Introduction to Penetration Testing and Web Applications

A web application uses the HTTP protocol for client-server communication and requires a web browser as the client interface. It is probably the most ubiquitous type of application in modern companies, from Human Resources' organizational climate surveys to IT technical services for a company's website. Even thick and mobile applications and many Internet of Things (IoT) devices make use of web components through web services and the web interfaces that are embedded into them.

Not long ago, it was thought that security was necessary only at the organization's perimeter and only at network level, so companies spent considerable amount of money on physical and network security. With that, however, came a somewhat false sense of security because of their reliance on web technologies both inside and outside of the organization. In recent years and months, we have seen news of spectacular data leaks and breaches of millions of records including information such as credit card numbers, health histories, home addresses, and the Social Security Numbers (SSNs) of people from all over the world. Many of these attacks were started by exploiting a web vulnerability or design failure.

Modern organizations acknowledge that they depend on web applications and web technologies, and that they are as prone to attack as their network and operating systems—if not more so. This has resulted in an increase in the number of companies who provide protection or defense services against web attacks, as well as the appearance or growth of technologies such as Web Application Firewall (WAF), Runtime Application Self-Protection (RASP), web vulnerability scanners, and source code scanners. Also, there has been an increase in the number of organizations that find it valuable to test the security of their applications before releasing them to end users, providing an opportunity for talented hackers and security professionals to use their skills to find flaws and provide advice on how to fix them, thereby helping companies, hospitals, schools, and governments to have more secure applications and increasingly improved software development practices.

主站蜘蛛池模板: 弥勒县| 丰宁| 金阳县| 东台市| 德昌县| 白朗县| 周至县| 乐至县| 清新县| 来安县| 寻乌县| 北宁市| 天祝| 青河县| 石棉县| 邹城市| 柘荣县| 北海市| 建阳市| 晋州市| 将乐县| 两当县| 平江县| 肃北| 南川市| 交口县| 宁乡县| 贵定县| 察哈| 靖安县| 和平区| 滨州市| 枣阳市| 忻州市| 弥渡县| 宿州市| 颍上县| 吉水县| 浠水县| 乌审旗| 保山市|