Skip to Content
How to Break Web Software: Functional and Security Testing of Web Applications and Web Services
book

How to Break Web Software: Functional and Security Testing of Web Applications and Web Services

by James A. Whittaker, Mike Andrews
February 2006
Intermediate to advanced
240 pages
5h 47m
English
Addison-Wesley Professional
Content preview from How to Break Web Software: Functional and Security Testing of Web Applications and Web Services

CHAPTER 3. Attacking the Client

image

What’s In This Chapter?

This chapter outlines attacks against ill-advised, client-side coding tricks that work on normal graphical user interface (GUI) applications but create security disasters in Web applications. The problem: Client-side code is too easy to tamper with. The lesson: You need to do all the important stuff on the server.

Also see Chapter 5, “Attacking User-Supplied Input Data,” for attacks against user input, which also affect the client.

Introduction

Long before the Web existed, most software was self-contained on a single machine or executed in a closed (non Internet-facing) client-server environment. ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Web Security Testing Cookbook

Web Security Testing Cookbook

Paco Hope, Ben Walther
Hands-On Security in DevOps

Hands-On Security in DevOps

Tony Hsiang-Chih Hsu

Publisher Resources

ISBN: 9780321657497Purchase book