Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions Review

Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions
Average Reviews:

(More customer reviews)
I'm still in the middle of the book, and I definitely will skim thru all the remaining pages (just because I paid for it), but I wouldn't recommend the book to anyone looking for serious and in-depth study on web security - the book just doesn't offer that. What it does is a list of possible attack vectors and sometimes offers "solutions" which can help to fight with the attacks. However, the attacks descriptions are shallow, solutions are very short and non-extensive and many of them go as far as telling a user to install NoScript extension for Firefox (huh? Web 2.0 doesn't work with no JavaScript).
There are also quadrillions of links to a security-related site (won't list it here) which offers a toolbar to checks your sites again the most common security problems. I don't have anything against links to useful tools of course, but THAT amount of links just makes this book look like an advertisement of the fore-mentioned site. Am not even talking about page space wasted to re-iterate "go to ...., install ...., click .... in order to test for ....." which usually take 0.5-1 pages. Users who read that sort of books can somehow figure out how to use a toolbar, I believe.
I'm not by any means a security expert, and this book did introduce me into the topic, but it didn't do anything beyond that. I still need to read some other book on the topic, and that book will probably contain the same info as the Hacking Web 2.0 Exposed (i.e. the very basic info on web expoits), so.. I actually just recommend to pass on this book at all, and look for something which covers the topic in greater depth.

Click Here to see more reviews about: Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions


Lock down next-generation Web services

"This book concisely identifies the types of attacks which are faced daily by Web 2.0 sites, and the authors give solid, practical advice on how to identify and mitigate these threats." --Max Kelly, CISSP, CIPP, CFCE, Senior Director of Security, Facebook

Protect your Web 2.0 architecture against the latest wave of cybercrime using expert tactics from Internet security professionals. Hacking Exposed Web 2.0 shows how hackers perform reconnaissance, choose their entry point, and attack Web 2.0-based services, and reveals detailed countermeasures and defense techniques. You'll learn how to avoid injection and buffer overflow attacks, fix browser and plug-in flaws, and secure AJAX, Flash, and XML-driven applications. Real-world case studies illustrate social networking site weaknesses, cross-site attack methods, migration vulnerabilities, and IE7 shortcomings.

Plug security holes in Web 2.0 implementations the proven Hacking Exposed way
Learn how hackers target and abuse vulnerable Web 2.0 applications, browsers, plug-ins, online databases, user inputs, and HTML forms
Prevent Web 2.0-based SQL, XPath, XQuery, LDAP, and command injection attacks
Circumvent XXE, directory traversal, and buffer overflow exploits
Learn XSS and Cross-Site Request Forgery methods attackers use to bypass browser security controls
Fix vulnerabilities in Outlook Express and Acrobat Reader add-ons
Use input validators and XML classes to reinforce ASP and .NET security
Eliminate unintentional exposures in ASP.NET AJAX (Atlas), Direct Web Remoting, Sajax, and GWT Web applications
Mitigate ActiveX security exposures using SiteLock, code signing, and secure controls
Find and fix Adobe Flash vulnerabilities and DNS rebinding attacks

Buy Now

Click here for more information about Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions

Read More...

The Myths of Security: What the Computer Security Industry Doesn't Want You to Know Review

The Myths of Security: What the Computer Security Industry Doesn't Want You to Know
Average Reviews:

(More customer reviews)
Let me start by saying I usually like John Viega's books. I rated Building Secure Software 5 stars back in 2005 and 19 Deadly Sins of Software Security 4 stars in 2006. However, I must not be the target audience for this book, and I can't imagine who really would be. The book mainly addresses consumer concerns and largely avoids the enterprise. However, if most consumers think "antivirus" when they think "security," why would they bother reading The Myths of Security (TMOS)?
TMOS is strongest when Viega talks about the antivirus (or antimalware, or endpoint protection, or whatever host-centric security mechanism you choose) industry. I didn't find anything to be particularly "myth-shattering," however. I have to agree with two of the previous reviewers. Many of the "chapters" in this book could be blog posts. The longer chapters could be longer blog posts. The lack of a unifying theme really puts TMOS at a disadvantage compared to well-crafted books. I was not a huge fan of The New School of Information Security or Geekonomics (both 4 stars), but those two titles are better than TMOS.
If you want to read books that will really help you think properly about digital security, the two must-reads are still Secrets and Lies by Bruce Schneier and Security Engineering, 2nd Ed by Ross Anderson. I would avoid Bruce's sequel, Beyond Fear -- it's ok, but he muddles a few concepts. (Heresy, I know!) I haven't read Schneier on Security, but I imagine it is good given the overall quality of his blog postings.
If you want to shatter some serious myths, spend time writing a book on the "80% myth," which is stated in a variety of ways by anyone who is trying to demonstrate that insider threats are the worst problem facing digital security. If you're going to pretend to debunk open source security, why not back it up with some numbers? Studies have been published recently, and original research and results would be welcome. How about demonstrating that user awareness training wastes money, because enough marks fall prey anyway? I'd also like to see research showing that frequent password changes are worse for security, not better. Wrap all of that in a coherent manner with substantial chapters and you have a real TMOS book.

Click Here to see more reviews about: The Myths of Security: What the Computer Security Industry Doesn't Want You to Know


If you think computer security has improved in recent years, The Myths of Security will shake you out of your complacency. Longtime security professional John Viega, formerly Chief Security Architect at McAfee, reports on the sorry state of the industry, and offers concrete suggestions for professionals and individuals confronting the issue. Why is security so bad? With many more people online than just a few years ago, there are more attackers -- and they're truly motivated. Attacks are sophisticated, subtle, and harder to detect than ever. But, as Viega notes, few people take the time to understand the situation and protect themselves accordingly. This book tells you:



Why it's easier for bad guys to "own" your computer than you think
Why anti-virus software doesn't work well -- and one simple way to fix it
Whether Apple OS X is more secure than Windows
What Windows needs to do better
How to make strong authentication pervasive
Why patch management is so bad
Whether there's anything you can do about identity theft
Five easy steps for fixing application security, and more

Provocative, insightful, and always controversial, The Myths of Security not only addresses IT professionals who deal with security issues, but also speaks to Mac and PC users who spend time online.


Buy Now

Click here for more information about The Myths of Security: What the Computer Security Industry Doesn't Want You to Know

Read More...

The Mom's Guide to Earning and Saving Thousands on the Internet (Mom's Guide to Earning & Saving Thousands on the Internet) Review

The Mom's Guide to Earning and Saving Thousands on the Internet (Mom's Guide to Earning and Saving Thousands on the Internet)
Average Reviews:

(More customer reviews)
I have been making money online since 1998 and am always checking out resources to help me make more. The Mom's Guide to Earning and Saving Thousands on the Internet offers some terrific savings ideas and resources in one place. It's especially helpful for busy moms who don't have time to research and investigate resources themselves.
I was very intersted in the earning aspect especially since it covered surveys and mystery shopping. I still don't feel this is a great way to earn income from home. I have tested many survey sites and have yet to get paid by the legitimate ones. Turns out I don't qualify for most surveys I'm sent. (I'm a 40 year old mom of two, married who owns a home...). I've gotten a free lunch with mystery shopping, but that won't pay the mortgage.
If you are looking for great resources and ideas to save money using the Internet, this is a good resource. But if you want to make money, this isn't your book.

Click Here to see more reviews about: The Mom's Guide to Earning and Saving Thousands on the Internet (Mom's Guide to Earning & Saving Thousands on the Internet)


How you can save more than $500 a month with just a click of a mouse

Web-savvy mothers Barb Webb and Maureen Heck show you how to avoid paying full price on everything from groceries to baby needs to renovations as well as find legitimate opportunities to make extra income for their households. In a few minutes of Web surfing a day, you will save time finding bargains and planning vacations without ever leaving your computer chairs.


Buy Now

Click here for more information about The Mom's Guide to Earning and Saving Thousands on the Internet (Mom's Guide to Earning & Saving Thousands on the Internet)

Read More...