Showing posts with label sql. Show all posts
Showing posts with label sql. Show all posts

Pro SQL Server 2008 Analytics: Delivering Sales and Marketing Dashboards (Expert's Voice in SQL Server) Review

Pro SQL Server 2008 Analytics: Delivering Sales and Marketing Dashboards (Expert's Voice in SQL Server)
Average Reviews:

(More customer reviews)
I referred to this book while doing a prototype in building a Sales dashboard for a company. It gave me a jump start in using Microsoft technologies to come up with a dashboard in a short time. To be honest this is the first book I am referring to on this task. Especially I liked the case studies chapter at the end of the book to be very helpful. The chapters provide covers well on details around SQL Server analytics but I was looking for examples in each chapter to get me though. But this book solved it's purpose for me.
I will recommend this book to other like me who want to start working on dashboards and analytics using SQL Server tools.


Click Here to see more reviews about: Pro SQL Server 2008 Analytics: Delivering Sales and Marketing Dashboards (Expert's Voice in SQL Server)

SQL Server 2008 is the latest version of Microsoft's popular SQL Server database product. It has been very well received since its release in July 2008, most notably for its greatly increased reporting and analytical capabilities over previous versions. There is a strong reader demand for information related to these aspects of SQL Server.This book aims to provide developers and their managers with a complete reference to building reporting dashboards that are able to assimilate information from various sources and integrate with other Microsoft technologies such as SharePoint and PerformancePoint to present that information in flexible ways. It is a generalist guide, and teaches techniques that can be applied to a wide range of reader situations.

Buy Now

Click here for more information about Pro SQL Server 2008 Analytics: Delivering Sales and Marketing Dashboards (Expert's Voice in SQL Server)

Read More...

Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-' Review

Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'
Average Reviews:

(More customer reviews)
I had really no idea what to expect when I started reading Web Application Obfuscation (WAO). I hoped it would address attacks on Web technologies, perhaps including evasion methods, but beyond that I didn't even really know how to think about whatever problem this book might address. After finishing WAO, it's only appropriate to say "wow." In short, I had no idea that Web browsers (often called "user agents" in WAO) are so universally broken. Web browser developers would probably reply that they're just trying to handle as much broken HTML as possible, but the WAO authors show this approach makes Web "security" basically impossible. I recommend reading WAO to learn just how crazy one can be when interacting with Web apps.
Speaking of crazy: ch 4 was off the hook. For example, p 121 speaks of the "great Javascript Charwall" by saying: "6 is the fewest number of characters possible which allow arbitrary Javascript to be executed." What!? I had no idea anyone spent time on these sorts of issues, and worse, that intruders could use these techniques to evade a slew of security mechanisms. This was a primary strength of WAO: bringing the reader into a world where obfuscation is an obsession.
I liked many other aspects of WAO. The book was very thorough. For one example, check the table on p 27. For another, see the regex explanation with examples in ch 1. The book has many such sections where the authors offer great detail on the subject at hand. I also enjoyed the many references to outside work. Authors of all technical books should follow WAO's lead, because 1) it gives credit where due and 2) it shows the authors are aware of outside influences and up-to-date.
WAO also does a nice job explaining how we arrived at the current state of broken Web technologies. Their history lesson of the browser wars in ch 2 set the stage for the chaos that follows. I'll finish my praises by mentioning the Web site the authors created as a companion to the book, complete with errata and code listings; it's a nice addition to the book.
If you're wondering why I rated WAO four instead of five stars, the reason involves the audience. I think too often the authors advance pretty far beyond the uninitiated reader. You have to admit that if obfuscation is your world, you're probably not going to read this book. However, if you're a newbie like me, you need the authors to spend more time explaining what they're doing and more importantly, WHY. Just what is the purpose of this technique or that attack? I think if the authors recruited some outside help to walk through the book, slow them down, and answer some basic questions, a second edition would be an easy five star work.
On the production side, a new edition should redraw figures 5.2 - 5.14. They look like they came straight from a PowerPoint pitch.
Overall, WAO is a great book to shatter any assumptions you may have about how Web clients and servers render content. Maybe the authors would care to describe how best one can operate in such a dangerous environment, i.e., is their an OpenBSD for Web technologies? All of the engines seem bad -- what's a user to do?

Click Here to see more reviews about: Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'


Web applications are used every day by millions of users, which is why they are one of the most popular vectors for attackers. Obfuscation of code has allowed hackers to take one attack and create hundreds-if not millions-of variants that can evade your security measures. Web Application Obfuscation takes a look at common Web infrastructure and security controls from an attacker's perspective, allowing the reader to understand the shortcomings of their security systems. Find out how an attacker would bypass different types of security controls, how these very security controls introduce new types of vulnerabilities, and how to avoid common pitfalls in order to strengthen your defenses.

Looks at security tools like IDS/IPS that are often the only defense in protecting sensitive data and assets
Evaluates Web application vulnerabilties from the attacker's perspective and explains how these very systems introduce new types of vulnerabilities
Teaches how to secure your data, including info on browser quirks, new attacks and syntax tricks to add to your defenses against XSS, SQL injection, and more


Buy Now

Click here for more information about Web Application Obfuscation: '-/WAFs..Evasion..Filters//alert(/Obfuscation/)-'

Read More...

Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions Review

Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions
Average Reviews:

(More customer reviews)
I'm still in the middle of the book, and I definitely will skim thru all the remaining pages (just because I paid for it), but I wouldn't recommend the book to anyone looking for serious and in-depth study on web security - the book just doesn't offer that. What it does is a list of possible attack vectors and sometimes offers "solutions" which can help to fight with the attacks. However, the attacks descriptions are shallow, solutions are very short and non-extensive and many of them go as far as telling a user to install NoScript extension for Firefox (huh? Web 2.0 doesn't work with no JavaScript).
There are also quadrillions of links to a security-related site (won't list it here) which offers a toolbar to checks your sites again the most common security problems. I don't have anything against links to useful tools of course, but THAT amount of links just makes this book look like an advertisement of the fore-mentioned site. Am not even talking about page space wasted to re-iterate "go to ...., install ...., click .... in order to test for ....." which usually take 0.5-1 pages. Users who read that sort of books can somehow figure out how to use a toolbar, I believe.
I'm not by any means a security expert, and this book did introduce me into the topic, but it didn't do anything beyond that. I still need to read some other book on the topic, and that book will probably contain the same info as the Hacking Web 2.0 Exposed (i.e. the very basic info on web expoits), so.. I actually just recommend to pass on this book at all, and look for something which covers the topic in greater depth.

Click Here to see more reviews about: Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions


Lock down next-generation Web services

"This book concisely identifies the types of attacks which are faced daily by Web 2.0 sites, and the authors give solid, practical advice on how to identify and mitigate these threats." --Max Kelly, CISSP, CIPP, CFCE, Senior Director of Security, Facebook

Protect your Web 2.0 architecture against the latest wave of cybercrime using expert tactics from Internet security professionals. Hacking Exposed Web 2.0 shows how hackers perform reconnaissance, choose their entry point, and attack Web 2.0-based services, and reveals detailed countermeasures and defense techniques. You'll learn how to avoid injection and buffer overflow attacks, fix browser and plug-in flaws, and secure AJAX, Flash, and XML-driven applications. Real-world case studies illustrate social networking site weaknesses, cross-site attack methods, migration vulnerabilities, and IE7 shortcomings.

Plug security holes in Web 2.0 implementations the proven Hacking Exposed way
Learn how hackers target and abuse vulnerable Web 2.0 applications, browsers, plug-ins, online databases, user inputs, and HTML forms
Prevent Web 2.0-based SQL, XPath, XQuery, LDAP, and command injection attacks
Circumvent XXE, directory traversal, and buffer overflow exploits
Learn XSS and Cross-Site Request Forgery methods attackers use to bypass browser security controls
Fix vulnerabilities in Outlook Express and Acrobat Reader add-ons
Use input validators and XML classes to reinforce ASP and .NET security
Eliminate unintentional exposures in ASP.NET AJAX (Atlas), Direct Web Remoting, Sajax, and GWT Web applications
Mitigate ActiveX security exposures using SiteLock, code signing, and secure controls
Find and fix Adobe Flash vulnerabilities and DNS rebinding attacks

Buy Now

Click here for more information about Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions

Read More...

Discovering SQL: A Hands-On Guide for Beginners (Wrox Programmer to Programmer) Review

Discovering SQL: A Hands-On Guide for Beginners (Wrox Programmer to Programmer)
Average Reviews:

(More customer reviews)
Without being cocky or pretentious, this book is too simple for my current skills and I know that. But I always check for new titles and authors. You will be surprised of how many new things you can learn from "intro" books. However, this book is too simple, even for a newbie. There are also 2 or 3 chapters that I would categorize as fillers and won't add useful T-SQL skills for a newbie, like the one for Performance and Normal forms (very important topics for being barely mentioned on a few pages)
1st, the positive
Nice style. The books reads like a novel. It honors its title so if you're new on the SQL arena, you will learn from this book without getting confused with lot of complex examples or SQL terminology. I also like the RDMS comparisons. I am learning Oracle and MySQL and it is really useful how the author compares similar commands among different engines; as a matter of fact, this is probably one of the things I like most of this book. It reminds me Itzik in some way who is a wonderful SQL writer and programmer but always try to be not code dependent.
The not so positive
I think that without being too complex, author could be a bit more technical. The examples are good but too simple. The Performance Tuning chapter is a joke! About 10 pages? Please ... and does not mention anything specific. For such a complex and important topic, I would remove the whole chapter altogether. Better not mentioning anything about Performance than just write about lot of generic concepts without really teaching something.
Overall, this is an ok book and a nice attempt, but it is too simple, even for the novice. For someone new into SQL arena, I would recommend "Microsoft® SQL Server® 2008 T-SQL Fundamentals" instead. But I really like Alex's writing style and how he tries to compare same command across several products. Wish I can give 3.5 starts, so I will round it to 3.

Click Here to see more reviews about: Discovering SQL: A Hands-On Guide for Beginners (Wrox Programmer to Programmer)

Teaching the SQL skills that businesses demand when hiring programmers
If you're a SQL beginner, you don't just want to learn SQL basics, you also want to get some practical SQL skills you can use in the job market. This book gives you both. Covering the basics through intermediate topics with clear explanations, hands-on exercises, and helpful solutions, this book is the perfect introduction to SQL. Topics include both the current SQL:2008 standards, the upcoming SQL:2011 standards, and also how to use SQL against current releases of the most popular commercial SQL databases, such as Oracle, SQL Server, and MySQL.
Introduces SQL concepts, explains SQL statements, and clearly shows how to write efficient and effective SQL code
Uses a hands-on style and a sample database that incorporates all SQL concepts taught in the book; this database will be enhanced through the book as key points and lessons are covered
Covers topics such as how SQL interacts with the sample database via various interfaces, including vendor-provided utilities, programming languages, SQL clients, and productivity software
Includes appendices with primers on database normalization, set theory and bollean algebra, RDBMS software step-by-step setup guides, and database connectivity

Learn how to write effective, efficient SQL code with Discovering SQL: A Hands-On Guide for Beginners.

Buy Now

Click here for more information about Discovering SQL: A Hands-On Guide for Beginners (Wrox Programmer to Programmer)

Read More...