EH-Net

Ethical Hacking Discussions and Related Certifications => Web Applications => Topic started by: acastanheira2001 on February 06, 2009, 04:54:56 AM



Title: web app security realm books
Post by: acastanheira2001 on February 06, 2009, 04:54:56 AM
Hi,

I need to test the web applications we develop. So I started using BurpSuite, it seems fine to me. But I don´t know what tests to make and neither how to do them.

I´m searching for this information on the net, or in some books.

What books do you recommend in the following site http://portswigger.net/books/ ?

Thanks,
André


Title: Re: web app security realm books
Post by: BillV on February 06, 2009, 07:30:57 AM
Why don't you have a look at the OWASP project and their Testing Guide?

OWASP Site (http://www.owasp.org)

Testing Guide (http://www.owasp.org/index.php/Category:OWASP_Testing_Project)

BillV


Title: Re: web app security realm books
Post by: BillV on February 06, 2009, 07:35:00 AM
Also, there's a thread here (http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,3311.msg15331/#msg15331) with some books mentioned in it.


Title: Re: web app security realm books
Post by: sethmisenar on February 06, 2009, 10:09:34 PM
Since you specifically mention Burp and portswigger, I think that I would go with Web Application Hackers Handbook.  Dafydd Stuttard (a.k.a. portswigger) is one of the coauthors of the book.  Extremely well written.

Seth


Title: Re: web app security realm books
Post by: jason on February 07, 2009, 09:56:47 PM
Another vote for Web Application Hackers Handbook.