0

Call Boomerang Books 1300 36 33 32

We are open! For operations and delivery updates due to COVID-19. (click here)

Description - Real-world Bug Hunting by Peter Yaworski

Real-World Web Hacking is a field guide to finding software bugs. Ethical hacker Peter Yaworski breaks down common types of bugs, then contextualizes them with real bug bounty reports released by hackers on companies like Twitter, Facebook, Google, Uber, and Starbucks. As you read each report, you'll gain deeper insight into how the vulnerabilities work and how you might find similar ones.

Each chapter begins with an explanation of a vulnerability type, then moves into a series of real bug bounty reports that show how the bugs were found. You'll learn things like how Cross-Site Request Forgery tricks users into unknowingly submitting information to websites they are logged into; how to pass along unsafe JavaScript to execute Cross-Site Scripting; how to access another user's data via Insecure Direct Object References; how to trick websites into disclosing information with Server Side Request Forgeries; and how bugs in application logic can lead to pretty serious vulnerabilities. Yaworski also shares advice on how to write effective vulnerability reports and develop relationships with bug bounty programs, as well as recommends hacking tools that can make the job a little easier.

Buy Real-world Bug Hunting by Peter Yaworski from Australia's Online Independent Bookstore, Boomerang Books.

Book Details

ISBN: 9781593278618
ISBN-10: 1593278616
Format: Paperback / softback
(234mm x 177mm x mm)
Pages: 300
Imprint: No Starch Press,US
Publisher: No Starch Press,US
Publish Date: 9-Jul-2019
Country of Publication: United States

Book Reviews - Real-world Bug Hunting by Peter Yaworski

» Have you read this book? We'd like to know what you think about it - write a review about Real-world Bug Hunting book by Peter Yaworski and you'll earn 50c in Boomerang Bucks loyalty dollars (you must be a Boomerang Books Account Holder - it's free to sign up and there are great benefits!)


Author Biography - Peter Yaworski

Peter Yaworski is a self-taught developer and ethical hacker who began building websites exclusively with Drupal. Since then, he has expanded his interest to Rails, Android app development, and software security, while producing over 100 video tutorials and interviews on YouTube covering ethical hacking, web development, and Android to help teach others what he's learned. Peter continues to be an active bug bounty participant with thanks from Shopify, HackerOne, Salesforce, Twitter, Starbucks and the US Department of Defense among others.

A Preview for this title is currently not available.