Opening book details…
Can I read Web Application Advanced Hacking on EtoBox?
Web Application Advanced Hacking by Maor Tal is a nonfiction available to read on EtoBox.
What is Web Application Advanced Hacking about?
Table of Contents 5 Legal Disclaimer 8 About the Author 9 Acknowledgement 10 Preface 11 Who is this book for? 12 A word of favor and caution 12 What to expect from this book 13 Feedback and book updates 15 Chapter 1: Deserialization Attacks 16 Insecure deserialization 18 PHP Object Injection 19 Python pickle serialization 26 Chapter 2: Type Juggling Attacks 30 Type juggling example explained 30 Special cases with type juggling 32 “Zero-like” type juggling 32 Chapter 3: NoSQL Databases 34 NoSQL injection fundamentals 34 MongoDB NoSQL injection explained 34 Testing MongoDB NoSQL injections 35 Attacking CouchDB interfaces 37 Remote privilege escalation vulnerability (CVE-2017-12635) 40 Arbitrary Command Execution (CVE-2017-12636) 42 Chapter 4: API Hacking GraphQL 45 GraphQL crash course 45 Detect GraphQL endpoints 47 Enumerate GraphQL schema 48 SQL injection via GraphQL query 50 Chapter 5: Misconfigured Cloud Storage 52 Enumerate public cloud-storage instances 52 Misconfigured S3 buckets 53 Google Studio insufficient permissions 54 Automate hunting for cloud storage 55 Chapter 6: Server-Side Request Forgery 56 SSRF Exploitation with SSRFmap 56 Cloud-based SSRF 57 SSRF Out-of-Band with
Who reads Web Application Advanced Hacking?
It is typically read by self-directed learners exploring a subject in depth.
Common subject areas: history, science, philosophy, social sciences.
- Author
- Maor Tal
- Published
- 2020
- Language
- EN
- Category
- nonfiction
More by Maor Tal
Similar books
- Hacking APIs : Breaking Web Application Programming Interfaces — Corey J. Ball (2022)
- Web Hacking 101 — Peter Yaworski
- Hacklog Volume 2 Web Hacking: Handbook on IT Security and Ethical Hacking — Marco Silvestri Stefano Novelli (2018)
- Hacking Web Apps: Detecting and Preventing Web Application Security Problems — Mike Shema (2012)
- Web Application Hacking Advanced SQL Injection and Data Store Attacks — Thomas Sermpinis (2020)
- Programming Web Services with XML-RPC : Creating Web Application Gateways — Simon St. Laurent; Joe Johnston; Edd Dumbill; Dave Winer (2001)