
APPLICATION SECURITY BOOK EXCERPTS
Exploiting Software: How to Break Code -- Chapter 7, Buffer Overflow
Greg Hoglund and Gary McGraw 01.11.2006
Rating: -4.50- (out of 5)




As a registered member of SearchAppSecurity.com, you're entitled to a complimentary copy of Chapter 7 of Exploiting Software: How to Break Code written by Greg Hoglund and Gary McGraw and published by Addison-Wesley Professional.
This chapter, "Buffer Overflow," discusses what buffer overflow attacks are, how to combat them and why they remain the crown jewel of attacks, and are likely to remain so for years to come.
Book description:
How does software break? How do attackers make software break on purpose? Why are firewalls, intrusion detection systems and antivirus software not keeping out the bad guys? What tools can be used to break software? This book provides the answers.
Exploiting Software is loaded with examples of real attacks, attack patterns, tools, and techniques used by bad guys to break software. If you want to protect your software from attack, you must first learn how real attacks are really carried out.
This must-have book may shock you -- and it will certainly educate you. Getting beyond the script kiddie treatment found in many hacking books, you will learn about
- Why software exploit will continue to be a serious problem
- When network security mechanisms do not work
- Attack patterns
- Reverse engineering
- Classic attacks against server software
- Surprising attacks against client software
- Techniques for crafting malicious input
- The technical details of buffer overflows
- Rootkits
Exploiting Software is filled with the tools, concepts, and knowledge necessary to break software.
>> Read "Chapter 7: Buffer Overflow" now.
>> Buy the book
 |

|
Rate this Tip
|
To rate tips, you must be a member of SearchSoftwareQuality.com. Register now
to start rating these tips. Log in if you are already a member.
|


');
// -->
 |
 |
|  |
RELATED CONTENT
 |
Application Security Book Excerpts |
 |
Fuzzing for Software Security Testing and Quality Assurance: Chapter 3, Testing for Quality
|
 |
Software Security Engineering: A Guide for Project Managers -- Chapter 3, Requirements Engineering for Secure Software
|
 |
InfoSecurity 2008 Threat Analysis, Chapter 4: XSS Theory
|
 |
Google Hacking for Penetration Testers, Volume 2: Chapter 6, Locating Exploits and Finding Targets
|
 |
Ajax Security -- Chapter 6, Transparency in Ajax Applications
|
 |
Fuzzing: Brute Force Vulnerability Discovery -- Chapter 12, Fuzzing Frameworks
|
 |
Cross Site Scripting Attacks: XSS Exploits and Defense -- Chapter 5, Advanced XSS Attack Vectors
|
 |
Static Analysis as Part of the Code Review Process -- Chapter 3, Secure Programming with Static Analysis
|
 |
Security Metrics: Replacing Fear, Uncertainty, and Doubt -- Chapter 3, Application Security Metrics
|
 |
Forms Authentication -- Chapter 5, Professional ASP.NET 2.0 Security, Membership, and Role Management
|
|
DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.
|
 |
|
|
 |
|
 |