Commencez à lire Beginning ASP.NET Security sur votre Kindle dans moins d'une minute. Vous n'avez pas encore de Kindle ? Achetez-le ici Ou commencez à lire dès maintenant avec l'une de nos applications de lecture Kindle gratuites.

Envoyer sur votre Kindle ou un autre appareil

 
 
 

Essai gratuit

Découvrez gratuitement un extrait de ce titre

Envoyer sur votre Kindle ou un autre appareil

Désolé, cet article n'est pas disponible en
Image non disponible pour la
couleur :
Image non disponible
 

Beginning ASP.NET Security [Format Kindle]

Barry Dorrans
5.0 étoiles sur 5  Voir tous les commentaires (1 commentaire client)

Prix conseillé : EUR 36,71 De quoi s'agit-il ?
Prix éditeur - format imprimé : EUR 42,02
Prix Kindle : EUR 25,70 TTC & envoi gratuit via réseau sans fil par Amazon Whispernet
Économisez : EUR 16,32 (39%)

App de lecture Kindle gratuite Tout le monde peut lire les livres Kindle, même sans un appareil Kindle, grâce à l'appli Kindle GRATUITE pour les smartphones, les tablettes et les ordinateurs.

Pour obtenir l'appli gratuite, saisissez votre adresse e-mail ou numéro de téléphone mobile.

Formats

Prix Amazon Neuf à partir de Occasion à partir de
Format Kindle EUR 25,70  
Broché EUR 42,26  





Descriptions du produit

Présentation de l'éditeur

Programmers: protect and defend your Web apps againstattack!

You may know ASP.NET, but if you don't understand how to secureyour applications, you need this book. This vital guide exploresthe often-overlooked topic of teaching programmers how to designASP.NET Web applications so as to prevent online thefts andsecurity breaches.

You'll start with a thorough look at ASP.NET 3.5 basics and seehappens when you don't implement security, including someamazing examples. The book then delves into the development of aWeb application, walking you through the vulnerable points at everyphase. Learn to factor security in from the ground up, discover awealth of tips and industry best practices, and explore codelibraries and more resources provided by Microsoft and others.

  • Shows you step by step how to implement the very latestsecurity techniques
  • Reveals the secrets of secret-keeping—encryption,hashing, and not leaking information to begin with
  • Delves into authentication, authorizing, and securingsessions
  • Explains how to secure Web servers and Web services, includingWCF and ASMX
  • Walks you through threat modeling, so you can anticipateproblems
  • Offers best practices, techniques, and industry trends you canput to use right away

Defend and secure your ASP.NET 3.5 framework Web sites with thismust-have guide.

Quatrième de couverture

A practical guide to securing ASP.NET sites

Beginning ASP.NET Security is for novice to intermediate ASP.NET programmers and provides a step–by–step solution to securing each area of ASP.NET development. Rather than approaching security from a theoretical direction, MVP Barry Dorrans shows you examples of how everyday code can be attacked, and describes the steps necessary for defense. Inside, you ll learn how you can defend your ASP.NET applications using the .NET framework, industry patterns and best practices, code libraries and resources provided by Microsoft and others.

Beginning ASP.NET Security:

  • Explores issues with user input including validation, cross–site scripting (XSS) and cross–site request forgery (CSRF)

  • Teaches how to securely access your database and defend against SQL injection attacks

  • Shares techniques for keeping secrets, including encryption, hashing and preventing information leaks

  • Examines methods for authenticating and authorizing users, including ASP.NET membership providers and preventing cookie theft

  • Shares tips for securing your web server, including how ASP.NET uses trust levels and locking down IIS

  • Unveils ways to securely use WCF web services

  • Presents security with the Microsoft ASP.NET Ajax framework and Silverlight

  • Includes an overview of security with the Microsoft MVC framework

Wrox Beginning guides are crafted to make learning programming languages and technologies easier than you think, providing a structured, tutorial format that will guide you through all the techniques involved.

Programmer Forums
Join our Programmer to Programmer forums to ask and answer programming questions about this book, join discussions on the hottest topics in the industry, and connect with fellow programmers from around the world.

Code Downloads
Take advantage of free code samples from this book, as well as code samples from hundreds of other books, all ready to use.

Read More
Find articles, ebooks, sample chapters and tables of contents for hundreds of books, and more reference resources on programming topics that matter to you.

wrox.com


Détails sur le produit

  • Format : Format Kindle
  • Taille du fichier : 3445 KB
  • Nombre de pages de l'édition imprimée : 436 pages
  • Editeur : Wrox; Édition : 1 (20 avril 2010)
  • Vendu par : Amazon Media EU S.à r.l.
  • Langue : Anglais
  • ASIN: B003JTHYX0
  • Synthèse vocale : Activée
  • X-Ray :
  • Word Wise: Non activé
  • Moyenne des commentaires client : 5.0 étoiles sur 5  Voir tous les commentaires (1 commentaire client)
  • Classement des meilleures ventes d'Amazon: n°587.464 dans la Boutique Kindle (Voir le Top 100 dans la Boutique Kindle)
  •  Souhaitez-vous faire modifier les images ?


En savoir plus sur l'auteur

Découvrez des livres, informez-vous sur les écrivains, lisez des blogs d'auteurs et bien plus encore.

Commentaires en ligne

4 étoiles
0
3 étoiles
0
2 étoiles
0
1 étoiles
0
5.0 étoiles sur 5
5.0 étoiles sur 5
Commentaires client les plus utiles
5.0 étoiles sur 5 Livre très utile 11 décembre 2012
Par Armand47
Format:Broché|Achat vérifié
Ce livre présente en détails les api qui permettent de protéger les sites asp.net contre les actions malveillantes les plus connues.
L'auteur explique clairement les bases pour assurer la sécurisation des formulaires, des sessions, de la base de données, de l'authentification, de WCF, etc....
J'ai trouvé le livre très utile.
Avez-vous trouvé ce commentaire utile ?
Commentaires client les plus utiles sur Amazon.com (beta)
Amazon.com: 4.9 étoiles sur 5  7 commentaires
6 internautes sur 7 ont trouvé ce commentaire utile 
5.0 étoiles sur 5 Excellent all round view of ASP.net security 2 mars 2010
Par A. Mackey - Publié sur Amazon.com
Format:Broché
Beginning ASP.net security begins by introducing the reader to security principals such as defence in depth, never trusting user input etc. The author then ensures the reader understands how the web and ASP.net function by providing an overview of HTTP & ASP.net processing of events, form submissions and Viewstate- all essential concepts to understand the security issues surrounding ASP.net applications.

The book is divided into 16 easy to read chapters. Chapters contain small snippets of code and demonstrate various security issues ensuring the reader understands the problem being discussed. Detailed advice is then given and solutions provided to fix the various issues.

Issues are supplemented with real world examples and the author's own experience (I chuckled at the index server example) and help provide some colour to what can be a difficult topic to keep interesting.

The book covers all major web based security issues such as XSS, XSRF, Sql Injection and also related topics such as securing IIS and issues surrounding the file system. Important concepts such as encryption, hashing and certificates are also covered in depth. The final chapters cover advanced topics such as CAS, Securing IIS and third party authentication solutions.

So what could be better? very little the book is clear, easy to read and contains concise examples. I would have perhaps liked to see an example of implementing a custom membership provider and a bit more on client side scripting/ajax related issues but the book does a great job covering the major areas and pointing the reader towards further resources.

I liked that the book provides recipes for dealing with complex problems such as implementing certificate based authentication and implementing Open ID. Several useful tools I wasn't aware of are also referenced.

Before I began reading Barry's book although no security expert I considered that I had a pretty good knowledge of security and was glad to see for the most part the book confirmed my understanding! It always surprises me how many web developers have so little knowledge of basic security concepts and best practice. There is no excuse now and if you have never looked into security this book should be required reading! However don't think that this book has nothing to offer the intermediate/advanced developer as it had many gem's for me (correct implementation of salting passwords, certificates, ViewStateUserKey, WCF security).

This book is a great introduction to security and related concepts and will serve as a useful reference/cook book to more experienced developers.
5 internautes sur 6 ont trouvé ce commentaire utile 
5.0 étoiles sur 5 Excellent coverage of Security for ASP.NET 11 juillet 2010
Par Baskin I. Tapkan - Publié sur Amazon.com
Format:Broché
Title of Barry Dorrans' book "Beginning ASP.NET Security" is not quite inline with the contents of the book I would think. I would at least make the title 'Intermediate'. Because you may see some eyes roll, when you see "Beginner's..." in the title. However given that securing applications is a journey, rather than the destination, maybe he has a valid point.

Mr. Dorrans does a very thorough job covering many and various aspects of web security. First chapter opens up with a defaced web site and a list "do's", such as never trusting input, failing gracefully (not giving any useful information such as stacktrace), watching and logging actions, and using the least privilege principles while running the applications. Lot of times, I hear "we use SSL, we are secure". Such naive developer should really consider reading this book.

Chapter 2 explains how the web works, and this is totally beginner's chapter, but still a great refresher. Introduces Fiddler2, Tracing in asp.net, the ASP.NET pipeline and web forms. Chapter 3 is about user input. I have read the book "Writing Secure Code" and very glad to see Mr. Dorrans's referencing of this book in the second paragraph. Goes on to introduce cross-site scripting attack and protection of cookies, the out-of-the box Validation controls which classic ASP.NET offers.

Chapter 4 extends the user input validation in forms of query strings, form fields, events and such, and the main take away is the CSRF (Cross-site request forgery) attack. Enjoyed reading the section of writing an HTTP module to protect against CSRF attacks which is a few pages long. Chapter 5 dives into ViewState, validating it, encrypting it. Error handling and logging, exception handling, and WMIare precious gems to take away from this chapter as well.

Chapter 6 is about hashing and encryption. Then goes in depth with salting, storing passwords, types of encyrption which are very inline with the next chapter, about user names and passwords. The authentication and authorization are discussed. Chapter 8 is securing database access, and the well-known SQL-injection attack followed by another chapter on filesystem security. The fileupload control for asp.net is introduced.

Chapter 10 is about XML security, validating, parsing, querying and xpath injection. Really enjoyed the short to the point code snippets in this chapter. Another take away is signing and encrypting an XML document using X509 certificate.

Part III (the remaining chapters) are getting further closer to the metal and relatively new technologies (.NET 3.0 and up). WCF, RIA (Ajax) and CAS are discussed in detail in chapter 11, 12, and 13. I would think in the next release CAS is going to be revised for .NET 4. Chapter 14 is about IIS security, logging etc. Chapter 15, 3rd party authentication was quite welcome these days, really enjoyed the Open-ID introduction and examples around it. The final chapter is about security in the ASP.NET MVC framework, securing controller actions, anti-forgery token for XSS, and using filters to custom authorization which I am actively using in current project.

Really enjoyed reading this book. Covers many aspects of security in various technologies,areas offered by ASP.NET. Highly recommend any developer who is actively developing web pages utilizing the .NET stack.
3 internautes sur 4 ont trouvé ce commentaire utile 
4.0 étoiles sur 5 Excellent beginners guide to ASP.NET security 6 mai 2010
Par Michael Jolley - Publié sur Amazon.com
Format:Broché
I was very pleased with the topics covered in this book. Barry Dorrans delivered a very non-interesting subject in a manner that kept your attention throughout. I wish more entry-level developers would read this before getting started. They would certainly have a better understanding of ASP.NET security and how to implement better coding practices up front.
5.0 étoiles sur 5 Get up to speed quickly on ASP.NET security 6 mai 2011
Par T. Anderson - Publié sur Amazon.com
Format:Broché|Achat vérifié
This is a great book for getting up to speed quickly on security tools available in ASP.NET.

Although the book says it is for beginners, it definitely goes beyond the beginner level.

The book starts out explaining why security matters. It then is broken down into 3 parts, PART I- The Asp.Net Security Basics, PART II Securing Common Asp.Net Tasks, and PART III Advanced Asp.Net Scenarios.

There are full chapters on the following topics Safely Accepting User Input, Hashing and Encryption, Usernames and Passwords, Securely Accessing Databases, Using the File System, Securing XML, WCF Services, Securing Rich Internet Applications, Code Access Security, IIS, and the ASP.NET MVC Framework.

The authors have a writing style that makes the book easy to read from cover to cover, but it also makes a great reference.

The downloadable code is very well organized and easy to use.

If you want to get up to speed quickly on ASP.NET security, this is the book you want.
1 internautes sur 2 ont trouvé ce commentaire utile 
5.0 étoiles sur 5 Great security overview 25 juillet 2012
Par JM555 - Publié sur Amazon.com
Format:Broché|Achat vérifié
This is a great book about various ASP.NET security topics. I agree with the other reviewers that this isn't strictly a "beginners" book, and actually has a lot of very useful info - the "accepting user input", "encryption" and "database" chapters were especially useful. It's a good balance of information - not so detailed that you'll fall asleep reading it, and not so basic that it's useless in a real world situation.

My only suggestion is that it might be helpful to expand the hashing/encryption chapter a bit more - maybe even break break them into several chapters with more examples. Highly recommended for any ASP.NET developer!
Ces commentaires ont-ils été utiles ?   Dites-le-nous
Rechercher des commentaires
Rechercher uniquement parmi les commentaires portant sur ce produit

Discussions entre clients

Le forum concernant ce produit
Discussion Réponses Message le plus récent
Pas de discussions pour l'instant

Posez des questions, partagez votre opinion, gagnez en compréhension
Démarrer une nouvelle discussion
Thème:
Première publication:
Aller s'identifier
 

Rechercher parmi les discussions des clients
Rechercher dans toutes les discussions Amazon
   


Rechercher des articles similaires par rubrique