The Web Application Hackers Handbook
Discovering and Exploiting Security Flaws
Chapter One
Web Application (In)security
There is no doubt that web application security is a current and very newsworthy
subject. For all concerned, the stakes are high: for businesses that
derive increasing revenue from Internet commerce, for users who trust web
applications with sensitive information, and for criminals who can make big
money by stealing payment details or compromising bank accounts. Reputation
plays a critical role: few people want to do business with an insecure web
site, and so few organizations want to disclose details about their own security
vulnerabilities or breaches. Hence, it is not trivial to obtain reliable information
about the state of web application security today.
This chapter takes a brief look at how web applications have evolved and the
many benefits they provide. We present some metrics about vulnerabilities in
current web applications, drawn from the authors' direct experience, demonstrating
... read full excerpt from The Web Application Hacker's Handbook: Discovering and Exploiting Security Flaws ebook