LTN Law Technology News
  • Home
  • News
  • Reviews
  • Commentary
  • Surveys
  • Events
  • LegalTech® Directory
  • About LTN
  • Register
  • Topics:
  • E-Discovery & Compliance
  • Litigation Support
  • Practice Management
  • Office Tech
  • Mobile Lawyer
  • Research & Libraries
  • Tech Law

Home > Book Review: 'Hacking Web Apps'

Font Size: increase font decrease font

Book Review: 'Hacking Web Apps'

By Albert Barsocchini All Articles 

Law Technology News

December 11, 2012

  •    
  •    
  •    
  •      
 
Book cover of Hacking Web Apps

Image: Syngress

Hacking has quickly turned into a mature market and it has never been easier to initiate a hack with devastating consequences. This is reflected by the number of books and articles coming out every day on computer and network security. Every time you access a website that allows you to accomplish specific taskshack — from online banking to shopping — you risk being attacked and all your personal information hijacked.

Syngress just released Hacking Web Apps that focuses on eight groups of security weaknesses and vulnerabilities most commonly exploited by hackers and more importantly, it explains how to guard against such attacks. Author Mike Schema, a web application security developer at Qualys Inc., presents in each chapter examples of different hacks against web applications and appropriate countermeasures. Schema identifies vulnerabilities in the new HTML5 standard, cross-site scripting (XSS) and covers SQL injection attacks as well as data store manipulation.

 

Anyone who uses the web to check email, shop, or work can benefit from knowing how sensitive information may be compromised or how sites harbor malicious content. This book does a good job of balancing the technical nature of hacking with the basic principles behind them.

For example attorneys are constantly using databases to research and store sensitive information for their practice. So called SQL injection is a common attack vector for hacking databases: injecting malicious code into the programming strings used to define and describe every way that a user may manipulate data in a database.

Countermeasures are surprisingly simple to enact for a database manager, such as staying current with patches; authenticating the user with SSL; validating all user supplied data by matching user data against expected data, e.g., the type, length, format, and range of data expected; and normalizing the data to a baseline character set and rejecting incomplete or unexpected data instead of trying to clean it up. Both the simplicity of the attack and the countermeasures have made this type of attack the "play ground" for the hacking community.

As applications become more dependent on the browser for computing, hackers will become equally focused on browser attacks as they are on website attacks.

After doing a quick read, I came away with a new found appreciation for how easy it is for the bad guy to make our life miserable in the digital age.

:::BIBLIOGRAPHIC DATA:::

Schema, Mike. Hacking Web Apps: Detecting and Preventing Web Application Security ProblemsSyngress, September 12, 2012. Paperback, 296 pp. ISBN No. 978-1-59749-951-4.



Subscribe to Law Technology News

You must be signed in to comment on an article

Find similar content

Companies, agencies mentioned

    
  • HTML5
  • Qualys

Key categories

    
  • Information Security

Most viewed stories

    
  1. Big Law Whipped for Poor Tech Training
    •      
  2. 10 Devices You Should Never Take Along on a Business Trip
    •      
  3. Is Stanford Law the New Vortex of Legal Technology?
    •      
  4. Using Computer Forensics to Investigate IP Theft
    •      
  5. How the Predictive Coding Process Will Affect Paralegals
    •      
  6. Collaboration Is Key to Defending Cyberattacks
    •      
  7. ILTA Study to Gauge New Technologies' Impact on Law Practice
    •      
  8. Enron Sandbox Stirs Up Private Data, Again
    •      
  9. CEIC: the Destination for Digital Investigation
    •      
  10. Cisco E-Book Delivers Ethics on the Go
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

Hiring Interns? Be Sure to Do It Right

ACC Weighs in on Arizona's In-House Pro Bono Rules

Ex-Dewey Partners Face New Foe in Firm's Bankruptcy

S&C Adds Linklaters Restructuring Partner in London
  •      
    • Subscription Required

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Enron Sandbox Stirs Up Private Data, Again

LegalTech West Coast Wraps Up With Ethics, VC News

In Tricky Prosecutions, Judges Play Peacemakers

Ropers Majeski Tries to Re-Invent Itself
  •      
    • Subscription Required

Fla. Attorneys Lead Force-Placed Insurance Fight

Lawsuit Names Missing Fla. Attorney for Alleged Fraud
  •      
    • Subscription Required

Summer Programs Still in a Drought

Lawyer Not Covered for Alleged Malpractice at Prior Firm
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Firm Takes Another Hit in Bid for 'Unconscionable' Fees

New York's Martin Act Faces Test in Challenge to 2005 Case

Castille Testifies in Favor of 'Civil Gideon' Funding

Workers' Comp Judges Can't Fight Rescinded Raise
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Advising Clients on Weather and the Workplace
  •      
    • Subscription Required

Texas Sues BP, Others Over Deepwater Oil Spill Disaster
  •      
    • Subscription Required

'Follow That Escapee!'

Judge Who Tossed Defense Counsel Accused of 'Partiality'
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • About LTN   |
  • Contact LTN   |
  • Advertise with Us   |
  • Sitemap
  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media