
Hands-on Penetration Testing for Web Applications - 2nd Edition
Richa Gupta
SKU: 9789365897036
FREE PREVIEW
ISBN: 9789365897036
eISBN: 9789365899078
Authors: Richa Gupta
Rights: Worldwide
Edition: 2025
Pages: 334
Dimension: 7.5*9.25 Inches
Book Type: Paperback
Hands-on Penetration Testing for Web Applications offers readers with the knowledge and skillset to identify, exploit, and control the security vulnerabilities present in commercial web applications, including online banking, mobile payments, and e-commerce applications.
Covering a diverse array of topics, this book provides a comprehensive overview of web application security testing methodologies. Each chapter offers key insights and practical applications that align with the objectives of the course. Students will explore critical areas such as vulnerability identification, penetration testing techniques, using open-source pen test management and reporting tools, testing applications hosted on cloud, and automated security testing tools. Throughout the book, readers will encounter essential concepts and tools such as OWASP Top 10 vulnerabilities, SQL injection, cross-site scripting (XSS), authentication and authorization testing, and secure configuration practices. With a focus on real-world applications, students will develop critical thinking skills, problem-solving abilities, and a security-first mindset required to address the challenges of modern web application threats.
With a deep understanding of security vulnerabilities and testing solutions, students will have the confidence to explore new opportunities, drive innovation, and make informed decisions in the rapidly evolving field of cybersecurity.
KEY FEATURES
● Exciting coverage on vulnerabilities and security loopholes in modern web applications.
● Practical exercises and case scenarios on performing pen testing and identifying security breaches.
● This new edition brings enhanced cloud security coverage and comprehensive penetration test management using AttackForge for streamlined vulnerability, documentation, and remediation.
WHAT YOU WILL LEARN
● Navigate the complexities of web application security testing.
● An overview of the modern application vulnerabilities, detection techniques, tools, and web penetration testing methodology framework.
● Contribute meaningfully to safeguarding digital systems.
● Address the challenges of modern web application threats.
● This edition includes testing modern web applications with emerging trends like DevSecOps, API security, and cloud hosting.
● This edition brings DevSecOps implementation using automated security approaches for continuous vulnerability remediation.
WHO THIS BOOK IS FOR
The target audience for this book includes students, security enthusiasts, penetration testers, and web application developers. Individuals who are new to security testing will be able to build an understanding about testing concepts and find this book useful. People will be able to gain expert knowledge on pentesting tools and concepts.
1. Introduction to Security Threats
2. Web Application Security Essentials
3. Web Pentesting Methodology
4. Testing Authentication Failures
5. Testing Secure Session Management
6. Testing Broken Access Control
7. Testing Sensitive Data Exposure
8. Testing Secure Data Validation
9. Techniques to Attack Application Users
10. Testing Security Misconfigurations
11. Automating Security Attacks
12. Penetration Testing Tools
13. Pen Test Management and Reporting
14. Defense In Depth
15. Security Testing in Cloud
Richa Gupta is working as a Senior Cyber Engineer at IKEA IT AB, where she is responsible for enhancing cybersecurity posture for the product looking at various aspects like cloud security, incident response, data security. She has 10 years of experience spans across various domains including infrastructure security, threat modeling, web application testing, mobile app security. She has done attack-based security assessment and penetration testing. She has worked extensively with large-scale web application deployments in retail services industry, holding industry-leading certifications such as Certified Ethical Hacker (CEH) and Professional Cloud Security Engineer.
You may also like
Recently viewed
