Monday 16 February 2015

OWASP Web App Testing Guide : E-Book

Hello Hack Defence Readers, Today i Have  Found a Very Useful E-Book For you Named OWASP Web App Penetration Testing  Guide. This Book is Latest Release by OWASP  Under RELEASE : “Release Quality” book content is the highest level of quality in a book title’s life cycle, and is a final product after alpha & Beta. This E-book Contain 224 Pages With OWASP 2014 Top Ten Vulnerability. 



[#] What is OWASP ?

The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. Our mission is to make application security “visible”, so that people and organizations can make informed decisions about application security risks and Every one is free to participate in OWASP and all of it's materials are available under a free and open software license. 

[#] Testing Guide Foreword - Table of contents : 


Frontispiece

About the OWASP Testing Guide Project

About The Open Web Application Security Project


Introduction :

  • The OWASP Testing Project.
  • Principles of Testing.
  • Testing Techniques Explained.
  • Deriving Security Test Requirements.
  • Security Tests Integrated in Development and Testing Workflows.
  • Security Test Data Analysis and Reporting.

The OWASP Testing Framework :


  • Phase 1: Before Development Begins.
  • Phase 2: During Definition and Design.
  • Phase 3: During Development.
  • Phase 4: During Deployment.
  • Phase 5: Maintenance and Operations SDLC Testing Workflow.

Web Application Security Testing :

  • Introduction and Objectives.
  • Configuration and Deployment Management Testing.
  • Identity Management Testing.
  • Authentication Testing.
  • Authorization Testing.
  • Session Management Testing.
  • Input Validation Testing.
  • Testing for Error Handling.
  • Testing for weak Cryptography.
  • Business Logic Testing.
  • Client Side Testing.

Appendix :

Appendix A: Testing Tools.

                  Black Box Testing Tools.
Appendix B: Suggested Reading.
                  Whitepapers 
                  Books
                  Useful Websites.
    Appendix C: Fuzz Vectors.
                      Fuzz Categories.
      Appendix D: Encoded Injection.
                        Input Encoding.
                        Output Encoding.



      Click Here to Download OWASP Web App Penetration Testing Guide v4.
             

      1 comment:

      1. This one is best guide book of OWASP web application. I learn many technical topic from this ebook. Web application developers must read this book because it will help you in your professional work.

        ReplyDelete