Potrai iniziare a leggere 24 Deadly Sins of Software Security sul tuo Kindle tra meno di un minuto. Non possiedi un Kindle? Scopri Kindle.

Invia a Kindle o a un altro dispositivo

 
 
 

Prova gratis

Leggi gratuitamente l'inizio di questo eBook

Invia a Kindle o a un altro dispositivo

Leggi gli eBook sul computer o altri dispositivi portatili con le Applicazioni di lettura Kindle gratuite.
24 Deadly Sins of Software Security : Programming Flaws and How to Fix Them
 
Visualizza l'immagine in formato grande
 

24 Deadly Sins of Software Security : Programming Flaws and How to Fix Them [Formato Kindle]

David LeBlanc

Prezzo Copertina Ed. Cartacea: EUR 43,67
Prezzo Kindle: EUR 23,20 include IVA (dove applicabile) e il download wireless gratuito con Amazon Whispernet
Risparmi: EUR 20,47 (47%)

Formati

Prezzo Amazon Nuovo a partire da Usato da
Formato Kindle EUR 23,20  
Brossura EUR 30,93  
Scopri come risparmiare fino all'80% su un titolo diverso ogni giorno
Iscriviti alla Newsletter dell'offerta lampo Kindle per ricevere direttamente nella tua casella di posta elettronica l'e-mail con l'offerta del giorno e non perdere nemmeno un titolo in promozione. Scopri di più

Descrizione prodotto

Sinossi

"What makes this book so important is that it reflects the experiences of two of the industry's most experienced hands at getting real-world engineers to understand just what they're being asked for when they're asked to write secure code. The book reflects Michael Howard's and David LeBlanc's experience in the trenches working with developers years after code was long since shipped, informing them of problems." --From the Foreword by Dan Kaminsky, Director of Penetration Testing, IOActive Eradicate the Most Notorious Insecure Designs and Coding Vulnerabilities Fully updated to cover the latest security issues,  24 Deadly Sins of Software Security reveals the most common design and coding errors and explains how to fix each one-or better yet, avoid them from the start. Michael Howard and David LeBlanc, who teach Microsoft employees and the world how to secure code, have partnered again with John Viega, who uncovered the original 19 deadly programming sins. They have completely revised the book to address the most recent vulnerabilities and have added five brand-new sins. This practical guide covers all platforms, languages, and types of applications. Eliminate these security flaws from your code: SQL injection Web server- and client-related vulnerabilities Use of magic URLs, predictable cookies, and hidden form fields Buffer overruns Format string problems Integer overflows C++ catastrophes Insecure exception handling Command injection Failure to handle errors Information leakage Race conditions Poor usability Not updating easily Executing code with too much privilege Failure to protect stored data Insecure mobile code Use of weak password-based systems Weak random numbers Using cryptography incorrectly Failing to protect network traffic Improper use of PKI Trusting network name resolution.

Dettagli prodotto

  • Formato: Formato Kindle
  • Dimensioni file: 1672 KB
  • Lunghezza stampa: 432
  • Utilizzo simultaneo di dispositivi: Fino a dispositivi, per limite di editore
  • Editore: McGraw-Hill; 1 edizione (3 settembre 2009)
  • Venduto da: Amazon Media EU S.à r.l.
  • Lingua: Inglese
  • ASIN: B002R0JXEU
  • Da testo a voce: Abilitato
  • X-Ray: Non abilitato
  • Posizione nella classifica Bestseller di Amazon: #95.372 a pagamento nel Kindle Store (Visualizza i Top 100 a pagamento nella categoria Kindle Store)

Recensioni clienti

Non ci sono ancora recensioni di clienti su Amazon.it
5 stelle
4 stelle
3 stelle
2 stelle
1 stella
Le recensioni clienti più utili su Amazon.com (beta)
Amazon.com: 4.3 su 5 stelle  6 recensioni
6 di 7 persone hanno trovato utile la seguente recensione
4.0 su 5 stelle 24 Deadly Sins of Software Security 9 agosto 2010
Di Mike - Pubblicato su Amazon.com
Formato:Brossura|Acquisto verificato Amazon
24 Deadly Sins carries on in the great tradition of the original 19 Deadly Sins but has expanded to cover problems that have developed since then as well as added coverage for more programing languages. It serves as a great introduction to the most common problems in software development that lead to security issues without getting bogged down in the weeds on any of them. It does not go into a great deal of detail so if that is what you are looking for this isn't the book you want but it does do what it sets out to do.

The organization of the book lends itself to a straight read through and as a jump around reference to cover the problems you need to look at when you need to look at them. Most chapters stand alone quite well and most references to other chapters are about closely related sins. It describes the basics of the problem, goes into more detail and helps you try to spot the problem in various languages. It covers some of the ways you can avoid the problems and provides additional remediation if available.

The book lends itself to being a decent text book on software security problems and its basic structure is not a bad approach to an introduction to the topic. I've been teaching an introduction to secure development class for a couple of years that was mostly based on the original book and I'm finishing updating that to the new 24 Deadly Sins breakdown.
1 di 1 persone hanno trovato utile la seguente recensione
5.0 su 5 stelle Excellent book!!! 24 dicembre 2012
Di Jose A. Villegas - Pubblicato su Amazon.com
Formato:Brossura|Acquisto verificato Amazon
The authors definitely know about software vulnerabilities due mostly in part by mistakes made during software development and coding processes. Their recommendations are very effective and I am very satisfied with my purchase.
1 di 1 persone hanno trovato utile la seguente recensione
5.0 su 5 stelle Great Summarization 6 dicembre 2011
Di W. Conklin - Pubblicato su Amazon.com
Formato:Brossura|Acquisto verificato Amazon
This book is the update to the 19 Deadly Sins, and does a tremendous job summarizing the information needed to understand the types of errors prevalent in software today. This is not a book with all the details behind the causes, fixes, etc. For those details, I would refer my students (and do) to Michael's other great book "Writing Secure Code, Second Edition". And for process related material, "The Security Development Lifecycle".

Howard is the real deal, a straight shooter and known for telling it like it is. This book is no different - no fluff, no extraneous material, just the stuff every project manager of a software development effort should know, so they know what to ask of their team.

I più evidenziati

 (Cos'è?)
&quote;
Languages such as Java, C#, and Visual Basic have native string types, provide bounds-checked arrays, and generally prohibit direct memory access. &quote;
Evidenziato da 3 utenti Kindle
&quote;
admins dont want to change settings to be more secure, and normal users have no idea how to change settings. &quote;
Evidenziato da 3 utenti Kindle

Discussioni clienti

Forum su questo prodotto
Discussione Risposte Ultimo post
Nessuna discussione

Poni domande, condividi opinioni, raccogli informazioni
Inizia una nuova discussione
Argomento:
Primo post:
Dovrai effettuare l'accesso
 

   


Ricerca articoli simili per categoria