Review of Web Application Security Books Posted
Both reviews share the same introduction.
I recently received copies of Hacking Exposed: Web Applications, 2nd Ed (HE:WA2E) by Joel Scambray, Mike Shema, and Caleb Sima, and Professional Pen Testing for Web Applications (PPTFWA) by Andres Andreu. I read HE:WA2E first, then PPTFWA. Both are excellent books, but I expect potential readers want to know which is best for them. I could honestly recommend readers buy either (or both) books. Most people should start by reading HE:WA2E, and then fill in gaps by reading PPTFWA.
Update: A torrrent for the Web App Honeypot is here. You can download the VMware image directly from Wrox here. The root password is Pa55w0rd.
Comments
syngress' `Web Application Security: A Guide for Developers And Penetration Testers' (isbn 159749061X) is supposed to be out this month. i doubt it will compare to either of the two above, but theoretically it should stack up.
i've also had my eye on `How to Break Web Software: Functional And Security Testing of Web Applications And Web Services' (isbn 0321369440) since it came out in february '06.
i may not have time to get to these before the new year, as there are other, more important books i'll be reading, such as `Ipv6 Core Protocols Implementation' (isbn 0124477518) and `Phishing And Counter-measures: Understanding the Increasing Problem of Electronic Identity Theft' (isbn 0471782459).
i haven't even finished `Hacking the Cable Modem' or `CWSP, 2E' fully yet. this holiday season promises tons of good presents^Wreading that i'm looking forward to!
Let us know what you think of those books when you read them. Do you have a blog?
Thanks!