Review of Web Application Security Books Posted just posted my two reviews on books about Web application security. The first is Hacking Exposed: Web Applications, 2nd Edition by Joel Scambray, Mike Shema, and Caleb Sima. Here is a link to the five star review.

The second is Professional Pen Testing for Web Applications by Andres Andreu. Here is a link to the four star review.

Both reviews share the same introduction.

I recently received copies of Hacking Exposed: Web Applications, 2nd Ed (HE:WA2E) by Joel Scambray, Mike Shema, and Caleb Sima, and Professional Pen Testing for Web Applications (PPTFWA) by Andres Andreu. I read HE:WA2E first, then PPTFWA. Both are excellent books, but I expect potential readers want to know which is best for them. I could honestly recommend readers buy either (or both) books. Most people should start by reading HE:WA2E, and then fill in gaps by reading PPTFWA.

Update: A torrrent for the Web App Honeypot is here. You can download the VMware image directly from Wrox here. The root password is Pa55w0rd.


Anonymous said…
hewa2e is indeed, quite incredible. i have not compared it to pptfwa, but i had planned on doing so. any further details on overlap of material between the two?

syngress' `Web Application Security: A Guide for Developers And Penetration Testers' (isbn 159749061X) is supposed to be out this month. i doubt it will compare to either of the two above, but theoretically it should stack up.

i've also had my eye on `How to Break Web Software: Functional And Security Testing of Web Applications And Web Services' (isbn 0321369440) since it came out in february '06.

i may not have time to get to these before the new year, as there are other, more important books i'll be reading, such as `Ipv6 Core Protocols Implementation' (isbn 0124477518) and `Phishing And Counter-measures: Understanding the Increasing Problem of Electronic Identity Theft' (isbn 0471782459).

i haven't even finished `Hacking the Cable Modem' or `CWSP, 2E' fully yet. this holiday season promises tons of good presents^Wreading that i'm looking forward to!

Let us know what you think of those books when you read them. Do you have a blog?

Oh, the word from Syngress says their Web app book is delayed until next year.
JimmytheGeek said…
The link to the review of HEWA2e goes to HEWA on amazon. I could only find your review via the "all my reviews" link. Of course, being recent, it was 2nd from the top.
Fixed, thanks Jimmy.
Anonymous said…
This comment has been removed by a blog administrator.

Popular posts from this blog

Zeek in Action Videos

New Book! The Best of TaoSecurity Blog, Volume 4

MITRE ATT&CK Tactics Are Not Tactics