The Browser Hacker's Handbook

The Browser Hacker's Handbook
复制标题

DOI:
--
复制
发表时间:
2014-02
期刊:
--
影响因子:
--
通讯作者:
Wade Alcorn;Christian Frichot;Michele Orrù
Wade Alcorn;Christian Frichot;Michele Orrù
中科院分区:
其他
文献类型:
--
作者:
Wade Alcorn;Christian Frichot;Michele Orrù

文献摘要

被引文献

相似文献

黑客利用浏览器漏洞攻击网络深处浏览器黑客手册提供了一个实际的理解黑客的日常网络浏览器,并使用它作为滩头阵地,发动进一步的攻击深入到企业网络。该手册由经验丰富的计算机安全专家团队编写,提供了探索一系列当前攻击方法的实践教程。Web浏览器已成为世界上最流行和最广泛使用的计算机“程序”。作为互联网的门户,它是任何在线运营的企业店面的一部分,但它也是任何系统最脆弱的入口点之一。随着攻击的增加,公司越来越多地采用浏览器加固技术来保护所有当前使用的浏览器中固有的独特漏洞。浏览器黑客手册全面涵盖了复杂的安全问题,并探讨了相关主题,如:攻击同源策略阿普欺骗、社会工程和网络钓鱼以访问浏览器DNS隧道、攻击Web应用程序和代理所有这些都来自浏览器利用浏览器及其生态系统(插件和扩展)跨源攻击,包括协议间通信和利用《浏览器黑客手册》是在考虑专业安全参与的情况下编写的。利用浏览器作为进入目标网络的支点,应该成为任何社会工程或红队安全评估的一个不可或缺的组成部分。本手册提供了一个完整的方法来理解和构建您的下一个浏览器渗透测试。
Hackers exploit browser vulnerabilities to attack deep within networksThe Browser Hacker's Handbook gives a practical understanding of hacking the everyday web browser and using it as a beachhead to launch further attacks deep into corporate networks. Written by a team of highly experienced computer security experts, the handbook provides hands-on tutorials exploring a range of current attack methods. The web browser has become the most popular and widely used computer "program" in the world. As the gateway to the Internet, it is part of the storefront to any business that operates online, but it is also one of the most vulnerable entry points of any system. With attacks on the rise, companies are increasingly employing browser-hardening techniques to protect the unique vulnerabilities inherent in all currently used browsers. The Browser Hacker's Handbook thoroughly covers complex security issues and explores relevant topics such as: Bypassing the Same Origin Policy ARP spoofing, social engineering, and phishing to access browsers DNS tunneling, attacking web applications, and proxyingall from the browser Exploiting the browser and its ecosystem (plugins and extensions)Cross-origin attacks, including Inter-protocol Communication and Exploitation The Browser Hacker's Handbook is written with a professional security engagement in mind. Leveraging browsers as pivot points into a target's network should form an integral component into any social engineering or red-team security assessment. This handbook provides a complete methodology to understand and structure your next browser penetration test.