Book
Webセキュリティ担当者のための脆弱性診断スタートガイド 第2版
上野宣
Summary
OWASP ZAPやBurp Suiteを用いた動的解析(DAST)の実践手順を、ステップバイステップで解説する ハンズオンガイド。ブラウザとサーバー間のHTTPリクエストを自ら傍受・改ざんし、理論として学んだ SQLインジェクションやXSSが実際のトラフィック上でどう悪用されるかを体感し、理論と実践の溝を埋める。
Target Readers
- 自ら開発したアプリの脆弱性を診断・検証したいエンジニア
- DASTツールの実践的な使い方を学びたい開発者
Tags
Colophon
- Publisher
- 翔泳社
- ISBN
- 978-4-7981-5916-4
- Published
- Feb 2019
- List price
- ¥3,608incl. taxMay differ from the actual selling price on Amazon
Get this book
* The link above is an advertisement via Amazon Associates.Related Books
Prerequisites
- Recommended
体系的に学ぶ 安全なWebアプリケーションの作り方 第2版
徳丸浩
Reason: After learning the principles of vulnerabilities, verify them with your own hands. Dynamic analysis with OWASP ZAP and Burp Suite lets you feel how attacks you knew only in theory actually succeed in real traffic, closing the gap between theory and practice.
- Related
セキュアなソフトウェアの設計と開発
Loren Kohnfelder
Reason: Once threat modeling has surfaced 'where the risks lie' at design time, confirm those assumptions through hands-on assessment. Matching design-level threats against actual behavior validates the effectiveness of your defenses.
Next Books
- Related
生成AIの安全性入門
綿岡晃輝
Reason: After gaining hands-on diagnostic experience with tools like OWASP ZAP and Burp Suite that closes the gap between theory and practice, turn that same posture — verifying defenses in the field — toward a new target. Generative-AI risk is evaluated through a different form, benchmarks and red-teaming, but the idea of backing up desk assumptions with verification carries over.
Sources