- The Guide to Finding and Reporting Web Vulnerabilities
- About the Author
- About the Tech Reviewer
- Foreword
- Introduction
- Who This Book Is For
- What Is In This Book
- Happy Hacking!
- 1 Picking a Bug Bounty Program
- 2 Sustaining Your Success
- 3 How the Internet Works
- 4 Environmental Setup and Traffic Interception
- 5 Web Hacking Reconnaissance
- 6 Cross-Site Scripting
- 7 Open Redirects
- 8 Clickjacking
- 9 Cross-Site Request Forgery
- 10 Insecure Direct Object References
- 11 SQL Injection
- 12 Race Conditions
- 13 Server-Side Request Forgery
- 14 Insecure Deserialization
- 15 XML External Entity
- 16 Template Injection
- 17 Application Logic Errors and Broken Access Control
- 18 Remote Code Execution
- 19 Same-Origin Policy Vulnerabilities
- 20 Single-Sign-On Security Issues
- 21 Information Disclosure
- 22 Conducting Code Reviews
- 23 Hacking Android Apps
- 24 API Hacking
- 25 Automatic Vulnerability Discovery Using Fuzzers
The Guide to Finding and Reporting Web Vulnerabilities
Vickie Li
薇琪李
Bug Bounty Bootcamp. Copyright © 2021 by Vickie Li.
漏洞赏金營地。版权所有 © 2021 Vickie Li。
All rights reserved. No part of this work may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or by any information storage or retrieval system, without the prior written permission of the copyright owner and the publisher.
版权所有。未经版权所有者和出版者事先书面许可,任何形式或方式的复制或传播本作品均被禁止,包括但不限于电子或机械形式、复印、录制或任何信息存储或检索系统。
ISBN-13: 978-1-7185-0154-6 (print)
ISBN-13: 978-1-7185-0155-3 (ebook)
ISBN-13: 978-1-7185-0154-6(印刷版)ISBN-13: 978-1-7185-0155-3(电子版)
Publisher: William Pollock
Production Manager: Rachel Monaghan
Production Editors: Miles Bond and Dapinder Dosanjh
Developmental Editor: Frances Saux
Cover Design: Rick Reese
Interior Design: Octopod Studios
Technical Reviewer: Aaron Guzman
Copyeditor: Sharon Wilkey
Compositor: Jeff Lytle, Happenstance Type-O-Rama
Proofreader: James Fraleigh
出版者:威廉·波洛克 制作经理:瑞秋·莫纳汉 制作编辑:迈尔斯·邦德和达平德·多桑吉 开发编辑:弗朗西斯·索克斯 封面设计:瑞克·里斯 内部设计:八爪鱼工作室 技术审核者:阿龙·古兹曼 校对员:沙龙·威尔基 排版人员:杰夫·莱特尔,偶然类型大杂烩 校对员:詹姆斯·弗雷利
For information on book distributors or translations, please contact No Starch Press, Inc. directly:
No Starch Press, Inc.
245 8th Street, San Francisco, CA 94103
phone: 1-415-863-9900; info@nostarch.com
www.nostarch.com
有关图书分销商或翻译的信息,请直接联系 No Starch Press, Inc.:No Starch Press, Inc.245 8th Street,旧金山,CA 94103 电话:1-415-863-9900;info@nostarch.comwww.nostarch.com
Names: Li, Vickie, author.
Title: Bug bounty bootcamp : the guide to finding and reporting web
vulnerabilities / Vickie Li.
Description: San Francisco : No Starch Press, [2021] | Includes index. |
Identifiers: LCCN 2021023153 (print) | LCCN 2021023154 (ebook) | ISBN
9781718501546 (print) | ISBN 9781718501553 (ebook)
Subjects: LCSH: Web sites--Security measures. | Penetration testing
(Computer security) | Debugging in computer science.
Classification: LCC TK5105.8855 .L523 2021 (print) | LCC TK5105.8855
(ebook) | DDC 025.042--dc23
LC record available at https://lccn.loc.gov/2021023153
LC ebook record available at https://lccn.loc.gov/2021023154
姓名:李,薇琪,作者。题目:漏洞赏金训练营: 发现和报告网站漏洞的指南 / 薇琪李。描叙:旧金山: 无淀粉出版社,[2021] | 包括索引。| 标识符: LCCN 2021023153 (print) | LCCN 2021023154 (ebook) | ISBN 9781718501546 (print) | ISBN 9781718501553 (ebook) 主题:LCSH: 网站-安全措施。|穿透测试(计算机安全)|计算机科学中的除错。分类: LCC TK5105.8855 .L523 2021 (print) | LCC TK5105.8855 (ebook) | DDC 025.042--dc23 LC 记录可在 https://lccn.loc.gov/2021023153LC ebook 记录可在 https://lccn.loc.gov/2021023154。
No Starch Press and the No Starch Press logo are registered trademarks of No Starch Press, Inc. Other product and company names mentioned herein may be the trademarks of their respective owners. Rather than use a trademark symbol with every occurrence of a trademarked name, we are using the names only in an editorial fashion and to the benefit of the trademark owner, with no intention of infringement of the trademark.
No Starch Press 和 No Starch Press 标识是 No Starch Press 公司的注册商标。此处提及的其他产品和公司名称可能为其各自所有者的商标。我们没有在每个商标名称出现时使用商标符号,而是仅以编辑方式使用这些名称,以造福商标所有者,无意侵犯商标权。
The information in this book is distributed on an “As Is” basis, without warranty. While every precaution has been taken in the preparation of this work, neither the author nor No Starch Press, Inc. shall have any liability to any person or entity with respect to any loss or damage caused or alleged to be caused directly or indirectly by the information contained in it.
本书中的信息是按“原样”分发的,没有任何保证。在书写这本书的过程中,我们采取了谨慎的措施,但无论是作者还是 No Starch Press, Inc.,对于任何因所包含的信息直接或间接造成的任何损失或损害,不承担任何责任。
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论