
۴۴٬۰۰۰تومان
نوع فایل دانلود: EPUB
پس از خرید، یک فایل EPUB دریافت میکنید.
این فایل با Calibre، Apple Books و سایر کتابخوانهای دیجیتال مناسب است.
با استفاده از سادگی پایتون و کتابخانههای موجود، ابزارهای تست امنیت وب را برای برنامه خود بسازید. با روششناسی و جعبهابزار تست نفوذ برنامههای وب با استفاده از پایتون آشنا شوید. با کتابخانه Scrapy یک خزنده/اسپایدر وب بنویسید. با نوشتن یک اسکریپت بهصورت کاملاً مستقل، آسیبپذیریهای تزریق SQL را شناسایی و بهرهبرداری کنید.
تست نفوذ وب یعنی استفاده از ابزارها و کد برای حمله به یک وبسایت یا برنامه وب، با هدف ارزیابی میزان آسیبپذیری آن در برابر تهدیدهای بیرونی. هرچند امروز ابزارهای آماده و پیشرفته زیادی برای اسکن آسیبپذیریهای سیستمها وجود دارد، اما استفاده از پایتون به شما امکان میدهد اسکریپتهایی مخصوص همان سیستم بنویسید یا ابزارهای موجود را تغییر دهید و گسترش دهید تا تا حد ممکن ضعفهای امنیتی را پیدا، بهرهبرداری و ثبت کنید.
کتاب «یادگیری تست نفوذ وب با پایتون» شما را قدمبهقدم با روششناسی تست نفوذ برنامههای وب همراه میکند و نشان میدهد چگونه برای هر مرحله از این فرایند، ابزارهای خودتان را با پایتون بنویسید. کتاب با تأکید بر اهمیت توانایی ساخت ابزارهای اختصاصی با پایتون برای تست نفوذ برنامههای وب آغاز میشود. سپس یاد میگیرید چگونه با استفاده از پایتون با یک برنامه وب تعامل کنید، ساختار یک درخواست HTTP، نشانی URL، هدرها و بدنه پیام را بشناسید، و بعدتر اسکریپتی برای ارسال درخواست و تفسیر پاسخ و هدرهای آن بسازید.
در ادامه کتاب، با استفاده از پایتون و کتابخانه Scrapy یک خزنده وب خواهید نوشت. این کتاب همچنین به شما کمک میکند ابزاری برای اجرای حملات جستوجوی فراگیر (brute force) در بخشهای مختلف یک برنامه وب توسعه دهید. بعد از آن، بیشتر با روشهای شناسایی و بهرهبرداری از آسیبپذیریهای تزریق SQL آشنا میشوید. تا پایان این کتاب، با موفقیت یک پراکسی HTTP بر پایه ابزار mitmproxy ساخته خواهید بود.
با استفاده از پایتون و کتابخانه Requests با یک برنامه وب تعامل کنید. یک خزنده ساده برای برنامه وب بسازید و آن را بازگشتی کنید. ابزاری برای brute force توسعه دهید تا منابعی مانند فایلها و پوشهها را کشف و فهرست کند. روشهای مختلف احراز هویت که معمولاً در برنامههای وب استفاده میشوند را بررسی کنید. با استفاده از تزریق SQL، نام جدولها را از یک پایگاه داده استخراج کنید. با روششناسی و جعبهابزار تست نفوذ برنامههای وب آشنا شوید.
کتاب «یادگیری تست نفوذ وب با پایتون» برای توسعهدهندگان وبی است که میخواهند وارد دنیای تست امنیت برنامههای وب شوند. آشنایی پایه با پایتون ضروری است.
1. مقدمهای بر تست نفوذ برنامههای وب
2. تعامل با برنامههای وب
3. خزش وب با Scrapy - نقشهبرداری از برنامه
4. کشف منابع
5. آزمون گذرواژه
6. شناسایی و بهرهبرداری از آسیبپذیریهای تزریق SQL
7. رهگیری درخواستهای HTTP
Leverage the simplicity of Python and available libraries to build web security testing tools for your application* Understand the web application penetration testing methodology and toolkit using Python* Write a web crawler/spider with the Scrapy library* Detect and exploit SQL injection vulnerabilities by creating a script all by yourselfWeb penetration testing is the use of tools and code to attack a website or web app in order to assess its vulnerability to external threats. While there are an increasing number of sophisticated, ready-made tools to scan systems for vulnerabilities, the use of Python allows you to write system-specific scripts, or alter and extend existing testing tools to find, exploit, and record as many security weaknesses as possible. Learning Python Web Penetration Testing will walk you through the web application penetration testing methodology, showing you how to write your own tools with Python for each activity throughout the process. The book begins by emphasizing the importance of knowing how to write your own tools with Python for web application penetration testing. You will then learn to interact with a web application using Python, understand the anatomy of an HTTP request, URL, headers and message body, and later create a script to perform a request, and interpret the response and its headers. As you make your way through the book, you will write a web crawler using Python and the Scrappy library. The book will also help you to develop a tool to perform brute force attacks in different parts of the web application. You will then discover more on detecting and exploiting SQL injection vulnerabilities. By the end of this book, you will have successfully created an HTTP proxy based on the mitmproxy tool.* Interact with a web application using the Python and Requests libraries* Create a basic web application crawler and make it recursive* Develop a brute force tool to discover and enumerate resources such as files and directories* Explore different authentication methods commonly used in web applications* Enumerate table names from a database using SQL injection* Understand the web application penetration testing methodology and toolkitLearning Python Web Penetration Testing is for web developers who want to step into the world of web application security testing. Basic knowledge of Python is necessary.1. Introduction to Web Application Penetration Testing2. Interacting with Web Applications3. Web Crawling with Scrapy – Mapping the Application4. Discovering resources5. Password Testing6. Detecting and Exploiting SQL Injection Vulnerabilities7. Intercepting HTTP Requests