Security Principles for PHP Applications: A php[architect] guide
Language: English
Published by LIGHTNING SOURCE INC, 2017
- Softcover
- New

Condition: New
£ 27.51
Quantity: Over 20 available
Add to basketSeller Inventory # 905890088
- Title
- Security Principles for PHP Applications: A php[architect] guide
- Author
- Mann, Eric
- Publisher
- LIGHTNING SOURCE INC
- Publication year
- 2017
- Condition
- New
- Binding
- Kartoniert / Broschiert
- Language
- English
- ISBN 10
- 1940111617
- ISBN 13
- 9781940111612
Discover how to secure your applications against the vulnerabilities exploited by attackers.
Security is an ongoing process not something to add right before your application launches. In this book, you'll learn how to write secure PHP applications from first principles. You'll be able to identify the threats exposed by legacy applications and avoid following the same broken patterns while engineering your tools. This book will give you the background to avoid the risk most commonly encountered in web application development.
This book is for anyone getting their start in web development. It's for anyone who wants to understand better the common risks that plague newer applications. It's for seasoned developers who want a refresher on the common pitfalls and mistakes that may affect their code. It should be a resource you can turn to when building or maintaining your web application to ensure you're practicing a security-first mindset.
This book is divided primarily into two sections. The first covers the ten application security risks presented by the OWASP Top Ten (as of 2017). Each chapter in this section will detail:
- The nature of the vulnerability to be avoided.
- Example code illustrating how the vulnerability might appear in practice.
- A detailed illustration of how to properly patch the vulnerability.
- Notable examples where this vulnerability has impacted business in the wild.
Why wait until your site is attacked or your data is breached?
Prevent your exposure by being aware of the ways a malicious user might hijack your web site or API.
Security Principles for PHP Applications is a comprehensive guide to cultivating a security-first mindset. This book contains examples of vulnerable code side-by-side with solutions to harden it. Organized around the 2017 OWASP Top Ten list, topics covered include:
- Injection Attacks such as SQL, OS, and LDAP caused by using untrusted data.
- Authentication and Session Management to prevent compromising user passwords, kets, and session tokens.
- Sensitive Data Exposure—adequately protecting data such as credit card numbers, tax IDs, and authentication credentials
- Access Control and Password Handling to properly enforce what authenticated users are allowed to do.
- PHP Security Settings to harden the server, framework, and libraries used to build your software.
- Avoiding Cross-Site Scripting flaws by properly validating input and escaping output strings.
- Adequately Logging and Monitoring to identify threats in real-time.
- API Protection by detecting, preventing, and responding to manual and automated attacks
- Preventing Cross-Site Request Forgery which can trick application users into sending forged HTTP requests.
- Using components with known vulnerabilities
- Insecure deserialization which can allow attackers to run arbitrary code
- XML External Entities—guarding against injection attacks when parsing XML input.
- Guarding against unvalidated redirects and forwards.
- Using peer code reviews to identify security issues before they are deployed to production.
Written by PHP professional Eric Mann, this book builds on his experience in building secure, web applications with PHP.
"Synopsis" may belong to another edition of this title.
Shipping rates from Germany to U.S.A.
| Item | 26 to 60 business days | 26 to 60 business days |
|---|---|---|
| First item | £ 41.53 | £ 41.53 |
Payment methods
- Bank Wire Transfer
- Check
- Paypal
Store description
Online Handel nur mit Neubüchern
Seller's business information
Moluna GmbH
Engberdingdamm 27
Greven, Germany 48268
Terms of sale
About Us
Legal website operator identification:
Moluna GmbH
Represented by the general manager Helge Blischke
Engberdingdamm 27
48268 Greven
Germany
Telephone: 02571/5698933
Telefax: 02571/5698930
E-Mail: abe@moluna.de
VAT No.: DE296281834
listed in the commercial register of the local court Steinfurt
Commercial register number - Part B of the commercial register - 10553
We are a member of the initiative „FairCommerce“ since 24.07.2015.
For more information, see: www.haendlerbund.de/faircommerce.
Right of withdrawal
If you are a consumer you can withdraw from the contract in accordance with the following. Consumer means any natural person who is acting for purposes which are outside his trade, business, craft or profession.
Information regarding the right of withdrawal
Statutory right to withdraw
You have the right to withdraw from this contract within 14 days without giving any reason.
The withdrawal period will expire after 14 days from the day on which you acquire, or a third party other than the carrier and indicated by you acquires, physical possession of the last good or the last lot or piece.
To exercise the right of withdrawal, electronically fill in and submit a clear statement on our website, under "My Purchases" in "My Account". We will communicate to you an acknowledgement of receipt of such a withdrawal on a durable medium (e.g. by e-mail) without delay.
To meet the withdrawal deadline, it is sufficient for you to send your communication concerning your exercise of the right of withdrawal before the withdrawal period has expired.
Effects of withdrawal
If you withdraw from this contract, we will reimburse to you all payments received from you, including the costs of delivery (except for the supplementary costs arising if you chose a type of delivery other than the least expensive type of standard delivery offered by us).
We may make a deduction from the reimbursement for loss in value of any goods supplied, if the loss is the result of unnecessary handling by you.
We will make the reimbursement without undue delay, and not later than 14 days after the day on which we are informed about your decision to withdraw from this contract.
We will make the reimbursement using the same means of payment as you used for the initial transaction, unless you have expressly agreed otherwise; in any event, you will not incur any fees as a result of such reimbursement.
We may withhold reimbursement until we have received the goods back, or you have supplied evidence of having sent back the goods, whichever is the earliest.
You shall send back the goods or hand them over to moluna, Greven, Germany, without undue delay and in any event not later than 14 days from the day on which you communicate your withdrawal from this contract to us. The deadline is met if you send back the goods before the period of 14 days has expired. You will have to bear the direct cost of returning the goods. You are only liable for any diminished value of the goods resulting from the handling other than what is necessary to establish the nature, characteristics and functioning of the goods.
Exceptions to the right of withdrawal
The right of withdrawal does not apply to:
- The delivery of newspapers, journals or magazines with the exception of subscription contracts; and
- The supply of digital content which is not supplied on a tangible medium (e.g. on a CD or DVD) if you accepted when you placed your order that we could start to deliver it, and that you could not withdraw once delivery had started.