<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>insanesecurity &#187; Books</title>
	<atom:link href="http://insanesecurity.info/blog/category/books/feed" rel="self" type="application/rss+xml" />
	<link>http://insanesecurity.info/blog</link>
	<description>security through a distorted eye</description>
	<lastBuildDate>Thu, 25 Feb 2010 22:31:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Browser Security Handbook</title>
		<link>http://insanesecurity.info/blog/browser-security-handbook</link>
		<comments>http://insanesecurity.info/blog/browser-security-handbook#comments</comments>
		<pubDate>Wed, 24 Jun 2009 17:02:07 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
				<category><![CDATA[Books]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[Opera]]></category>
		<category><![CDATA[Safari]]></category>

		<guid isPermaLink="false">http://insanesecurity.info/blog/?p=81</guid>
		<description><![CDATA[Recently after moving the blog to this self-hosted platform I decided to cleanup a bit my feed reader&#8230; you know, add some, delete some. And while searching for blogs to subscribe to I came across Michal Zalewski&#8217;s website searching for a feed. Unfortunately didn&#8217;t find a feed, but did find his newest project&#8230; The Browser [...]]]></description>
			<content:encoded><![CDATA[<p>Recently after moving the blog to this self-hosted platform I decided to cleanup a bit my feed reader&#8230; you know, add some, delete some. And while searching for blogs to subscribe to I came across <a href="http://lcamtuf.coredump.cx/">Michal Zalewski&#8217;s website</a> searching for a feed. Unfortunately didn&#8217;t find a feed, but did find his newest project&#8230;</p>
<p><span id="more-81"></span></p>
<p>
The <a href="http://code.google.com/p/browsersec/wiki/Main">Browser Security Handbook</a> is a free online book covering information related to web browsers like: IE6, IE7, FF2, FF3, Opera, Chrome, Safari and Android. The book covers material from url schemas, http protocol, DOM, up to same-origin policy.</p>
<p>Being a comprehensive document about browsers it&#8217;s a book that I would recommend security testers, as well to website developers. I wouldn&#8217;t be amazed if it where a reference lecture upon browsers in the years to follow.</p>
<p>If you are here you might as well check other published material from Michal Zalewski: <a href="http://lcamtuf.coredump.cx/worm.txt">&#8220;I don&#8217;t think I really love you&#8221;</a> (first Zalewski material I ever read), <a href="http://lcamtuf.coredump.cx/tmp_paper.txt">Absence of fd-based unlink()</a>, <a href="http://lcamtuf.coredump.cx/signals.txt">&#8220;Delivering signals for Fun and Profit&#8221;</a>, <a href="http://artofhacking.com/files/phrack/phrack57/P57-0X0A.TXT">Rise of the Robots</a>, <a href="http://lcamtuf.coredump.cx/juggling_with_packets.txt">Juggling with packets</a>, <a href="http://lcamtuf.coredump.cx/ipfrag.txt">IP Fragmentation</a> and <a href="http://lcamtuf.coredump.cx/strikeout/">&#8220;Strike that out, SAM&#8221;</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.info/blog/browser-security-handbook/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Hacker’s Underground Handbook – Review</title>
		<link>http://insanesecurity.info/blog/the-hackers-underground-handbook-review</link>
		<comments>http://insanesecurity.info/blog/the-hackers-underground-handbook-review#comments</comments>
		<pubDate>Wed, 24 Jun 2009 16:59:41 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
				<category><![CDATA[Books]]></category>

		<guid isPermaLink="false">http://insanesecurity.info/blog/?p=78</guid>
		<description><![CDATA[A couple of days ago David (The Great) Melnichuk released The Hacker&#8217;s Underground Handbook, (e)book that comes as an aid for all those that are starting just now in this domain. Why this and not any other intro/tutorial found on the web, you may ask. Although the internet is the biggest resource, finding useful information [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of days ago <a href="http://mrcracker.com">David (The Great) Melnichuk</a> released <a href="http://learn-how-to-hack.net/?vip=21">The Hacker&#8217;s Underground Handbook</a>, (e)book that comes as an aid for all those that are starting just now in this domain.</p>
<p><span id="more-78"></span></p>
<p>
<a href="http://learn-how-to-hack.net/?vip=21"><img class="aligncenter" title="The Hackers Underground Handbook" src="http://learn-how-to-hack.net/images/template/learn_to_hack.gif" style="float:left" border="0" alt="" width="200"/></a></p>
<p>Why this and not any other intro/tutorial found on the web, you may ask. Although the internet is the biggest resource, finding useful information (in this domain) may prove quite hard, especialy if you aren&#8217;t &#8216;initiated&#8217; yet in hacking. (no there&#8217;s no initiation ritual) And if you don&#8217;t know exactly what you are looking for you may come across: <a href="http://catb.org/~esr/faqs/hacker-howto.html">boring</a>, <a href="http://elite-hackers.com/?p=starting">idiotic</a> (this is just a joke, by the way) and outdated material.</p>
<p><a href="http://learn-how-to-hack.net/?vip=21">The Hacker&#8217;s Underground Handbook</a> will guide you through password hacking, windows hacking, malware, phising, web hacking, network hacking and Linux (intro, installation, etc). All this material fully packed with images, thus being a top step-by-step guide, on the course of which you cannot fail.</p>
<p>A great starting book which will guide you in the right direction, helping you understand the basic concepts of computer security and matters that you should take in consideration.</p>
]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.info/blog/the-hackers-underground-handbook-review/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>OWASP Code Review Guide</title>
		<link>http://insanesecurity.info/blog/owasp-code-review-guide</link>
		<comments>http://insanesecurity.info/blog/owasp-code-review-guide#comments</comments>
		<pubDate>Wed, 24 Jun 2009 16:25:00 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
				<category><![CDATA[Books]]></category>
		<category><![CDATA[ASP]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Javascript]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://insanesecurity.info/blog/?p=50</guid>
		<description><![CDATA[Code review is probably the single-most effective technique for identifying security flaws. When used together with automated tools and manual penetration testing, code review can significantly increase the cost effectiveness of an application security verification effort. (Introduction) The first section (Methodology) walks you through the: introduction to code review, preparation for code review, security code [...]]]></description>
			<content:encoded><![CDATA[<p>Code review is probably the single-most effective technique for identifying security flaws. When used together with automated tools and manual penetration testing, code review can significantly increase the cost effectiveness of an application security verification effort. (<a href="http://www.owasp.org/index.php/Code_Review_Introduction" target="_blank">Introduction</a>)<br />
<span id="more-50"></span><br />
<img src="http://insanesecurity.info/wp-content/uploads//owasp-code-review-guide.jpg" style="float:right;margin: 0 0 0 4px" width="200" />The first section (Methodology) walks you through the: introduction to code review, preparation for code review, security code review in software development life cycle (waterfall and agile), security code review coverage, application threat modeling and code review metrics. From this first section I&#8217;ve found very interesting the &#8220;application threat modeling&#8221; page, because I never did know how to classify (evaluate) the risk of a vulnerability and it really made me understand a lot about it.</p>
<p>The next section of the guide is about crawling code, what to look for in JAVA/ASP/JavaSript.</p>
<p>I&#8217;ll skip the rest (I&#8217;ll let you discover it) and only mention the &#8220;example by technical control&#8221;, section which I would recommend to any web developer (regardless of language) because It points out every aspect for the following technical controls: authentication, authorization, session management, input/data validation, error handling, secure deployment, cryptographic controls.</p>
<p>That being said, you can read the guide on-line at <a href="http://www.owasp.org/index.php/OWASP_Code_Review_Guide_Table_of_Contents" target="_blank">owasp.org</a>, or download the pdf version from <a href="http://www.lulu.com/content/5678680" target="_blank">lulu.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.info/blog/owasp-code-review-guide/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
