19 Deadly Sins of Software Security

Tags:, , ; 227 views ; Comments: No Responses

19 Deadly Sins of Software Security
by Michael Howard (Author), David LeBlanc (Author), John Viega (Author)

  • Paperback: 304 pages
  • Publisher: McGraw-Hill Osborne Media; 1 edition (July 26, 2005)
  • Language: English
  • ISBN-10: 0072260858
  • ISBN-13: 978-0072260854

Product Description

0072260858500bw1 19 Deadly Sins of Software Security

This essential book for all software developers–regardless of platform, language, or type of application–outlines the “19 deadly sins” of software security and shows how to fix each one. Best-selling authors Michael Howard and David LeBlanc, who teach Microsoft employees how to secure code, have partnered with John Viega, the man who uncovered the 19 deadly programming sins to write this much-needed book. Coverage includes:

  • Windows, UNIX, Linux, and Mac OS X
  • C, C++, C#, Java, PHP, Perl, and Visual Basic
  • Web, small client, and smart-client applications

From the Back Cover

“Ninety-five percent of software bugs are caused by the same 19 programming flaws.” —Amit Yoran, Former Director of The Department of Homeland Security’s National Cyber Security Division

Secure your software by eliminating code vulnerabilities from the start. This essential book for all software developers–regardless of platform, language, and type of application–outlines the 19 sins of software security and shows how to fix each one. Best-selling authors Michael Howard and David LeBlanc, who teach Microsoft employees how to write secure code, have partnered with John Viega, the man who uncovered the 19 deadly programming sins to write this hands-on guide. Detailed code examples throughout show the code defects as well as the fixes and defenses. If you write code, you need this book. Eliminate these security flaws from your code:

  • Buffer overruns
  • Format string problems
  • Integer overflows
  • SQL injection
  • Command injection
  • Failure to handle errors
  • Cross-site scripting
  • Failure to protect network traffic
  • Use of magic URLs and hidden forms
  • Improper use of SSL
  • Use of weak password-based systems
  • Failure to store and protect data securely
  • Information leakage
  • Trusting network address resolution
  • Improper file access
  • Race conditions
  • Unauthenticated key exchange
  • Failure to use cryptographically strong random numbers
  • Poor usability

Michael Howard, CISSP, is an architect of the security process changes at Microsoft and a co-author of Processes to Produce Secure Software published by the Department of Homeland Security’s National Cyber Security Division. He is a Senior Security Program Manager in the Security Engineering Group at Microsoft Corporation and co-author of Writing Secure Code (Microsoft Press). David LeBlanc, Ph.D., is Chief Software Architect for Webroot Software, and was formerly Security Architect in the Office group at Microsoft. He is co-author of Writing Secure Code. John Viega is the CTO of Secure Software. He first

Popularity: 30% [?]

Related eBooks - Up | Down


Modern Software Review: Techniques and T...

Modern Software Review: Techniques and Technologies (Hardcover) by Yuk Kuen Wong (Author) # Hardcover: 324 pages # Publisher: IRM Press (March 15, 2006) # Language: English # ISBN-10: 1599040131 # ISBN-13: 978-1599040134 Product Description
Download
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...

Tags:; 7 views ; Comments: No Responses

Open Source Security Tools: Practical Gu...

Open Source Security Tools: Practical Guide to Security Applications by Tony Howlett (Author) # Paperback: 608 pages # Publisher: Prentice Hall PTR (August 8, 2004) # Language: English # ISBN-10: 0321194438 # ISBN-13: 978-0321194435 Product Description
Download
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...

Tags:, , ; 11 views ; Comments: No Responses

Sun Certified System Administrator for S...

Sun Certified System Administrator for Solaris 9.0 Study Guide (Exams 310-014 & 310-015) by Tim Gibbs # Paperback: 936 pages # Publisher: Osborne/McGraw-Hill (November 25, 2002) # Language: English # ISBN-10: 007222598X # ISBN-13: 978-0072225983 Product Description
Download
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...

Tags:, ; 18 views ; Comments: No Responses

Oracle8i: The Complete Reference...

Oracle8i: The Complete Reference by Kevin Loney (Author), George Koch (Author) # Hardcover: 1308 pages # Publisher: Osborne/McGraw-Hill (May 23, 2000) # Language: English # ISBN-10: 0072123648 # ISBN-13: 978-0072123647 Product Description
Download
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...

Tags:, ; 58 views ; Comments: No Responses

Sun Certified Solaris 9 System and Netwo...

Sun Certified Solaris 9 System and Network Administrator All-in-One Exam Guide by Paul A. Watters (Author) # Hardcover: 768 pages # Publisher: Osborne/McGraw-Hill (January 28, 2003) # Language: English # ISBN-10: 0072225300 # ISBN-13: 978-0072225303 Product Description
Download
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

Tags:, , ; 8 views ; Comments: No Responses

Oracle Database 10g High Availability wi...

Oracle Database 10g High Availability with RAC, Flashback, and Data Guard by Matthew Hart (Author), Scott Jesse (Author), Matthew Hart (Author), Scott Jesse (Author) # Paperback: 496 pages # Publisher: McGraw-Hill Osborne Media; 1 edition (April 21, 2004) # Language: English # ...
Download
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

Tags:, , ; 28 views ; Comments: No Responses

Sun Certified System Administrator for S...

Sun Certified System Administrator for Solaris 9.0 Study Guide by Tim Gibbs (Author) # Paperback: 936 pages # Publisher: Osborne/McGraw-Hill (November 25, 2002) # Language: English # ISBN-10: 007222598X # ISBN-13: 978-0072225983 Product Description
Download
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

Tags:, ; 8 views ; Comments: No Responses

RHCE Red Hat Certified Engineer Linux St...

RHCE Red Hat Certified Engineer Linux Study Guide by Michael Jang (Author) # Paperback: 768 pages # Publisher: McGraw-Hill Osborne Media; 4 edition (March 30, 2004) # Language: English # ISBN-10: 0072253657 # ISBN-13: 978-0072253658 Product Description
Download
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

Tags:, , , ; 274 views ; Comments: No Responses