4/05/2011

Exploratory Software Testing: Tips, Tricks, Tours, and Techniques to Guide Test Design Review

Exploratory Software Testing: Tips, Tricks, Tours, and Techniques to Guide Test Design
Average Reviews:

(More customer reviews)
A few years back, I read "How to Break Software" by James Whittaker. I liked it. It wasn't wonderful, but it had a good batch of practical, useful tips. Then I read "How to Break Software Security" and "How to Break Web Software". I liked them as well, but not as much. Still, I figured I'd read James Whittaker's newest book "Exploratory Software Testing". Sadly, the downward progression of his writing continues. This book is by far the worst of the bunch.
Chapter 1 - "The Case for Software Quality" is nothing more than "software is terrific, but it has bugs". That's it, nothing more here.
Chapter 2 - "The Case for Manual Testing" talks a bit about testing, and tries to define exploratory testing. Whittaker's definition has apparently caused some controversy among some well-known practitioners of exploratory testing, so here is his perhaps unique definition:
"When the scripts are removed entirely (or as we shall see in later chapters, their rigidness relaxed), the process is called exploratory testing."
Whittaker then divides exploratory testing into two sections. Exploratory testing in the small is that which guides the tester to make small, distinct decisions while testing. Exploratory testing in the large guides the tester in how an application is explored more than how a specific feature is tested.
Chapter 3 - "Exploratory Testing in the Small" was, to me, the only useful chapter in the whole book. Here Whittaker offers practical advice with examples for thinking about constructing test data, software state, and test environment.
Chapter 4 - "Exploratory Testing in the Large" is where Whittaker dives into what appears to be the point of the whole book - his Tourist Metaphor. Apparently this is a big hit at Microsoft, but I found it pointless. Think about every type of testing you have ever performed. Now try to torture it into a phrase that ends with the word Tour. There you go - that's the chapter.
Just to give you a flavor, here's a list of all these Tours, and their variations:
The Guidebook Tour
Blogger's Tour
Pundit's Tour
Competitor's Tour
The Money Tour
Skeptical Customer Tour
The Landmark Tour
The Intellectual Tour
Arrogant American Tour
The FedEx Tour
The After-Hours Tour
Morning-Commute Tour
The Garbage Collector's Tour
The Bad-Neighborhood Tour
The Museum Tour
The Prior Version Tour
The Supporting Actor Tour
The Back Alley Tour
Mixed-Destination Tour
The All-Nighter Tour
The Collector's Tour
The Lonely Businessman's Tour
The Supermodel Tour
The TOGOF Tour
The Scottish Pub Tour
The Rained-Out Tour
The Couch Potato Tour
The Saboteur Tour
The Antisocial Tour
Opposite Tour
Crime Spree Tour
Wrong Turn Tour
The Obsessive-Compulsive Tour
Perhaps the idea of calling UI Testing a Supermodel Tour appeals to you, and will make for a richer, more productive set of tests. I don't get it. I just don't see any value here. Doesn't testing have enough variation in language and definitions already, without adding this silliness?
Chapter 5 - "Hybrid Exploratory Testing Techniques" tells us that it's acceptable to combine scenario testing with exploratory testing. Then it spends time rehashing each of the tours from Chapter 4 and tries to suggest a side trip for each.
Chapter 6 - "Exploratory Testing in Practice" presents essays written by several Microsoft testers describing how they each used one or more of the tours in a testing situation. It appears as if Whittaker instructed his charges to write a "What I did this summer"-style essay, in the form of "How I used Tours to do my testing".
Chapter 7 - "Touring and Testing's Primary Pain Points" tries to tell us (in a few paragraphs) how to avoid five pain points - Aimlessness, Repetiveness, Transiency, Monontony, and Memorylesness. There's little real instruction here. For example, we are told that in order to avoid repetitiveness, we must know what testing has already occurred, and understand when to inject variation. Uhm, ok.
Chapter 8 - "The Future of Software Testing" has nothing at all to do with the other chapters, or exploratory testing. It's basically Whittaker's gee-whiz vision of what might be possible (some day) in the future. Perhaps. Whittaker has given this talk in several webinars - it's simply rehashed here.
Since these chapters take up only 136 pages, and obviously aren't enough to fill out a real book, three unrelated appendices are bolted on. A few pages about Testing as a career, and a bunch of pages lifted directly from Whittaker's blogs fill out the book to over 200 pages.
If you really want to learn about Exploratory Testing, this is probably not the place. "Exploratory Software Testing" is fluff - stretched and tortured out barely to book-length. There's not much in the way of learning here.
And if Microsoft testers are really instructed to "Tell me what kind of testing you did today, and make sure it ends with the word Tour", then I feel very sorry for them.

Click Here to see more reviews about: Exploratory Software Testing: Tips, Tricks, Tours, and Techniques to Guide Test Design

How to Find and Fix the Killer Software Bugs that Evade Conventional Testing In Exploratory Software Testing, renowned software testing expert James Whittaker reveals the real causes of today’s most serious, well-hidden software bugs--and introduces powerful new “exploratory” techniques for finding and correcting them.Drawing on nearly two decades of experience working at the cutting edge of testing with Google, Microsoft, and other top software organizations, Whittaker introduces innovative new processes for manual testing that are repeatable, prescriptive, teachable, and extremely effective. Whittaker defines both in-the-small techniques for individual testers and in-the-large techniques to supercharge test teams. He also introduces a hybrid strategy for injecting exploratory concepts into traditional scripted testing. You’ll learn when to use each, and how to use them all successfully. Concise, entertaining, and actionable, this book introduces robust techniques that have been used extensively by real testers on shipping software, illuminating their actual experiences with these techniques, and the results they’ve achieved. Writing for testers, QA specialists, developers, program managers, and architects alike, Whittaker answers crucial questions such as: • Why do some bugs remain invisible to automated testing--and how can I uncover them?• What techniques will help me consistently discover and eliminate “show stopper” bugs?• How do I make manual testing more effective--and less boring and unpleasant?• What’s the most effective high-level test strategy for each project?• Which inputs should I test when I can’t test them all?• Which test cases will provide the best feature coverage?• How can I get better results by combining exploratory testing with traditional script or scenario-based testing?• How do I reflect feedback from the development process, such as code changes?

Buy NowGet 25% OFF

Buy cheap Exploratory Software Testing: Tips, Tricks, Tours, and Techniques to Guide Test Design now.

4/04/2011

How We Test Software at Microsoft Review

How We Test Software at Microsoft
Average Reviews:

(More customer reviews)
I have been a software tester, SDET, for over ten years, and while I stay current with the industry via books and websites, I learned a long time ago that software testing books rarely reflect the real world of software testing. It is a fact that testing comes in later in a software release cycle, and more often then not, well after the decision making. We start out at the wrong end of the problem, so to speak, and end up telling people too late, about issues that should have been addressed much earlier in the release cycle. I get tried of the standard solution to this problem that is presented in most test books and websites, which is `prove the approach doesn't work'. That is inevitability met with the response of upper management, 'keep the quality, but cut the test effort'. (Shoot the messenger)
This book isn't going to waste your time with superficial solutions, or perfect world scenarios, this book is written from the trenches. I spent the first day reading it, nodding my head, and at times yelling "yes, that's it EXACTLY". The writers are drawing from experience, they understand testing software, and more importantly, they understand how to position a tester, and a test team, for success. This book goes far beyond Kaner's "Testing Computer Software", and is a must for any software tester who is passionate about shipping quality products.

Click Here to see more reviews about: How We Test Software at Microsoft


It may surprise you to learn that Microsoft employs as many software testers as developers. Less surprising is the emphasis the company places on the testing discipline—and its role in managing quality across a diverse, 150+ product portfolio.

This book—written by three of Microsoft’s most prominent test professionals—shares the best practices, tools, and systems used by the company’s 9,000-strong corps of testers. Learn how your colleagues at Microsoft design and manage testing, their approach to training and career development, and what challenges they see ahead. Most important, you’ll get practical insights you can apply for better results in your organization.

Discover how to:

Design effective tests and run them throughout the product lifecycle
Minimize cost and risk with functional tests, and know when to apply structural techniques
Measure code complexity to identify bugs and potential maintenance issues
Use models to generate test cases, surface unexpected application behavior, and manage risk
Know when to employ automated tests, design them for long-term use, and plug into an automation infrastructure
Review the hallmarks of great testers—and the tools they use to run tests, probe systems, and track progress efficiently
Explore the challenges of testing services vs. shrink-wrapped software


Buy NowGet 34% OFF

Buy cheap How We Test Software at Microsoft now.

4/03/2011

Bon Appetit Desserts: The Cookbook for All Things Sweet and Wonderful Review

Bon Appetit Desserts: The Cookbook for All Things Sweet and Wonderful
Average Reviews:

(More customer reviews)
This book is amazing - there are an immense amount of recipes that are rated out of 4 whisks - 1 whisk being easy to make and 4 whisks being more advanced. The layout is easy and simple, the pictures are sparse but beautiful and everything sounds delicious! Some of the recipes call for expensive and/or hard to find products but luckily substitutions can be made that taste just as good. I made the pumpkin spiced cake with caramel-cream cheese frosting, and it was unique and delicious. I highly recommend for any sweets lover and aspiring baker.

Click Here to see more reviews about: Bon Appetit Desserts: The Cookbook for All Things Sweet and Wonderful

Includes a subscription (or renewal) to Bon Appetit MagazineFor more than 50 years, Bon Appetit magazine has been seducing readers with to-die-for desserts. From quick homestyle cookies to unforgettable special-occasion finales such as spiced chocolate torte wrapped in chocolate ribbons, Bon Appetit showcases meticulously tested recipes that turn out perfectly--every time. Now, culled from Bon Appetit's extensive archives and including never-before-published recipes, Bon Appetit Desserts promises to be the comprehensive guide to all things sweet and wonderful.Authored by Bon Appetit editor-in-chief Barbara Fairchild, Bon Appetit Desserts features more than 600 recipes--from layer cakes to coffee cakes, tortes and cupcakes to pies, tarts, candies, puddings, souffles, ice cream, cookies, holiday desserts, and much, much more. Certain to inspire both experienced home cooks and those just starting out in the kitchen, each recipe is designed to ensure the dessert preparation process is as enjoyable as the finished result.Bon Appetit Desserts is destined to be the definitive, comprehensive, invaluable dessert resource."This is a gorgeous book that makes me want to make everything--no, taste everything--inside! This is a must-have for every baker, cook, and sweet freak in your life." --Elizabeth Falkner, chef and owner of Citizen Cake and Orson"At last, a collection of Bon Appetit's most treasured dessert recipes, thoroughly tested as always, beautifully illustrated, and, of course, wonderfully delicious. You'll reach for this book each time sweets are on your menu, but you'll come back to it just as often for its myriad tips; great chapters on ingredients, equipment, and techniques; and the many detailed and easy-to-grasp how-tos.It's truly a one-stop book for all of us who love baking." --Dorie Greenspan, author of Baking: From My Home to Yours and Around My French Table"Bon Appetit Desserts is filled with exactly the kind of sweets I like to make: inviting, unpretentious, and easy to love, but also innovative enough to turn a few heads. And the best part is, Bon Appetit Desserts is not only about recipes. With chapters on ingredients, equipment, and techniques, plus a slew of tips from the Bon Appetit test kitchens, it's also a mini-education. Oh, in case you aren't sold yet, I have ten words for you: Banana Layer Cake with Caramel Cream and Sea Salt-Roasted Pecans." --Molly Wizenberg, author of A Homemade Life: Stories and Recipes from My Kitchen Table

Buy NowGet 42% OFF

Buy cheap Bon Appetit Desserts: The Cookbook for All Things Sweet and Wonderful now.

Simply Scones: Quick and Easy Recipes for More than 70 Delicious Scones and Spreads Review

Simply Scones: Quick and Easy Recipes for More than 70 Delicious Scones and Spreads
Average Reviews:

(More customer reviews)
Every recipe I have tried from this cookbook has been fantastic. There are some wonderful combinations such as orange and chocolate scones. The directions are easy, the ingredients are usually common items that are easy to find and all the recipes I have tried turned out yummy.
Although it is a small book, in size, it is not small in yumminess or easiness. I have to admit that scones have become a staple in our house, due in a large part, to this book.
Enjoy.

Click Here to see more reviews about: Simply Scones: Quick and Easy Recipes for More than 70 Delicious Scones and Spreads

Scones make delectable treats for afternoon tea, breakfast, lunch, even midnight snacks.This tempting book features more than seventy luscious recipes for scones and spreads certain to delight both traditional and adverturesome palates:Sweet Scones: Oat Current, Triple Chocolate Chunk, Jam-Filled Walnut, Pistachio Fig SconesSavory Scones: Cheese, Hearty Grain, Pesto, Tex-Mex SconesSpreads: Apple Butter, Clotted Cream, Yogurt Cheese, Chocolate Nut Butter, Raspberry Cream Cheese SpreadPlus dozens more.Special sections tell how to make perfect scones, and how to serve a scrumptious afternoon tea.If you've never indulged in a batch of fresh-baked scones, there's no reason to miss out now!

Buy Now

Buy cheap Simply Scones: Quick and Easy Recipes for More than 70 Delicious Scones and Spreads now.

4/02/2011

500 More Low-Carb Recipes: 500 All New Recipes From Around the World Review

500 More Low-Carb Recipes: 500 All New Recipes From Around the World
Average Reviews:

(More customer reviews)
How do I love Dana Carpender in a completely platonic low carb life saver kind of way? Let me count the ways. Her new cookbook is fabulous. If you don't have it, you simply must get it. So many great looking recipes. As soon as my copy arrived, I read it cover to cover and am about to read it again. We are trying a different recipe every night. We have tried several already and they are very good. We're gonna have another one tonight. I have all of her cookbooks and this one is fab. Her books offer a lot of variety of flavors, which is essential to keeping any way of eating interesting. I'm trying to broaden my taste horizens, and her books give me lots of options. I use her cookbooks everyday. I recommend them all the time, but I don't loan them out. I would be lost if I did! She makes low carb low effort, which makes my life significantly easier. Thanks Dana!

Click Here to see more reviews about: 500 More Low-Carb Recipes: 500 All New Recipes From Around the World

If you've thought about quitting your low-carb lifestyle, it's most likely because you're bored - you just want a really, truly, interesting meal for a change. Problem solved! You and low-carbers like you made 500 Low-Carb Recipes a best-seller, so here are 500 more, and they're better than ever. You'll find flavors from all around the world: Mexican, Thai, Vietnamese, Irish, Caribbean, Japanese, Moroccan, Italian, and Cajun, just to name a few. Here you will find the collected culinary wisdom of hundreds of people who have embraced low-carb cooking and learned just how wonderful it can be. From quick and easy recipes for family dinners to new side dishes to go with those steaks and chops to festive foods to make the holidays enjoyable without blowing your program, we have it all: Thai Beef Lettuce Wraps * Crema di Mascherpone * Mexican Cabbage Soup * Shrimp and Artichoke "Risotto" * French Toasty Eggs * Crab-stuffed Poblano Peppers * Sesame-Almond Napa Slaw * Chili Relleno Casserole * Baked Sole in Creamy Curry Sauce * Caribbean Grilled Chicken Salad * Tuscan Soup * Zucchini Lasagna * Easy Low-Carb Fudge * and much, much moreSo quit with the boring food already! You'll never know just how great healthy low-carb foods can taste - and how much variety you can have - until you try 500 More Low-Carb Recipes!

Buy NowGet 32% OFF

Buy cheap 500 More Low-Carb Recipes: 500 All New Recipes From Around the World now.

4/01/2011

Testing Computer Software, 2nd Edition Review

Testing Computer Software, 2nd Edition
Average Reviews:

(More customer reviews)
Testing Computer Software is one of the those rare books that has taken on the problems of the Verification Engineer. As all of us know, most books written today are targeted for the development audience and even many of these are either poorly written or try to cover too much area. This book however, though broad in its scope, does a good job of treating all of the important areas in verification and testing.
I have found Chapters 2, 3, 7, 11 and 12 to be the most useful and poignant to the average engineer. Not only is each chapter well laid out, but the authors also offer compelling arguments in each chapter to back up their arguments as well. I enjoyed particularly Chapter 3 the section on Path Testing, which conjures up horror stories from my development days. In this section the authors assert that 100% path testing does not imply 100% test coverage. They go on to argue with some rigor why the two are not necessarily the same. Many of you as I can probably claim that though all of the paths in their code were tested, verification was still able to find some condition that would make some part of the code fail. This chapter explains why this may be so and methodologies on how to attack testing those areas.
You will find the book well structured, informative and actually intuitive to navigate through. Each chapter builds on the previous chapters to provide the engineer with a clear idea of all the steps and intricacies involved in testing and verifying complex programs. It can therefore be used by the beginner as a source book for specific test applications, or by the team lead or manager who needs to know more about the actual scope and planning of a complex testing project. This book surely fills a great void in the area of publications software verification.

Click Here to see more reviews about: Testing Computer Software, 2nd Edition



Buy NowGet 22% OFF

Buy cheap Testing Computer Software, 2nd Edition now.

Professional Pen Testing for Web Applications (Programmer to Programmer) Review

Professional Pen Testing for Web Applications (Programmer to Programmer)
Average Reviews:

(More customer reviews)
Taking a top-level view on the subject on pen testing web applications this book is a success. It does not focus on hack techniques only and certainly does not use case studies to just show off. The author provides an excellent balance of in-depth technical hacking information with the way the results from such activity get applied to the business of pen testing. Many other books simply show techniques or cover a case study and then move on, the author of this book, Andres Andreu, covers how to handle the results of such needle in the haystack work in order to make strides towards web presence protection. He is clearly not trying to generate more script kiddies but provide professionals the power to understand their security position in respect to web applications and take measures to protect themselves through this heightened awareness.

One of the strong points the author makes is certainly well taken in that the typical security professional is not knowledgeable enough to properly protect the web applications of today, they are generally network specialists. Based on this notion the book predominately attacks the issue from a programmatic stance aiming at filling the gaps where security is important. But he provides enough foundation and basics that if you carefully read you should not be at a loss when using this book. Also provided are enough data to build an effective personal lab and practice most of the areas covered throughout the book. This book really should be on every desk or shelf of security professionals that deal with web applications.
The book has a general pragmatic overtone and the author is obviously focused on real world work and results, keeping theory to a minimum. There are 11 chapters which are loosely associated to what is seemingly the evolution of a pen-testing project that the author sometimes refers to as a journey. Then there are 4 Appendices covering some interesting areas.
Chapter 1 at first glance seems like the typical nonsense where we find out how vulnerable we all are and how messed up the industry is. And while there is some of that there is also a very strong distinct message about what makes an effective web application pen tester and if you read the material carefully the author is being very motivational and even covering psychological aspects of this type of work. I enjoyed reading about the mindset one has to get into in order to do this type of white hat work effectively. It gave me a new perspective on what I, as a network security professional, deal with daily. There were also some nice touches of doing this not just as an employee but also as a professional. This lean towards consultants is important because the rules are always different when a consultant comes in to do this type of work as an outsider.
Chapter 2 is titled "Some Basics" quite appropriately because only some basics are covered. There is so much more that can be covered in this area even though to be fair the book would then be twice its current size. In any event it is either a love hate type chapter, for example if you have experience with technologies like SOAP then you will not care much for it and will move on. On the other hand if you have gaps in your knowledge that are covered in this chapter you will find it quite beneficial. This seems like a technical chapter targeting non-web-programmers. Security and network engineers stand to learn a lot in this chapter. It covers many different areas like SSL certificates and CSR's all the way to SOAP and WSDL. Along the way many important areas are covered such as standard web languages, web state, data encryption, data encoding, and XML. At first this material in this chapter seems all over the place and I had to come back to it various times. But after the material sank in I realized the method behind the author's seemingly chaotic approach to the material. Love it or hate it there is great material in this chapter.
Chapter 3 is your standard surveillance material with a clear lean towards application specific material as opposed to network level. Some network level material is presented even though these areas are covered much better in other books. The author doesn't seem to be trying to cover this in classic from, he just wants what he needs from the network so as to better attack the application. There are some hidden gems in this chapter that will be eye opening in the sense that some pre-packaged programs for this work will inevitably fall short. Manual analysis of gathered data becomes clear as an important step. One interesting step presented is to gather any and all publicly available information and use it all together to form the basis of some eventual attack.
Chapter 4 seems totally out of place at first and it annoyed me. After the technical material from chapter 3 I wanted to attack something. And this chapter seems to back track into some theoretical best practices nonsense. But there are many hidden technical tidbits in this chapter and so it requires some careful reading. I like the way the author linked the OWASP Top 10 and the WASC categories, this was unique in its approach and I haven't seen that done anywhere else. This chapter will set the general basis for organizing your work into attack areas and has many areas of non-obvious technical information. I would have liked seeing more in the area of threat modeling even though I know many real world practitioners don't practice this. The author exposes the practice in summarized form and clearly states the some clients in the real world don't care about this. But the material is presented in such a way that it can help you discipline yourself into some structured process. After all, an interesting and valuable chapter.
Chapter 5 nose-dives into attacking web servers with a focus on IIS and Apache. Some old and some new exploits are covered. But the key part of the chapter is the area where the types of attacks are covered since this applies to just about any web server. The programmatic approach is blatant here in that most exploits are backed up with code that can execute the attack covered. This is very useful even though you have to be somewhat proficient in Perl for instance to make some of the examples work. I enjoyed this chapter a lot and even wrote some scripts based on the information from this chapter. I now regularly test new web servers with this knowledge before they go live.
Chapter 6 is really the hands on apex of the technical aspects the book brings to light. In respect to standard web applications this chapter is huge and effectively covers many aspects ranging from proxy servers as pen testing tools to custom scripts to injection attacks to brute force attacks. Along the way the author covers related areas like effective dictionary generation for brute forcing. He even covers L33T Speak because it is out there. Chapter 6 starts out with a lightweight checklist that is intended to be a foundation and cannot be anything more. This could have been developed further. After this the chapter covers manual and automated testing.
The manual testing section focuses on Webscarab, Perl/LibWhisker, Authentication attacks (with ObiWan, Brutus, Crowbar THC-hydra, & Lcrack), Buffer overflow's, and client side attacks such as XSS, RSS, cookies based. This section ends with a small but clear example from what the author claims is a "real-world example". Based on the level of detail presented I believe this indeed accurate.
After all the manual work is covered Mr. Andreu dives into the world of automated tools in the form of Open Source and he even exposes some commercial tools that are supposed to be good, even though he certainly leaves that up to the reader. From the Open Source category Paros proxy, Spike proxy, Nikto, E-or, Wikto, ntoinsight, and finally Nessus are covered. Different levels of depth are gone into based on the tool but they are nevertheless effectively presented to us readers. I have used some of them successfully after first being exposed to them from reading this chapter.
Chapter 7 took me from where the previous chapter left off into the dark world of known exploits. It is as if the researchers mentioned in this chapter performed the chapter 6 learning's somewhere and documented their findings into information that can be used by anyone. This chapter is structured similar to Chapter 6 in that it starts out with some examples based on manual work; hence the flow from the previous chapter is nice. Lotus Domino and IIS are attacked in the first 2 manual examples and there is a sense of real world here because in the real world black and white are rare. The author takes us through the entire process of these examples from some of his projects and then shows how sometimes the exposure is acceptable risk as opposed to saying something abrupt like "and so I hacked this successfully". These examples do a great job of putting together many of the teachings presented throughout the book up to this point. They are all tied in effectively and the deep complexity of this work starts to take shape this chapter.
From here there is a shift into automated testing using Metasploit. The tool is presented effectively but the example I felt lacked a lot. Maybe this is because the 2 earlier examples were much juicier but I was left in a somewhat anti-climactic state.
To finish off the chapter the author exposes you to some public sources of valuable data as well as providing you a powerful warning about self-protection and exposing 2 commercial players in the known vulnerability market. The public sources is a nice touch because the information is presented in terms of staying on top of an ever rapidly changing arena like the web based...Read more›

Click Here to see more reviews about: Professional Pen Testing for Web Applications (Programmer to Programmer)

There is no such thing as "perfect security" when it comes to keeping all systems intact and functioning properly. Good penetration (pen) testing creates a balance that allows a system to be secure while simultaneously being fully functional. With this book, you'll learn how to become an effective penetrator (i.e., a white hat or ethical hacker) in order to circumvent the security features of a Web application so that those features can be accurately evaluated and adequate security precautions can be put in place.After a review of the basics of web applications, you'll be introduced to web application hacking concepts and techniques such as vulnerability analysis, attack simulation, results analysis, manuals, source code, and circuit diagrams. These web application hacking concepts and techniques will prove useful information for ultimately securing the resources that need your protection.What you will learn from this book* Surveillance techniques that an attacker uses when targeting a system for a strike* Various types of issues that exist within the modern day web application space* How to audit web services in order to assess areas of risk and exposure* How to analyze your results and translate them into documentation that is useful for remediation* Techniques for pen-testing trials to practice before a live projectWho this book is forThis book is for programmers, developers, and information security professionals who want to become familiar with web application security and how to audit it.Wrox Professional guides are planned and written by working programmers to meet the real-world needs of programmers, developers, and IT professionals. Focused and relevant, they address the issues technology professionals face every day. They provide examples, practical solutions, and expert education in new technologies, all designed to help programmers do a better job.

Buy NowGet 34% OFF

Buy cheap Professional Pen Testing for Web Applications (Programmer to Programmer) now.