An Advanced Guide for Security Professionals and Developers (Updated Edition)
- About This Book
Foreword
Preface
- Who This Book Is For
- Prerequisites
- Ethical Considerations and Legal Disclaimer
- How This Book Is Structured
Chapter 1: Beyond the Basics - Revisiting the Foundations with an Advanced Lens
- 1.1 Advanced Reconnaissance and Information Gathering
- 1.2 Understanding Modern Web Architectures
- 1.3 Advanced Proxy Usage and Configuration (Burp Suite/OWASP ZAP)
Chapter 2: Deep Dive into Injection Vulnerabilities
- 2.1 SQL Injection: Advanced Exploitation
- 2.2 NoSQL Injection
- 2.3 Server-Side Template Injection (SSTI)
- 2.4 XML External Entity (XXE) Injection
- 2.5 OS Command Injection: Advanced Contexts
- 2.6 React2Shell and React Server Component Deserialization
- 2.7 Blind Deserialization and Mitigation Bypass (Expanded)
Chapter 3: Authentication and Authorization Bypass Techniques
- 3.1 JSON Web Token (JWT) Attacks
- 3.2 SAML Attacks
- 3.3 OAuth 2.0 and OpenID Connect Flaws
- 3.4 Multi-Factor Authentication (MFA) Bypass Strategies
- 3.5 Complex Access Control Vulnerabilities
- 3.6 OAuth 2.1 Implementation Pitfalls
- 3.7 OAuth Implementation Best Practices Summary
Chapter 4: Exploiting Complex Client-Side Vulnerabilities
- 4.1 Advanced Cross-Site Scripting (XSS)
- 4.2 JavaScript Prototype Pollution
- 4.3 DOM Clobbering
- 4.4 Advanced Cross-Site Request Forgery (CSRF)
- 4.5 Clickjacking and UI Redressing: Advanced Techniques
Chapter 5: Server-Side Request Forgery (SSRF) - In Depth
- 5.1 Identifying SSRF Vulnerabilities
- 5.2 Exploitation Techniques
- 5.3 Bypassing SSRF Filters
Chapter 6: Deserialization Vulnerabilities
- 6.1 Understanding Serialization and Deserialization
- 6.2 Java Deserialization Attacks
- 6.3 PHP Deserialization (Object Injection)
- 6.4 Python Deserialization (Pickle)
- 6.5 .NET Deserialization
- 6.6 Blind Deserialization and Mitigation Bypass
Chapter 7: Attacking APIs and Microservices
- 7.1 REST API Security Testing
- 7.2 GraphQL Security Testing
- 7.3 Attacking gRPC and Protocol Buffers
- 7.4 API Gateway and Service Mesh Security Issues
Chapter 8: Exploiting Business Logic Flaws
- 8.1 Identifying Logic Flaws
- 8.2 Common Patterns
- 8.3 Race Conditions
Chapter 9: Web Cache Poisoning and Deception
- 9.1 Understanding Web Caching Mechanisms
- 9.2 Cache Poisoning Techniques
- 9.3 Cache Deception Attacks
- 9.4 Edge Side Includes (ESI) Injection
Chapter 10: HTTP Request Smuggling
- 10.1 Understanding Ambiguous Requests (CL.TE, TE.CL, TE.TE)
- 10.2 Identifying Request Smuggling Vulnerabilities
- 10.3 Exploitation Techniques
- 10.4 HTTP/3 QUIC Request Smuggling and TOCTOU (QUIC-er Races)
- 10.5 HTTP/3 Impact on Traditional Attack Vectors
Chapter 11: Cloud-Native Application Security
- 11.1 Serverless (FaaS) Security Issues
- 11.2 Container Security (Docker, Kubernetes)
- 11.3 Cloud Storage Misconfigurations (S3, Azure Blob, GCS)
- 11.4 Infrastructure as Code (IaC) Security Review
Chapter 12: Advanced Evasion Techniques
- 12.1 Bypassing Web Application Firewalls (WAFs)
- 12.2 Bypassing Client-Side Controls
- 12.3 Rate Limit Bypass Techniques
- 12.4 WAFFLED: Parsing Discrepancy-Based WAF Bypass
- 12.5 AI-Powered WAF Bypass Optimization
Chapter 13: Exploit Chaining and Post-Exploitation
- 13.1 The Art of Chaining Vulnerabilities
- 13.2 Web-Based Post-Exploitation
Chapter 14: Reporting, Remediation, and Future Trends
- 14.1 Writing High-Quality Technical Reports
- 14.2 Advanced Remediation Strategies
- 14.3 Emerging Threats and Future Trends
