TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: the best(s) web security book for web developers

11 点作者 dheavy将近 12 年前
What are, in your opinions, the best web security books available for a web developer today?<p>The kind you would have on your desk along your Rails&#x2F;Django&#x2F;JS classics when building a web app with your team?

4 条评论

jyu将近 12 年前
I&#x27;d also like to know Security 101 for web developers.<p>In a recent appsec thread, there were two books that a lot of people recommended:<p><a href="http:&#x2F;&#x2F;www.amazon.com&#x2F;The-Tangled-Web-Securing-Applications&#x2F;dp&#x2F;1593273886" rel="nofollow">http:&#x2F;&#x2F;www.amazon.com&#x2F;The-Tangled-Web-Securing-Applications&#x2F;...</a><p><a href="http:&#x2F;&#x2F;www.amazon.com&#x2F;The-Web-Application-Hackers-Handbook&#x2F;dp&#x2F;1118026470" rel="nofollow">http:&#x2F;&#x2F;www.amazon.com&#x2F;The-Web-Application-Hackers-Handbook&#x2F;d...</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=5862102" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=5862102</a>
tptacek将近 12 年前
We&#x27;re a software security firm, and when promising candidates reach out to us and tell us they&#x27;re worried that they don&#x27;t have a lot of exposure to web app security, we buy them _The Web App Hackers Handbook_ (I invariably apologize for the stupid title) and _The Tangled Web_.
LarryMade2将近 12 年前
I think a lot of those security checklist things are a good guidemap of what you need to do. Then add to that a security book specific to your application&#x27;s programming language(s)<p>Heres one, there are plenty more: <a href="http:&#x2F;&#x2F;www.techrepublic.com&#x2F;blog&#x2F;security&#x2F;ensure-basic-web-site-security-with-this-checklist&#x2F;424" rel="nofollow">http:&#x2F;&#x2F;www.techrepublic.com&#x2F;blog&#x2F;security&#x2F;ensure-basic-web-s...</a>
dheavy将近 12 年前
Thanks for your input guys, it&#x27;s very valuable!