The following book reviews are the copyright of their respective authors and no part should be reproduced without the express permission of the author. Publishers and Authors of the books reviewed may reproduce the whole or extracts of a review for their book. To request copyright permission please email webmaster@birmingham.pm.org.
All the reviews herein are the opinions of the reviewer and are not necessarily the views of Birmingham Perl Mongers and its members. If you feel a review or comment has been made in error, please contact webmaster@birmingham.pm.org to rectify the situation.
Static Link: http://birmingham.grango.org/reviews/35
Title: | Web Security and Commerce |
---|---|
Author(s): | Simson Garfinkel with Gene Spafford |
ISBN: | 1-56592-269-7 |
Publisher: | O'Reilly Media |
Reviewer: | Barbie |
This is a book everyone should read, not just the system admin types, programmers and designers, but end users too. It's a book that contains a lot of thought provoking material with regards to security on the web, both from server attacks and private user information being compromised.
It can be read cover to cover, or by dropping in and out of the bits of interest. Some of the chapters are very web server specific and wouldn't be of interest to HTML editors and users, but there is plenty to keep you on your toes.
I have been waiting for a security book that relates specifically to Perl, but in the interim, this is certainly a good place to start. Each chapter is preceded by either a bit of history, a typical scenario, or an explanation of the terminology before getting to grips with how to combat attacks and the like.
Many aspects of software security are covered, including web servers, firewalls, web browsers, digital signatures, ActiveX controls & plugins, cryptography, SSL together with the programming side of things with Java & JavaScript and the CGI/API languages of Perl & C. I'm not quite sure why there is no mention of VBScript, which is just as lethal in the wrong hands, if not more so with the growth of virii written in the language.
To end the book there are several chapters relating to Commerce & Society, in particular Credit Cards, Blocking Software and the Legal Issues. As a warning to all it's perhaps worth reading this section alone.
I still haven't finished reading this, and am likely to continue re-reading chapters from time to time, just to remind myself of the dangers out there. It's all to easy to become complacent when building your web portal, thinking "well it works for me". If we all planned ahead to combat the known dangers, then the unforeseen ones could be greatly reduced.
My Verdict - A damn good read and a must for anyone thinking about hosting sites.
We are one of the UK's largest Perl user groups, representing Birmingham UK to the international Perl community since 2000. We hold monthly social and technical presentations, and several of our members are now regular attendees and speakers at the YAPC::Europe Perl Conferences.
For further information about Birmingham.pm, please read our Frequently Asked Questions page.
For details about joining our mailing list, please Click Here for more details.
No meeting currently scheduled
No meeting currently scheduled
Download the Birmingham.pm ICalendar
or subscribe to our Google Calendar
Aberdeen Perl Mongers
Bath Perl Mongers
Birmingham Perl Mongers
Bristol Perl Mongers
Devon & Cornwall Perl Mongers
Edinburgh Perl Mongers
Glasgow Perl Mongers
London Perl Mongers
Milton Keynes Perl Mongers
North of England Perl Mongers
Nottingham Perl Mongers
Southampton Perl Mongers
Thames Valley Perl Mongers
• Linux System Programming
• Mastering Perl
• GIMP 2 for Photographers
• Minimal Perl
• Wicked Cool Perl Scripts
• Red Hat Linux 9 Unleashed
• IRC Hacks - 100 Industrial-Strength Tips & Tools
• eBay Hacks - 100 Industrial-Strength Tips & Tools
• Exploiting Software - How To Break Code
• Mac OS X Unleashed, 2nd Edition
* New Reviews
.. More Reviews
Individual Sponsors:
Barbie
Steve Pitchford
Alex Chudnovsky
Richard Dawe
Jon Mitchell
Greg Brown
Brian McCauley
JJ
Richard Clamp
Jon Brookes
Corporate Sponsors:
Birmingham Science Park Aston
Target Support Solutions (TSS) Ltd.
MACS Software Ltd.