Web Application Security for Developers Audiobook By Re-Wise Publishers cover art

Web Application Security for Developers

The OWASP Top 10 and Beyond

Virtual Voice Sample

Get 30 days of Standard free

Auto-renews at $8.99/mo after 30-day trial. Cancel anytime
Try for $0.00
More purchase options

Web Application Security for Developers

By: Re-Wise Publishers
Narrated by: Virtual Voice
Try for $0.00

$8.99 a month after 30 days. Cancel anytime.

Buy for $14.99

Buy for $14.99

Background images

This title uses virtual voice narration

Virtual voice is computer-generated narration for audiobooks.

If you write code that runs on the web, you are responsible for its security, whether or not you have a security team behind you. Most application vulnerabilities are not introduced by infrastructure failures or sophisticated nation-state hackers. They are introduced by developers writing code without a clear picture of how it gets exploited. This book closes that gap.

Written for backend and full-stack developers who are not security specialists, this guide translates the OWASP Top 10 (2021 edition) and a range of additional critical vulnerabilities into the language developers already speak: real code, real attacks, and real fixes. No jargon walls. No vague advice. No lectures about "taking security seriously." Just the mechanisms, the mistakes, and the practical remedies.

Inside this book, you will learn how to:

  • Understand and prevent SQL injection, command injection, and LDAP injection using parameterized queries and input validation
  • Store passwords correctly using bcrypt and Argon2, and implement session management that resists fixation and hijacking
  • Identify and close account enumeration vulnerabilities in login forms, registration flows, and password reset endpoints
  • Implement CSRF protection, Content Security Policy, and clickjacking defenses with the right HTTP headers
  • Audit, update, and lock your dependencies against supply chain attacks, including dependency confusion
  • Recognize dangerous patterns such as insecure deserialization, prototype pollution, ReDoS, and eval injection
  • Build access control logic that prevents both horizontal and vertical privilege escalation
  • Handle file uploads, open redirects, mass assignment, and JWT vulnerabilities without introducing new risks
  • Log the right events without accidentally logging sensitive data, and structure your monitoring for real-world detection

This is a practitioner's pocket reference, not a textbook. Each vulnerability is explained with the actual code a developer might write, the actual payload an attacker would use, and the concrete fix that eliminates the risk. The included Developer Security Checklist gives you an actionable summary you can apply immediately to any project.

Whether you are building a new application from scratch or hardening one that is already in production, this book gives you the security knowledge that belongs in every developer's toolkit.

Programming & Software Development Security & Encryption Software Software Development Management Technology Computer Security
adbl_web_anon_alc_button_suppression_t1
No reviews yet