Press Release

Cigital Thought Leaders, Paco Hope and Ben Walther, Author Definitive Book on Web Security Testing

"Web Security Testing Cookbook" provides the necessary tools to make security testing a regular part of the development lifecycle.

DULLES, Va., October 30, 2008—Web Security Testing Cookbook Cigital, Inc., a leading software security and quality consulting firm, today announced the release of Web Security Testing Cookbook (O'Reilly, 2008) by Paco Hope and Ben Walther.

Web Security Testing Cookbook (O'Reilly, 2008) is a hands-on, recipe-style reference for web software developers and testers. The recipes show how to check for the most common web security issues, during unit tests, regression tests, and exploratory tests. The book covers a broad range of techniques, from basics like observing messages between clients and servers, to multi-phase tests that script the login and execution of web application features.

"This book complements many of the security texts in the market that tell you what a vulnerability looks like, but not how to systematically test it day in and day out," says Paco Hope. "Leveraging the recipes in this book will add significant security coverage to testing without adding significant time and cost to your effort."

Recipes from Web Security Testing Cookbook demonstrate how to:

  • Obtain, install, and configure useful and free security testing tools
  • Understand how the application communicates with users, to better simulate attacks in tests
  • Choose from many different methods that simulate common attacks such as SQL injection, cross-site scripting, and manipulating hidden form fields
  • Make tests repeatable by using the scripts and examples in the recipes as starting points for automated tests

"Testing web application security is often a time-consuming, repetitive, and unfortunately all too often a manual process. It need not be," said Mike Andrews, author of How to Break Web Software. "This book gives you the keys to simple, effective, and reusable techniques that help find issues before the hackers do."

About the Authors

Paco Hope is a Technical Manager with Cigital. His areas of expertise include software security, security testing, and online casino gaming. He specializes in analyzing the security of software, software systems, and software development processes. Paco frequently speaks at conferences such as the Better Software Conference, STAR East, and STAR West. He conducts training on risk-based security testing, writing security requirements, and software security fundamentals. He can be reached at paco@cigital.com.

Ben Walther is a consultant at Cigital, with a hand in both normal Quality Assurance and Software Security. He designs and executes tests on a daily basis—so he understands the need for simple recipes in the hectic QA world. He frequently speaks on web application testing tools. At Cigital he has tested systems ranging from financial data processing applications to slot machines. Mr. Walther has a B.S. in Information Science from Cornell University and can be reached at bwalther@cigital.com.

About O’Reilly

O'Reilly Media spreads the knowledge of innovators through its books, online services, magazine, and conferences. Since 1978, O'Reilly has been a chronicler and catalyst of leading-edge development, homing in on the technology trends that really matter. Long the information source of choice for technologists, the company now also delivers the knowledge of expert early adopters to everyday computer users. Whether it's delivered in print, online, or in person, everything O'Reilly produces reflects the company's unshakeable belief in the power of information to spur innovation. Visit O’Reilly at www.oreilly.com.

About Cigital

Cigital, Inc., a leading software security and quality consulting firm, has enabled some of the most well-known organizations in financial services, communications, insurance, hospitality, e-commerce and government to reduce their mission-critical software business risks. Cigital consultants specialize in software security and quality solutions to help organizations protect some of their most valuable assets: company and mission information, customer and individual data, shareholder value and brand. Cigital assures the reliable delivery and deployment of software that organizations build, buy and integrate. Each client's unique requirements are served through a combination of proven methodologies, tools and best practices. Established in 1992, Cigital is headquartered near Washington, D.C. with offices in Boston, New York, Los Angeles and Delhi, India.

Contact:
Terri Randolph
Cigital
703-404-5757
trandolph@cigital.com

About the Book

Web Security Testing Cookbook, ISBN 9780596514839 by Paco Hope and Ben Walther, is available online. List price US$39.99. http://oreilly.com/catalog/9780596514839/index.html