19 Deadly Sins of Software Security: Programming Flaws and How to Fix Them (Security One-off)

3.64 avg rating
( 42 ratings by GoodReads )
 
9780072260854: 19 Deadly Sins of Software Security: Programming Flaws and How to Fix Them (Security One-off)

This essential book for all software developers--regardless of platform, language, or type of application--outlines the “19 deadly sins” of software security and shows how to fix each one. Best-selling authors Michael Howard and David LeBlanc, who teach Microsoft employees how to secure code, have partnered with John Viega, the man who uncovered the 19 deadly programming sins to write this much-needed book. Coverage includes:

  • Windows, UNIX, Linux, and Mac OS X
  • C, C++, C#, Java, PHP, Perl, and Visual Basic
  • Web, small client, and smart-client applications

"synopsis" may belong to another edition of this title.

From the Back Cover:

“Ninety-five percent of software bugs are caused by the same 19 programming flaws.” —Amit Yoran, Former Director of The Department of Homeland Security’s National Cyber Security Division

Secure your software by eliminating code vulnerabilities from the start. This essential book for all software developers--regardless of platform, language, and type of application--outlines the 19 sins of software security and shows how to fix each one. Best-selling authors Michael Howard and David LeBlanc, who teach Microsoft employees how to write secure code, have partnered with John Viega, the man who uncovered the 19 deadly programming sins to write this hands-on guide. Detailed code examples throughout show the code defects as well as the fixes and defenses. If you write code, you need this book. Eliminate these security flaws from your code:

  • Buffer overruns
  • Format string problems
  • Integer overflows
  • SQL injection
  • Command injection
  • Failure to handle errors
  • Cross-site scripting
  • Failure to protect network traffic
  • Use of magic URLs and hidden forms
  • Improper use of SSL
  • Use of weak password-based systems
  • Failure to store and protect data securely
  • Information leakage
  • Trusting network address resolution
  • Improper file access
  • Race conditions
  • Unauthenticated key exchange
  • Failure to use cryptographically strong random numbers
  • Poor usability

Michael Howard, CISSP, is an architect of the security process changes at Microsoft and a co-author of Processes to Produce Secure Software published by the Department of Homeland Security’s National Cyber Security Division. He is a Senior Security Program Manager in the Security Engineering Group at Microsoft Corporation and co-author of Writing Secure Code (Microsoft Press). David LeBlanc, Ph.D., is Chief Software Architect for Webroot Software, and was formerly Security Architect in the Office group at Microsoft. He is co-author of Writing Secure Code. John Viega is the CTO of Secure Software. He first defined the 19 deadly sins of software security for the Department of Homeland Security. He is co-author of many security books including Building Secure Software (Addison-Wesley).

About the Author:

Michael Howard is a senior security program manager in the security engineering group at Microsoft Corporation, and a co-author of the award-winning Writing Secure Code. He is a co-author of Basic Training in IEEE Security and Privacy Magazine and a co-author of the National Cyber Security Task Force “Processes to produce Secure Software” document for the Department of Homeland Security. As an author of the Security Development Lifecycle, Michael spends most of his time is spent defining and enforcing security best practice and software development process improvements to deliver more secure software to normal humans.

David LeBlanc, Ph.D., is currently Chief Software Architect for Webroot Software. Prior to joining Webroot, he served as security architect for Microsoft's Office division, was a founding member of the Trustworthy Computing Initiative, and worked as a white-hat hacker in Microsoft's network security group. David is also co-author of Writing Secure Code and Assessing Network Security, as well as numerous articles. On good days, he'll be found riding the trails on his horse with his wife, Jennifer.

John Viega discovered the 19 deadly programming flaws that received such press and media attention, and this book is based on his discovery. He is the Founder and Chief Scientist of Secure Software(www.securesoftware.com), is a well-known security expert, and coauthor of Building Secure Software (Addison-Wesley), Network Security with OpenSSL (O'Reilly) an Adjuct Professor of Computer Science at Virginia Tech (Blacksburg, VA) and Senior Policy Researcher at the Cyberspace Policy Institute, and he serves on the Technical Advisory Board for the Open Web Applications Security Project. He also founded a Washington, D.C. area security interest group that conducts monthly lectures presented by leading experts in the field. John is responsible for numerous software security tools, and is the original author of Mailman, the GNU mailing list manager. He holds a B.A. and M.S. in Computer Science from the University of Virginia. He is the author or coauthor of nearly 80 technical publications, including numerous refered research papers and trade articles. He is coauthor of Building Secure Software, Network Security and Cryptography with OpenSSL and The Secure Programming Cookbook for C and C++.

"About this title" may belong to another edition of this title.

Top Search Results from the AbeBooks Marketplace

1.

Howard, Michael; LeBlanc, David; Viega, John
Published by McGraw-Hill Osborne Media
ISBN 10: 0072260858 ISBN 13: 9780072260854
New PAPERBACK Quantity Available: 1
Seller
BookShop4U
(PHILADELPHIA, PA, U.S.A.)
Rating
[?]

Book Description McGraw-Hill Osborne Media. PAPERBACK. Book Condition: New. 0072260858. Bookseller Inventory # Z0072260858ZN

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 10.34
Convert Currency

Add to Basket

Shipping: FREE
Within U.S.A.
Destination, Rates & Speeds

2.

Howard, Michael; LeBlanc, David; Viega, John
Published by McGraw-Hill Osborne Media
ISBN 10: 0072260858 ISBN 13: 9780072260854
New PAPERBACK Quantity Available: 1
Seller
Vital Products COM LLC
(southampton, PA, U.S.A.)
Rating
[?]

Book Description McGraw-Hill Osborne Media. PAPERBACK. Book Condition: New. 0072260858. Bookseller Inventory # Z0072260858ZN

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 10.34
Convert Currency

Add to Basket

Shipping: FREE
Within U.S.A.
Destination, Rates & Speeds

3.

Howard, Michael; LeBlanc, David; Viega, John
Published by McGraw-Hill Osborne Media 2005-07-26 (2005)
ISBN 10: 0072260858 ISBN 13: 9780072260854
New Paperback Quantity Available: 4
Seller
Ebooksweb COM LLC
(Bensalem, PA, U.S.A.)
Rating
[?]

Book Description McGraw-Hill Osborne Media 2005-07-26, 2005. Paperback. Book Condition: New. 1. 0072260858. Bookseller Inventory # Z0072260858ZN

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 10.34
Convert Currency

Add to Basket

Shipping: FREE
Within U.S.A.
Destination, Rates & Speeds

4.

Howard, Michael; LeBlanc, David; Viega, John
Published by McGraw-Hill Osborne Media (2005)
ISBN 10: 0072260858 ISBN 13: 9780072260854
New Paperback Quantity Available: 1
Seller
MediaCastle
(San Diego, CA, U.S.A.)
Rating
[?]

Book Description McGraw-Hill Osborne Media, 2005. Paperback. Book Condition: New. New. Fast Shipping. APO,FPO welcome. Bookseller Inventory # 917408

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 8.98
Convert Currency

Add to Basket

Shipping: US$ 3.99
Within U.S.A.
Destination, Rates & Speeds

5.

Howard, Michael; LeBlanc, David; Viega, John
Published by McGraw-Hill Osborne Media (2005)
ISBN 10: 0072260858 ISBN 13: 9780072260854
New Softcover Quantity Available: 1
Seller
Book Deals
(Lewiston, NY, U.S.A.)
Rating
[?]

Book Description McGraw-Hill Osborne Media, 2005. Book Condition: New. Brand New, Unread Copy in Perfect Condition. A+ Customer Service!. Bookseller Inventory # ABE_book_new_0072260858

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 15.49
Convert Currency

Add to Basket

Shipping: FREE
Within U.S.A.
Destination, Rates & Speeds

6.

Howard, Michael; LeBlanc, David; Viega, John
Published by McGraw-Hill Osborne Media (2005)
ISBN 10: 0072260858 ISBN 13: 9780072260854
New Paperback Quantity Available: 1
Seller
Irish Booksellers
(Rumford, ME, U.S.A.)
Rating
[?]

Book Description McGraw-Hill Osborne Media, 2005. Paperback. Book Condition: New. book. Bookseller Inventory # 0072260858

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 18.68
Convert Currency

Add to Basket

Shipping: FREE
Within U.S.A.
Destination, Rates & Speeds

7.

Howard, Michael; LeBlanc, David; Viega, John
ISBN 10: 0072260858 ISBN 13: 9780072260854
New Quantity Available: 1
Seller
Castle Rock
(Pittsford, NY, U.S.A.)
Rating
[?]

Book Description Book Condition: Brand New. Book Condition: Brand New. Bookseller Inventory # 97800722608541.0

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 32.30
Convert Currency

Add to Basket

Shipping: US$ 3.99
Within U.S.A.
Destination, Rates & Speeds

8.

Howard, Michael; LeBlanc, David; Viega, John
Published by McGraw-Hill Osborne Media (2005)
ISBN 10: 0072260858 ISBN 13: 9780072260854
New Paperback Quantity Available: 3
Seller
Murray Media
(North Miami Beach, FL, U.S.A.)
Rating
[?]

Book Description McGraw-Hill Osborne Media, 2005. Paperback. Book Condition: New. Bookseller Inventory # P110072260858

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 56.61
Convert Currency

Add to Basket

Shipping: US$ 2.99
Within U.S.A.
Destination, Rates & Speeds

9.

Howard, Michael; LeBlanc, David; Viega, John
Published by McGraw-Hill Osborne Media
ISBN 10: 0072260858 ISBN 13: 9780072260854
New PAPERBACK Quantity Available: 1
Seller
Cloud 9 Books
(West Palm Beach, FL, U.S.A.)
Rating
[?]

Book Description McGraw-Hill Osborne Media. PAPERBACK. Book Condition: New. 0072260858 New Condition. Bookseller Inventory # NEW6.0030191

More Information About This Seller | Ask Bookseller a Question

Buy New
US$ 59.99
Convert Currency

Add to Basket

Shipping: US$ 4.99
Within U.S.A.
Destination, Rates & Speeds