24 Deadly Sins of Software Security: Programming Flaws and How to Fix Them
Howard, Michael; LeBlanc, David; Viega, John
Language: English
Published by McGraw-Hill Companies, 2009
- Softcover
- Used

Seller: ThriftBooks-Atlanta, AUSTELL, GA, U.S.A.ThriftBooks-Atlanta
AbeBooks seller since March 24, 2009
Condition: Used - Fair
US$ 8.72
Quantity: 1 available
Add to basketItem description from seller
Readable copy. Pages may have considerable notes/highlighting. ~ ThriftBooks: Read More, Spend Less.
Seller Inventory # G0071626751I5N00
- Title
- 24 Deadly Sins of Software Security: Programming Flaws and How to Fix Them
- Author
- Howard, Michael; LeBlanc, David; Viega, John
- Publisher
- McGraw-Hill Companies
- Publication year
- 2009
- Condition
- Fair
- Dust jacket
- No Jacket
- Binding
- Paperback
- Language
- English
- ISBN 10
- 0071626751
- ISBN 13
- 9780071626750
- Item weight
- 1.73 pounds
Publisher's Note: Products purchased from Third Party sellers are not guaranteed by the publisher for quality, authenticity, or access to any online entitlements included with the product.
Eradicate the Most Notorious Insecure Designs and Coding Vulnerabilities
Fully updated to cover the latest security issues, 24 Deadly Sins of Software Security reveals the most common design and coding errors and explains how to fix each one-or better yet, avoid them from the start. Michael Howard and David LeBlanc, who teach Microsoft employees and the world how to secure code, have partnered again with John Viega, who uncovered the original 19 deadly programming sins. They have completely revised the book to address the most recent vulnerabilities and have added five brand-new sins. This practical guide covers all platforms, languages, and types of applications. Eliminate these security flaws from your code:
- SQL injection
- Web server- and client-related vulnerabilities
- Use of magic URLs, predictable cookies, and hidden form fields
- Buffer overruns
- Format string problems
- Integer overflows
- C++ catastrophes
- Insecure exception handling
- Command injection
- Failure to handle errors
- Information leakage
- Race conditions
- Poor usability
- Not updating easily
- Executing code with too much privilege
- Failure to protect stored data
- Insecure mobile code
- Use of weak password-based systems
- Weak random numbers
- Using cryptography incorrectly
- Failing to protect network traffic
- Improper use of PKI
- Trusting network name resolution
"Synopsis" may belong to another edition of this title.
About the Author
John Viega discovered the 19 deadly programming flaws that received such press and media attention, and this book is based on his discovery. He is the Founder and Chief Scientist of Secure Software (www.securesoftware.com), is a well-known security expert, and coauthor of Building Secure Software (Addison-Wesley), Network Security with OpenSSL (O'Reilly) an Adjunct Professor of Computer Science at Virginia Tech (Blacksburg, VA) and Senior Policy Researcher at the Cyberspace Policy Institute, and he serves on the Technical Advisory Board for the Open Web Applications Security Project. He also founded a Washington, D.C. area security interest group that conducts monthly lectures presented by leading experts in the field. John is responsible for numerous software security tools, and is the original author of Mailman, the GNU mailing list manager. He holds a B.A. and M.S. in Computer Science from the University of Virginia. He is the author or coauthor of nearly 80 technical publications, including numerous refereed research papers and trade articles. He is coauthor of Building Secure Software, Network Security and Cryptography with OpenSSL and The Secure Programming Cookbook for C and C++.
Michael Howard is is a principal security program manager on the Trustworthy Computing Group’s Security Engineering team at Microsoft. He is the author or coauthor of many well-known software security books and is an editor of IEEE Security & Privacy.
David LeBlanc, Ph.D., is a principal software development engineer on the Microsoft Office security team. He is a coauthor, with Michael Howard, of Writing Secure Code (Microsoft Press).
John Viega is CTO of the SaaS Business Unit at McAfee and was previously their chief security architect. He is the author of five other security books. Mr. Viega first defined the 19 deadly sins of software security for the Department of Homeland Security.
"About the title" may belong to another edition of this title.
ThriftBooks-Atlanta
AUSTELL, GA, U.S.A.
AbeBooks seller since March 24, 2009
Shipping rates within U.S.A.
| Item | 4 to 8 business days | 4 to 8 business days |
|---|---|---|
| First item | US$ 0.00 | US$ 0.00 |
Payment methods
Store description
ThriftBooks is a fully independent seller of used books, having sold more than 160 million used and new books since we started in 2003. Each quality used book is sorted, graded, shelved and shipped by hand by our team of dedicated employees in our seven warehouses across the US. We have the best selection of books, in the right condition and format, at everyday low prices. We also have a dedicated, US-based Customer Service team, ranked in the top three by Newsweek for Best Customer Service in 2018 and 2019, so you can shop with confidence. We support and invest in our employees, appreciate and value our customers, and truly believe in the power of the written word to educate, energize, and engage readers of all ages and interests.…
Seller's business information
Thrift Books Global, LLC
18300 Cascade Ave S, Ste 150
Seattle, WA U.S.A. 98188
Terms of sale
We guarantee the condition of every book as it's described
on the Abebooks website. If you're dissatisfied with your
purchase (Incorrect Book/Not as Described/Damaged) or if the
order hasn't arrived, you're eligible for a refund within 30
days of the estimated delivery date. If you've changed your
mind about a book that you've ordered, please use the "Ask
bookseller a question link to contact us" and we'll respond
as soon as possible.
Shipping terms
All domestic Standard shipments are distributed from our warehouses by OSM, then handed off to the USPS for final delivery.
2-Day Shipping is delivered by FedEx, which does not deliver to PO boxes.
International shipments are tendered to the local postal service in the destination country for final delivery – We do not use courier services for international deliveries.