resourcesPublications

 
 

Books

 
Books

Web Application Security – A Beginner’s Guide

November 3, 2011

Publisher: McGraw-Hill Osborne Media; 1 edition
Published: November 3, 2011
ISBN-10: 0071776168
ISBN-13: 978-0071776165

 
 
Books

Hacking Exposed Web Applications 3rd Edition

October 15, 2010

Publisher: McGraw-Hill Osborne Media; 3 edition
Published: October 15, 2010
ISBN-10: 0071740643
ISBN-13: 978-0071740647

 
 
Books

Hacking Exposed Wireless 2nd Edition

July 9, 2010

Publisher: McGraw-Hill Osborne Media; 2 edition
Published: July 9, 2010
ISBN-10: 0071666613
ISBN-13: 978-0071666619

 
 
Books

AJAX Security

December 6, 2007

Publisher: Addison Wesley Professional
Published: December 06, 2007
ISBN-10: 0321491939
ISBN-13: 978-0321491930

 
 
Books

Hacking Exposed Wireless: Wireless Security Secrets & Solutions

March 26, 2007

Publisher: McGraw-Hill Osborne Media; 1st edition
Published: March 26, 2007
ISBN-10: 0072262583
ISBN-13: 978-0072262582

 
 
Books

Writing Security Tools and Exploits

March 11, 2006

Publisher: Syngress; 1 edition
Published: March 11, 2006
ISBN-10: 1597499978
ISBN-13: 978-1597499972

 
 
Books

Penetration Tester’s Open Source Toolkit

February 8, 2006

Publisher: Syngress Publishing; 1 edition
Published: February 8, 2006
ISBN-10: 1597490210
ISBN-13: 978-1597490214

 
 
Books

Sockets, Shellcode, Porting, and Coding

March 21, 2005

Publisher: Syngress Publishing; 1 edition
Published: March 21, 2005
ISBN-10: 1597490059
ISBN-13: 978-1597490054

 

Articles

SPI Dynamics Expert Articles Series – Implementing Effective Vulnerability Remediation Strategies Within the Web Application Development Lifecycle – Aug2007

August 16, 2007

Vincent Liu co-authors Implementing Effective Vulnerability Remediation Strategies Within the Web Application Development Lifecycle as part of the SPI Dynamics Expert Articles series.

 

SPI Dynamics Expert Articles Series – Web Application Vulnerability Assessment Essentials:: Your First Step to a Highly Secure Web Site – Aug2007

August 15, 2007

Vincent Liu co-authors Web Application Vulnerability Assessment Essentials: Your First Step to a Highly Secure Web Site as part of the SPI Dynamics Expert Articles series.

 

ISSA Journal – July 2007 – Penetration Testing: The White Hat Hacker

August 1, 2007

Vincent Liu authors Penetration Testing: The White Hat Hacker in the July 2007 issue of the ISSA Journal.

 

CSO Magazine – The Rise of Antiforensics – June 2007

June 8, 2007

Vincent Liu will be featured in “The Rise of Antiforensics” in CSO magazine.

 

CIO Magazine – How Online Criminals Make Themselves Tough to Find, Near Impossible to Nab – May 2007

May 31, 2007

Vincent Liu will be featured in CIO Magazine – How Online Criminals Make Themselves Tough to Find, Near Impossible to Nab.

 

The Business Journal of Phoenix – Even without big budget, employee theft can be stopped – Nov 2006

November 24, 2006

Vincent Liu will be providing expertise on protecting corporate assets in the November 24, 2006 issue article, The Business Journal of Phoenix – Even without big budget, employee theft can be stopped

 
 

Conference Slides

SharePoint Hacking Diggity – Presentation Slides

June 14, 2012

For all presentation slides related to the SharePoint Hacking Diggity project, please see: SharePoint Hacking Diggity Project – Presentation Slides

 

Google Hacking Diggity – Presentation Slides

June 14, 2012

For all presentation slides related to the Google Hacking Diggity project, please see: Google Hacking Diggity Project – Presentation Slides Page

 

OWASP Atlanta – Attack Chaining Advanced Maneuvers – May 2012

May 31, 2012

Rob Ragan and Oscar Salazar will be presenting on the topic of Advanced Attack Chaining during the OWASP Atlanta meeting on May 31, 2012 at 6:00 PM EST. Slides can be downloaded here: OWASP Atlanta – Attack Chaining Advanced Maneuvers – May 2012 – Slides

 

SANS Penetration Testing Summit 2010

June 14, 2010

The Good, the Bad, and the Ridiculous slides presented at the SANS Penetration testing Summit 2010 in Baltimore, MD can downloaded here.

 
 

Whitepapers

InformationWeek – Using Google to Find Vulnerabilities – 05Mar2012

March 5, 2012

Fran Brown authors the InformationWeek/Dark Reading report InformationWeek – Using Google to Find Vulnerabilities In Your IT Environment. In it, we will examine a slew of new tools and techniques that will allow security professionals to leverage Google, Bing, Baidu and other open search interfaces to proactively track down and eliminate sensitive information disclosures and vulnerabilities in their public systems. We also take a look at defensive tools designed to pull thousands of real-time RSS updates from search engines to provide users with alerts—a sort of intrusion detection system (IDS) for Google hacking.

 

The Challenges of Automated Application Assessments in a Web 2.0 World

December 12, 2009

Rob Ragan and Vincent Liu author The Challenges of Automated Application Assessments in a Web 2.0 World, which discusses the difficulties of properly auditing modern Web 2.0 applications.

 

Effective Controls for Attaining Continuous Application Security Throughout the Web Application Development Life Cycle

September 12, 2007

Vincent Liu co-authors Effective Controls for Attaining Continuous Application Security Throughout the Web Application Development Life Cycle as part of the SPI Dynamics Expert Articles series.