
ASP.NET Core Secure Coding Cookbook
Author(s): Roman Canlas (Author)
- Publisher: Packt Publishing
- Publication Date: 16 July 2021
- Language: English
- Print length: 324 pages
- ISBN-10: 180107156X
- ISBN-13: 9781801071567
Book Description
Learn how to secure your ASP.NET Core web app through robust and secure code
Key Features
- Discover the different types of security weaknesses in ASP.NET Core web applications and learn how to fix them
- Understand what code makes an ASP.NET Core web app unsafe
- Build your secure coding knowledge by following straightforward recipes
Book Description
ASP.NET Core developers are often presented with security test results showing the vulnerabilities found in their web apps. While the report may provide some high-level fix suggestions, it does not specify the exact steps that you need to take to resolve or fix weaknesses discovered by these tests.
In ASP.NET Secure Coding Cookbook, you’ll start by learning the fundamental concepts of secure coding and then gradually progress to identifying common web app vulnerabilities in code. As you progress, you’ll cover recipes for fixing security misconfigurations in ASP.NET Core web apps. The book further demonstrates how you can resolve different types of Cross-Site Scripting. A dedicated section also takes you through fixing miscellaneous vulnerabilities that are no longer in the OWASP Top 10 list. This book features a recipe-style format, with each recipe containing sample unsecure code that presents the problem and corresponding solutions to eliminate the security bug. You’ll be able to follow along with each step of the exercise and use the accompanying sample ASP.NET Core solution to practice writing secure code.
By the end of this book, you’ll be able to identify unsecure code causing different security flaws in ASP.NET Core web apps and you’ll have gained hands-on experience in removing vulnerabilities and security defects from your code.
What you will learn
- Understand techniques for squashing an ASP.NET Core web app security bug
- Discover different types of injection attacks and understand how you can prevent this vulnerability from being exploited
- Fix security issues in code relating to broken authentication and authorization
- Eliminate the risks of sensitive data exposure by getting up to speed with numerous protection techniques
- Prevent security misconfiguration by enabling ASP.NET Core web application security features
- Explore other ASP.NET web application vulnerabilities and secure coding best practices
Who this book is for
This ASP.NET Core book is for intermediate-level ASP.NET Core web developers and software engineers who use the framework to develop web applications and are looking to focus on their security using coding best practices. The book is also for application security engineers, analysts, and specialists who want to know more about securing ASP.NET Core using code and understand how to resolve issues identified by the security tests they perform daily.
Table of Contents
- Secure Coding Fundamentals
- Injection Flaws
- Broken Authentication
- Sensitive Data Exposure
- XML External Entities
- Broken Access Control
- Security Misconfiguration
- Cross-Site Scripting
- Insecure Deserialization
- Using components with known vulnerabilities
- Insufficient Logging and Monitoring
- Miscellaneous Vulnerabilities
- Best Practices
Editorial Reviews
Review
“Secure coding knowledge is fundamental in order for modern society to survive. It is rare for authors to be able to accurately depict how secure coding should be done in the various languages and frameworks that software developers use today. Mr. Roman has written an amazing book that all ASP.NET Core 5 developers should buy. The knowledge is contextual to their work and will help them reach the hard-to-attain goal of a secure software ecosystem in their organizations.”
—
Jim Manico, Founder and Secure Coding Instructor at Manicode Security, OWASP Volunteer
” ‘A ship in port is safe, but that’s not what ships are built for.’
– Grace Hopper
Similarly, your application is built for a reason. But, as Grace implies, security must be achieved, even if it isn’t our primary purpose.
In ASP.NET Core 5 Secure Coding Cookbook, author Roman Canlas has set a precedent by writing a book with a title that you have to think about for a few seconds before you can fully grok its purpose. Much like the title, you’ll find yourself pondering and contemplating over the content of this book, finding new ways to apply this wisdom. You’ll find practical solutions and detailed explanations, from security coding fundamentals to fixing issues in injection, authentication, exposed data, and more.
Take this book with you in your career, and then refer back to these recipes as often as you can. Just like chefs should review their recipes before they cook their culinary creations, you also should review these recipes before you serve your customers with a masterpiece of your own.”
—
Ed Price, Senior Program Manager of Architectural Publishing, Microsoft | Azure Architecture Center
About the Author
Roman Canlas is a Senior Application Security Engineer working at a Fortune 500 company where he successfully established its global Application Security program from the ground up. His years of experience as a developer-led him to be an expert in Secure Code reviews and Static Application Security testing, focusing on web technologies.
Roman held multiple certifications; the GIAC Web Application Penetration Tester (GWAPT), ISC2’s Certified Secure Software Lifecycle Professional (CSSLP), and EC-Council’s Certified Application Security Engineer in .NET (CASE.NET).
Roman also has a Master’s degree in Information Systems and a Bachelors in Computer Science.
Wow! eBook


