Mike Shema develops web application security solutions at Qualys, Inc. His current work is focused on an automated web assessment service. Mike previously worked as a security consultant and trainer for Foundstone where he conducted information security assessments across a range of industries and technologies. His security background ranges from network penetration testing, wireless security, code review, and web security. He is the co-author of Hacking Exposed: Web Applications, The Anti-Hacker Toolkit and the author of Hack Notes: Web Application Security. In addition to writing, Mike has presented at security conferences in the U.S., Europe, and Asia.
<p> The threats highlighted should be understood by web developers, administrators and general users alike. If you use the web in any way then this should be on your bookshelf. In addition to the detailing the threat Shema also provides countermeasures to minimise or remove the risk, but be warned; you may never look at a website the same way again. - Andrew Waite, Security Researcher, InfoSanity Research