| By RIA News Desk | Article Rating: |
|
| August 28, 2007 01:00 PM EDT | Reads: |
14,712 |
AJAXWorld Conference & Expo 2007 West will present a "Security" session by Billy Hoffman entitled "How Hackers Break Into AJAX Application."Interest in AJAX is sky-high and only continues to grow. Unfortunately, far too many people rush into AJAX development without giving proper consideration to security issues. Sure people talk in the abstract about an “increased attack surface” or “leaking secrets” but how securely are people developing AJAX apps? We will present a sample travel website we built using design patterns, advice and code samples from respected resources in the AJAX communities. Next we will show you how we tear the application to shreds, booking ourselves free flights, accessing coupon codes, hijacking the administration functions and stealing everyone’s account information. We do all this using flaws that popular AJAX resource ignore or only mention in passing such as: Improper use of client-side XSLT; Use of overly- or underly-granular server-side APIs; and storing secrets (either data or functionality) in client-side code; exploiting Ajax race conditions, and Applying static analysis to deobfuscate client-side JavaScript. Given the popularity of AJAX and the ease of use of framework helper libraries, it can be very tempting for developers to use Ajax when it's not really necessary. This is a significant security risk in itself, since AJAX applications can be more difficult to secure than traditional Web applications. Furthermore, the use of third-party frameworks can actually make the problem worse, since they hide potential security issues without truly resolving them. We will address these issues, make recommendations on which Ajax frameworks to avoid, and make recommendations on when to avoid AJAX altogether. Following the design and implementation guidelines set out in this presentation will help you to delay your AJAX gratification to provide the highest level of security satisfaction for you and your partners.
Speaker Bio: Billy Hoffman is a lead security researcher for SPI Dynamics (www.spidynamics.com). At SPI Dynamics, Billy focuses on automated discovery of Web application vulnerabilities and crawling technologies. He has been a guest speaker at Black Hat Federal, Toorcon, Shmoocon, O'Reilly's Emerging Technology Conference, The 5th Hope, and several other conferences. His work has been featured in Wired, Make magazine, Slashdot, G4TechTV, and in various other journals and Web sites. Topics have included reverse engineering law and techniques, ATMs, XM Radio and magstripe projects. In addition, Billy is a reviewer of white papers for the Web Application Security Consortium (WASC), and is a creator of Stripe Snoop, a suite of research tools that captures, modifies, validates, generates, analyzes, and shares data from magstripes. He also spends his time contributing to OSS projects and writes articles under the handle Acidus.
Published August 28, 2007 Reads 14,712
Copyright © 2007 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By RIA News Desk
Ever since Google popularized a smarter, more responsive and interactive Web experience by using AJAX (Asynchronous JavaScript + XML) for its Google Maps & Gmail applications, SYS-CON's RIA News Desk has been covering every aspect of Rich Internet Applications and those creating and deploying them. If you have breaking RIA news, please send it to RIA@sys-con.com to share your product and company news coverage with AJAXWorld readers.
![]() |
AJAX Security News 07/25/07 06:44:50 PM EDT | |||
Interest in AJAX is sky-high and only continues to grow. Unfortunately, far too many people rush into AJAX development without giving proper consideration to security issues. Sure people talk in the abstract about an increased attack surface - or leaking secrets? but how securely are people developing AJAX apps? We will present a sample travel website we built using design patterns, advice and code samples from respected resources in the AJAX communities |
||||
- Yahoo! Named “Platinum Sponsor” of Cloud Computing Expo
- Yahoo! to Keynote 4th Cloud Expo: Accelerating Innovation with Cloud Computing
- Zynga’s FarmVille Becomes Largest and Fastest Growing Social Game Ever
- Publishing Synergy: Blog, Twitter and Ulitzer
- Wave on Ulitzer: Confessions of a Google Wave Fanboy
- Is Ulitzer a New Trend or the Ultimate Death of Journalism?
- Twitter, Linked In, Ning and Ulitzer: Easy Personal Branding Strategy
- Confessions of a Ulitzer Addict
- Ulitzer Live! New Media Conference & Expo
- Ulitzer vs. Ning
- Yahoo! Named “Platinum Sponsor” of Cloud Computing Expo
- Yahoo! to Keynote 4th Cloud Expo: Accelerating Innovation with Cloud Computing
- Ulitzer vs. Ning - a Quick Review
- Social Media Terrorists
- Twitter is the Dumbest Thing I Have Ever Seen in My Life
- Zynga’s FarmVille Becomes Largest and Fastest Growing Social Game Ever
- Publishing Synergy: Blog, Twitter and Ulitzer
- Wikipedia Moderators Make Hitler Look Like a Hobbyist
- Wave on Ulitzer: Confessions of a Google Wave Fanboy
- Is Ulitzer a New Trend or the Ultimate Death of Journalism?
- Where Are RIA Technologies Headed in 2008?
- Google Space Launches at Heathrow Airport
- Google Version 2.0: Googzilla - The Calculating Predator
- SEO/SEM Tips & Tricks: How and When Should You Submit Your Website to Google?
- Google Snaps Up the Father of the Orion Search Engine
- AOL To Enhance Video Search Engine by Adding RSS Feeds
- Ulitzer vs Knol - Google Wants Its Own Wikipedia
- AJAXWorld Knocks Spots Off LinuxWorld
- The World's Youngest "Google Entrepreneur" Is One Month Old
- Microsoft's Chase After Google Reverberates



































