| By RIA News Desk | Article Rating: |
|
| August 30, 2007 07:45 AM EDT | Reads: |
8,107 |
With so many Web 2.0 applications being written in AJAX, it was only a matter of time before the vulnerabilities began to crop up, but no one expected the unusual form they would take. This session by the man who discovered the first cross-vendor AJAX vulnerability – JavaScript Hijacking - will detail it and other security concerns while also discussing ways that AJAX could be implemented to make it less risky. Finally, we will take a look at AJAX security incidents to-date, and identify the ways that increased adoption of AJAX is likely to change the way hackers behave.AJAXWorld 2007 East Conference & Expo Sponsored by the World's Top Web 2.0 and RIA Technology Leaders!
AJAXWorld Conference & Expo 2007 East sponsors and exhibitors included: Laszlo Systems (Diamond Sponsor), JackBe (Platinum Sponsor), Adobe (Platinum Sponsor), Cynergy (Platinum Sponsor), Backbase (Gold Sponsor) Google (Gold Sponsor), Nexaweb (Gold Sponsor), ICEsoft (Gold Sponsor), Oracle (Gold Sponsor), Helmi Technologies (Gold Sponsor), JetBrains (Gold Sponsor), TIBCO (Gold Sponsor), Kapow Technologies (Gold Sponsor), Sun Microsystems (Silver Sponsor), Parasoft (Silver Sponsor), Servoy (Silver Sponsor), Etelos (Silver Sponsor), Microsoft (Expo Plus Sponsor), Lightstreamer (Exhibitor Plus Sponsor), IT Mill (Exhibitor Plus Sponsor), FrogLogic (Exhibitor Plus Sponsor), ThinWire (Expo Sponsor), Quasar Tecnologies (Expo Sponsor), Zapatec (Exhibitor Plus Sponsor), MB Technologies Bindows (Exhibitor), OpenSpot (Exhibitor), ILOG (Exhibitor), Passport Corporation (Exhibitor), Addison-Wesley (Exhibitor), The Thomson Corporation (Exhibitor), Isomorphic Software-SmartClient (Exhibitor), Universal Mind (Exhibitor), Farata Systems (Exhibitor Plus), Manning Publications (AJAX Book Sponsor), Apress (AJAX Book Sponsor), Conference Guru (Media Sponsor), Flash Goddess (Media Sponsor), AJAXWorld Magazine (Media Sponsor), Web 2.0 Journal (Media Sponsor), SYS-CON.TV (Media Sponsor), IT Mill (Media Sponsor), Methods & Tools (Media Sponsor), Web 2.0 Journal (Media Sponsor), and OASIS.
As of today OpenAjax Alliance members include: 24SevenOffice, abiss.gr, ActiveGrid, ActiveState, Adobe, American Greetings, Aplix Corporation, Appeon, Aptana, Arimaan Global Consulting, BEA Systems, Cisco Systems, Coradiant, Curl, Custom Credit Systems (Thinwire), Document Advantage, Dojo Foundation DreamFace Interactive, Eclipse Foundation, edge IPK, eLink Business Innovations, ESRI, F5, Fidelity Investments, Finetooth, Getahead (DWR), Global Computer Enterprises, GoETC, Google, Helmi Technologies, HR-XML, IBM, ICEsoft, Ikivo, ILOG, Innoopract, iPolipo, Isomorphic Software, IT MILL, JackBe, Javeline, JSSL, JWAX, Laszlo Systems, Lightstreamer, Microsoft, MobileAware, Mozilla Corporation, NetScript Technologies, Nexaweb, Nitobi, Novell, OpenLink Software, OpenSpot, OpenSymphony (OpenQA), Openwave Systems, Opera, OpSource, Oracle, OS3.IT, RadView, Redmonk, RIFT Technologies, SAP, Scalix, Seagull Software, Service-Now.com, Sitepen, Software AG, Sun Microsystems, Tealeaf Technology, Teleca Mobile, Telerik, The Frontside, Tibco, Transmend, Vertex Logic, Visible Measures, Visual WebGui, Volantis Systems, Webtide, XML11, Xucia, Zend, Zimbra, and Zoho.
Published August 30, 2007 Reads 8,107
Copyright © 2007 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By RIA News Desk
Ever since Google popularized a smarter, more responsive and interactive Web experience by using AJAX (Asynchronous JavaScript + XML) for its Google Maps & Gmail applications, SYS-CON's RIA News Desk has been covering every aspect of Rich Internet Applications and those creating and deploying them. If you have breaking RIA news, please send it to RIA@sys-con.com to share your product and company news coverage with AJAXWorld readers.
![]() |
radixweb 08/18/08 07:24:10 AM EDT | |||
Great Post... Java Programmer... |
||||
![]() |
radixweb 08/18/08 03:07:42 AM EDT | |||
Hey, Great Post..... |
||||
![]() |
AJAX Security News Desk 08/28/07 12:33:55 PM EDT | |||
With so many Web 2.0 applications being written in AJAX, it was only a matter of time before the vulnerabilities began to crop up, but no one expected the unusual form they would take. This session by the man who discovered the first cross-vendor AJAX vulnerability - JavaScript Hijacking - will detail it and other security concerns while also discussing ways that AJAX could be implemented to make it less risky. Finally, we will take a look at AJAX security incidents to-date, and identify the ways that increased adoption of AJAX is likely to change the way hackers behave. |
||||
- Yahoo! to Keynote 4th Cloud Expo: Accelerating Innovation with Cloud Computing
- Wave on Ulitzer: Confessions of a Google Wave Fanboy
- Yahoo! SVP Shelton Shugar to Discuss Innovation at Cloud Computing Expo
- Ulitzer Provides a Powerful Social Journalism Platform
- Live Demo of Yahoo! Query Language at Cloud Computing Expo
- Bernanke Should Go Back to Teaching
- How to Extract Your Contacts from LinkedIn and Facebook
- Yahoo! Announces Open-Source Cloud Server
- Google Responds to the Bing Challenge
- Google Open Sources its JavaScript Tools
- Adobe Cans Another 9% of its Workforce
- Unix Co-Creator Writes New Open Source Programming Language for Google
- Yahoo! Named “Platinum Sponsor” of Cloud Computing Expo
- Yahoo! to Keynote 4th Cloud Expo: Accelerating Innovation with Cloud Computing
- Confessions of a Ulitzer Addict
- Wave on Ulitzer: Confessions of a Google Wave Fanboy
- Twitter, Linked In, Ning and Ulitzer: Easy Personal Branding Strategy
- Ulitzer Live! New Media Conference & Expo
- Ulitzer vs. Ning
- Yahoo! SVP Shelton Shugar to Discuss Innovation at Cloud Computing Expo
- Google Wave Hits Wider Beta
- Ulitzer Provides a Powerful Social Journalism Platform
- Social Media on Ulitzer - Strategy Nets New AUM for RIA
- Live Demo of Yahoo! Query Language at Cloud Computing Expo
- Where Are RIA Technologies Headed in 2008?
- The Top 250 Players in the Cloud Computing Ecosystem
- Google Version 2.0: Googzilla - The Calculating Predator
- Google Space Launches at Heathrow Airport
- SEO/SEM Tips & Tricks: How and When Should You Submit Your Website to Google?
- Google Snaps Up the Father of the Orion Search Engine
- AOL To Enhance Video Search Engine by Adding RSS Feeds
- Ulitzer vs Knol - Google Wants Its Own Wikipedia
- AJAXWorld Knocks Spots Off LinuxWorld
- The World's Youngest "Google Entrepreneur" Is One Month Old
- Microsoft's Chase After Google Reverberates
- Google Jabbers On with GoogleTalk


































