YISTA

Ajaxy Web 2.0 apps vulnerable to attacks

April 4th, 2007 by Marston

According to Fortify Software, 11 out of 12 of the most popular Ajax/JS frameworks are vulnerable to javascript hijacking. So apparently every shiney web 2.0 app out there is ripe for the picking!

“Fortify said that the “pervasive and critical vulnerability” is present in 11 of the 12 most popular AJAX frameworks, and therefore in many Web 2.0 applications. It allows an attacker to pose as the application’s user and intercept data sent via JavaScript commands, by using the script tag to circumvent the ’same origin policy’ imposed by web browsers.”

“JavaScript Hijacking appears to be a ubiquitous problem,” said Fortify. It claimed that only Direct Web Remoting (DWR) 2.0, a project which dynamically generates Java classes on the server from JavaScript, is immune to the attack, but said that fixes are available or feasible for other AJAX frameworks.

I’ve never heard of Direct Web Remoting before, but hey, maybe there is something to be learned here. The article doesn’t talk specifically about Prototype or Scriptaculous but I’m sure they among the bunch.

Here is the Yahoo! story: Web 2.0 apps vulnerable to attack

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]
Filed under: Security, Web 2.0

One Response to “Ajaxy Web 2.0 apps vulnerable to attacks”

  1. George Burnett
    April 8th, 2007 - 7:35 pm

    I have been waiting for something like this to come along and show it’s BIG ugly head!

    This is going to open a world of new XSS hacks.

Leave a Reply

Yah, I saw that already too, but just in case you may missed something YISTA is here to keep you up-to-date on the latest hardware, technologies, hacks and caffeinated properties :) Subscribe to our newsletter. Send tips and requests.
Grab our RSS feed   |  Follow us on Twitter YISTA on Twitter

Additional Possibly Related Posts:

  • Reddit.com XSS Exploit
  • New Tech Defined: DNSSEC
  • Adobe Apollo, Dekoh and Joyent Slingshot launch
  • Mac OS X Hack Challenge Suspended

YISTA Sections Show Sections | Hide Sections

  • *nix
  • Apple
  • Arts
  • Audio
  • Caffeine
  • Coding
  • Conferences
  • Design
  • File Sharing
  • Gadgets
  • Games
  • Gaming
  • Google
  • Guides
  • Hacks
  • Hardware
  • Health
  • iPod
  • Laptops
  • Microsoft
  • Mobiles
  • Mods
  • Movies
  • Networking
  • News
  • Nintendo
  • Open Source
  • Parody
  • Rumors
  • Search
  • Security
  • Social Networking
  • Software
  • TV
  • Uncategorized
  • Videos
  • Viruses
  • VoIP
  • Web 2.0
  • Wireless

YISTA Sections Amazon Kindling TCHOPro Chocolate iPhone Redesign iPhone Video Conference Hack LED Bike Wheel Images DIY iPod Super Dock :: Part 1 Portable Mobile 3G to Wi-Fi Hotspot Device Adobe Apollo, Dekoh and Joyent Slingshot launch Pownce Opens To The Public BlackBerry :: Red Pearl Unboxing MTV’s URGE To Copy iTunes Music Store Pepsi Cappuccino

Hot Topics

Amazon Apple Arts Blackberry Caffeine code Coding comic compiz Conferences Dell Design DIY DRM Firefox Flickr Google Hacks Hardware iPhone iPod iTunes Linux Macbook Mac OS X Mobiles music Nintendo OLPC Open Source Palm Parody robots Search Security Software space The Pirate Bay torrents Ubuntu Videos VoIP Web 2.0 web app Wii

. Sign up for the YISTA daily email
You will receive our new posts delivered right into your inbox every afternoon. It's free and easy!

Recent Comments

Create MPEGs of Your Favorite YouTube Videos

1 Comment
Microsoft’s “Big Ass Table”

1 Comment
Open Cloud Manifesto Leaked

1 Comment
Tweet on Twitter Clients

1 Comment

Recent Posts

Japanese Astronauts Flying Carpet Trick
05/20/2009
Amazon Kindling
05/13/2009
TCHOPro Chocolate
05/06/2009
Asus Seashell EEE 1008HA
05/06/2009
Begin Charting Your Life
05/06/2009

About YISTA

YISTA is the No. 1 technologist's guide for geeks. w00t indeed!

Subscribe: Newsletter | RSS Feed RSS

Browse: The Archives

Contact: Tips & Requests | Advertise

Copyright © 2005-2008 YISTA. All rights reserved.  Proudly powered by WordPress.