Welcome Guest | |
Follow Us:
    
Newsletter Signup:
Is Web 2.0 inherently insecure?
Ajax applications may be less secure than standard Web applications By Jordan Wiens, NWC, June 01, 2007
      

Ajax applications may be less secure than standard Web applications. At a minimum, splitting an app into two distinct programmatic components—one for the browser, one for the server—appears to open up Ajax-specific vulnerabilities.

Although the ‘X’ in Ajax stands for XML, many Web 2.0 apps don’t actually use XML as a container for the data being sent to and from the client and server. Instead, they pass data as a JavaScript object or as code that can be evaluated in JavaScript, simplifying client-side processing.

The problem—recently highlighted in a Fortify Software advisory and originally described over a year ago—is that this approach leaves users vulnerable, in particular, to cross-site request forgery attacks. In such an attack, a Web site can cause your brow­ser to make requests to another domain name with your current session cookie for that site, and access the returned data by overriding default JavaScript functions.

This means a lot of Ajax applications must be updated. If the framework developers can’t get it right, what are the odds that an average developer can keep Ajax apps secure?



blog comments powered by Disqus
Featured Videos


 
    
 
     Analytics & Reports
Tech Center : Understanding The Danger Within
Data Center Automation - 10 Questions to Ask Before Proceeding
Identity Management: 10 Questions to Ask
Tech Center: DBA Guide to Improved Security
Research: 2009 InformationWeek 500 Report
Future Strategist Award
Who's next in line for the CIO position?
As a CIO you mentor someone in your organization for the future IT leadership role. InformationWeek would like to acknowledge and felicitate that special person at an awards ceremony at Interop
Top Stories
Case Study
How Patni built its private cloud
Patni's global head of technology, Satish Joshi, explains the challenges and nuances of building a private cloud
InformationWeek India on Facebook
Inteorp Mumbai 2010
Interop Mumbai 2010