All the latest UK technology news, reviews and analysis

Ajax developers playing with fire

by Tom Sanders at AjaxWorld in Santa Clara, California

05 Oct 2006

Be the first to comment

  • Tweet this
The rise of Ajax applications is exposing enterprises to a new series of security threats
Ajax programmers pay insufficient attention to security risks

The rise of Asynchronous JavaScript and XML (Ajax) applications is exposing enterprises and end users to a new series of security threats, but developers are insufficiently aware of the risks.

"We are seeing a rise in web application attacks because people are realising that it is easier to go through the web application," Billy Hoffman, a lead security researcher with Spi Dynamics, told vnunet.com

"There is all sorts of money to be made in web security," Hoffman said at the AjaxWorld conference in Santa Clara, California. 

"It is often easier to attack an application through the web layer than by trying to break through the firewall or spoof around the intrusion detection system. Criminals take the path of least resistance."

From the end-user perspective, Ajax is a programming technique that allows websites to pre-fetch data and facilitate more interactive websites.

Google unveiled Ajax tools for its search engine on Tuesday that let web publishers integrate search and search results directly onto their web pages.

Other popular services using Ajax include the Flickr photo sharing service and the Digg social book-marking site. 

Under the hood, Ajax uses web services techniques such as XML to transmit information directly from a database to the website.

In a non-Ajax application, the same application would have required a web server to build the actual webpage presented to the user. But an Ajax application combines disparate data sources directly on the client system.

Whereas the database was kept within the safe confines of the corporate firewall, Ajax requires the services to be directly accessed by outside systems. "When you 'Ajaxify' an application, it increases the attack surface," said Hoffman.

Yahoo was hit by a security vulnerability in its online mail service last summer.

A maliciously crafted email message allowed attackers to access users' email accounts, download the contents of their address books and send out spam emails from the hacked accounts.

Such threats are known as cross-site scripting vulnerabilities (commonly referred to as XSS) because they span several services.

They are rapidly becoming a dominant online threat category, according to Hoffman. Salesforce.com, PayPal and Google have all been forced to repair XSS security holes in their online software.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Desktop Deployment Support Analyst (Worksite, SQL)

Desktop Deployment Support Analyst (Worksite, SQL...

Project Manager

Project Manager is required by Bank in Germany Suitable...

Web Developer / Web Designer Mobile & Social Media Application

Mobile & Social Media Application Web Developer...

CCVP Consultant

CCVP Consultant - Telecoms Cisco Certified Voice Professional...

To send to more than one email address, simply separate each address with a comma.