The rise of Ajax applications is exposing enterprises to a new series of security threats
Ajax programmers pay insufficient attention to security risks

Ajax developers playing with fire

Security overlooked in Web 2.0 land grab

Tom Sanders at AjaxWorld in Santa Clara, California

The rise of Asynchronous JavaScript and XML (Ajax) applications is exposing enterprises and end users to a new series of security threats, but developers are insufficiently aware of the risks.

"We are seeing a rise in web application attacks because people are realising that it is easier to go through the web application," Billy Hoffman, a lead security researcher with Spi Dynamics, told vnunet.com

Advertisement

"There is all sorts of money to be made in web security," Hoffman said at the AjaxWorld conference in Santa Clara, California. 

"It is often easier to attack an application through the web layer than by trying to break through the firewall or spoof around the intrusion detection system. Criminals take the path of least resistance."

From the end-user perspective, Ajax is a programming technique that allows websites to pre-fetch data and facilitate more interactive websites.

Google unveiled Ajax tools for its search engine on Tuesday that let web publishers integrate search and search results directly onto their web pages.

Other popular services using Ajax include the Flickr photo sharing service and the Digg social book-marking site. 

Under the hood, Ajax uses web services techniques such as XML to transmit information directly from a database to the website.

In a non-Ajax application, the same application would have required a web server to build the actual webpage presented to the user. But an Ajax application combines disparate data sources directly on the client system.

Whereas the database was kept within the safe confines of the corporate firewall, Ajax requires the services to be directly accessed by outside systems. "When you 'Ajaxify' an application, it increases the attack surface," said Hoffman.

Yahoo was hit by a security vulnerability in its online mail service last summer.

A maliciously crafted email message allowed attackers to access users' email accounts, download the contents of their address books and send out spam emails from the hacked accounts.

Such threats are known as cross-site scripting vulnerabilities (commonly referred to as XSS) because they span several services.

They are rapidly becoming a dominant online threat category, according to Hoffman. Salesforce.com, PayPal and Google have all been forced to repair XSS security holes in their online software.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

a padlock

Microsoft to plug security holes

Microsoft has given advance warning of a number of security...

Nokia handset

Top 10 articles, 10 July 09

No Nokia Android phone, ActiveX attacks and Google enters into...

Can Google beat Microsoft at its own game?

Google's announcement this week that it plans to step into...

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Primary Navigation