Web Hack List

Collected research

Ajax (in)security

Billy Hoffman's Black Hat USA 2006 deck. Ajax pushes control logic to the client, exposing the server-side function API as attack surface; XmlHttpRequest traffic is indistinguishable from browser traffic, so requests cannot be repudiated; Ajax turns XSS self-propagating, analysed through the Samy MySpace worm. Ajax bridges are unauthenticated open proxies for laundering attacks at third parties.

Record

Researcher
Billy Hoffman
Published by
blackhat.com
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Billy Hoffman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .