Collected research
Ajax (in)security
Billy Hoffman's Black Hat USA 2006 deck. Ajax pushes control logic to the client, exposing the server-side function API as attack surface; XmlHttpRequest traffic is indistinguishable from browser traffic, so requests cannot be repudiated; Ajax turns XSS self-propagating, analysed through the Samy MySpace worm. Ajax bridges are unauthenticated open proxies for laundering attacks at third parties.
Record
- Researcher
- Billy Hoffman
- Published by
- blackhat.com
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Billy Hoffman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .