Collected research
Breaking AJAX Web Applications: Vulns 2.0 in Web 2.0
Stamos and Lackey's Black Hat Japan 2006 deck on the AJAX attack surface: enumerating server-side methods from downstream JavaScript, manipulating parameters no browser ever sent, XSS through eval'd JSON responses, and CSRF against XHR endpoints. Includes a framework-by-framework review of Microsoft ATLAS, Google GWT and Java DWR, and crossdomain.xml wildcard abuse.
Record
- Researcher
- Alex Stamos and Zane Lackey
- Published by
- blackhat.com
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Alex Stamos and Zane Lackey, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .