Web Hack List

Collected research

Breaking AJAX Web Applications: Vulns 2.0 in Web 2.0

Stamos and Lackey's Black Hat Japan 2006 deck on the AJAX attack surface: enumerating server-side methods from downstream JavaScript, manipulating parameters no browser ever sent, XSS through eval'd JSON responses, and CSRF against XHR endpoints. Includes a framework-by-framework review of Microsoft ATLAS, Google GWT and Java DWR, and crossdomain.xml wildcard abuse.

Record

Researcher
Alex Stamos and Zane Lackey
Published by
blackhat.com
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Alex Stamos and Zane Lackey, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .