Web Hack List

Collected research

JavaScript Hijacking

Secure Coding: JavaScript Hijacking

Brian Chess's 1 April 2007 Secure Coding post naming JavaScript Hijacking. Ajax frameworks returning JavaScript rather than XML can be loaded cross-origin by a script tag, so a malicious site reads confidential array or object literals. Fortify found almost every framework surveyed, including GWT and Atlas, made this easy or unavoidable.

Record

Document
Secure Coding: JavaScript Hijacking
Researcher
Brian Chess
Published by
seclists.org
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Brian Chess, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .