Collected research
JavaScript Hijacking
Secure Coding: JavaScript Hijacking
Brian Chess's 1 April 2007 Secure Coding post naming JavaScript Hijacking. Ajax frameworks returning JavaScript rather than XML can be loaded cross-origin by a script tag, so a malicious site reads confidential array or object literals. Fortify found almost every framework surveyed, including GWT and Atlas, made this easy or unavoidable.
Record
- Document
- Secure Coding: JavaScript Hijacking
- Researcher
- Brian Chess
- Published by
- seclists.org
- Topic
- Server
In the archive
Related sources
- JavaScript Hijacking Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Brian Chess, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .