Session
Vulnerabilities 2.0 in Web 2.0: Next Generation Web Apps from a Hacker's Perspective
Alex Stamos, Founding Partner, iSEC Partners
Track: Web 2.0 Services and Platforms
Date: Monday, April 16
Time: 11:15am
- 12:05pm
Location: 2022
Unfortunately, there is a dark side to this new technology that has not been properly explored. The tighter integration of client and server code, as well as the invention of much richer downstream protocols that are parsed by the web browser, has created new attacks as well as made classic web application attacks more difficult to prevent.
We will discuss XSS, Cross-Site Request Forgery (XSRF), parameter tampering, and object serialization attacks in AJAX applications, and will discuss our open source AJAX-based XSRF attack framework. We will also be discussing a security analysis of several popular AJAX frameworks, including Microsoft Atlas, Prototype, Java DWR, Dojo, and SAJAX.
The talk will include live demos against vulnerable web applications, and will be appropriate for attendees with a basic understanding of HTML and JavaScript.














































































