My Account Log in

1 option

Ajax security

O'Reilly Online Learning: Academic/Public Library Edition Available online

View online
Format:
Book
Author/Creator:
Hoffman, Billy, Author.
Contributor:
Sullivan, Bryan, Contributor.
Language:
English
Subjects (All):
Ajax (Web site development technology)--Security measures.
Ajax (Web site development technology).
Computer networks.
Computer security.
Physical Description:
1 online resource (xxvi, 470 p. ) ill. ;
Edition:
1st edition
Place of Publication:
[Place of publication not identified] Addison Wesley 2008
Language Note:
English
System Details:
text file
Summary:
The Hands-On, Practical Guide to Preventing Ajax-Related Security Vulnerabilities More and more Web sites are being rewritten as Ajax applications; even traditional desktop software is rapidly moving to the Web via Ajax. But, all too often, this transition is being made with reckless disregard for security. If Ajax applications aren’t designed and coded properly, they can be susceptible to far more dangerous security vulnerabilities than conventional Web or desktop software. Ajax developers desperately need guidance on securing their applications: knowledge that’s been virtually impossible to find, until now . Ajax Security systematically debunks today’s most dangerous myths about Ajax security, illustrating key points with detailed case studies of actual exploited Ajax vulnerabilities, ranging from MySpace’s Samy worm to MacWorld’s conference code validator. Even more important, it delivers specific, up-to-the-minute recommendations for securing Ajax applications in each major Web programming language and environment, including .NET, Java, PHP, and even Ruby on Rails. You’ll learn how to: · Mitigate unique risks associated with Ajax, including overly granular Web services, application control flow tampering, and manipulation of program logic · Write new Ajax code more safely—and identify and fix flaws in existing code · Prevent emerging Ajax-specific attacks, including JavaScript hijacking and persistent storage theft · Avoid attacks based on XSS and SQL Injection—including a dangerous SQL Injection variant that can extract an entire backend database with just two requests · Leverage security built into Ajax frameworks like Prototype, Dojo, and ASP.NET AJAX Extensions—and recognize what you still must implement on your own · Create more secure “mashup” applications Ajax Security will be an indispensable resource for developers coding or maintaining Ajax applications; architects and development managers planning or designing new Ajax software, and all software security professionals, from QA specialists to penetration testers.
Contents:
Cover Page
Title Page
Copyright Page
Contents
Preface
Preface (The Real One)
Chapter 1 Introduction to Ajax Security
Chapter 2 The Heist
Chapter 3 Web Attacks
Chapter 4 Ajax Attack Surface
Chapter 5 Ajax Code Complexity
Chapter 6 Transparency in Ajax Applications
Chapter 7 Hijacking Ajax Applications
Chapter 8 Attacking Client-Side Storage
Chapter 9 Offline Ajax Applications
Chapter 10 Request Origin Issues
Chapter 11 Web Mashups and Aggregators
Chapter 12 Attacking the Presentation Layer
Chapter 13 JavaScript Worms
Chapter 14 Testing Ajax Applications
Chapter 15 Analysis of Ajax Frameworks
Appendix A Samy Source Code
Appendix B Source Code for Yamanner Worm
Index
Footnotes
Chapter 1
Chapter 4
Chapter 5
Chapter 7
Chapter 8
Chapter 9
Chapter 10
Chapter 11
Chapter 12
Chapter 13.
Notes:
Bibliographic Level Mode of Issuance: Monograph
Description based on publisher supplied metadata and other sources.
ISBN:
9780132701921
0132701928
OCLC:
213482733

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account