CiteULike is a free online bibliography manager. Register and you can start organising your references online.

The security risks of AJAX/web 2.0 applications Export

Network Security, Vol. 2007, No. 3. (March 2007), pp. 4-8.

Citation Format

[Posts]

View FullText article


X Reviews [Write a review of this article]

X Find related articles from these CiteULike users

X Find related articles with these CiteULike tags

X Posting History

X Abstract

Web 2.0 has become a generic phrase summing up everything that is hot and new about the internet. However, underneath it lie some fundamental concepts, including the writeable web, increased audience participation, and a move away from traditional `click and wait' web applications, in which input was delivered on a page by page basis. AJAX (asynchronous Javascript and XML) is a programming mechanism that has enabled developers to deliver a better experience to web users. However, just as basic Javascript validation mechanisms did before it, AJAX-based applications may be subject to abuse by intruders who can launch attacks designed to bypass login scripts, for example. Programmers and project managers must come to terms with the tension between a better user experience and the potential for security flaws. One way to resolve them is to use robust coding techniques to protect applications. Paul Ritchie, a security consultant at penetration testing company SecureTest, examines the underlying concepts of AJAX and then evaluates some potential attack vectors. The term `web 2.0' was coined by O'Reilly Media following a number of conferences that it hosted in 2004. The popular media latched onto the concept and turned it into a popular phrase that has become synonymous with a new breed of website. Web 2.0 sites typically bring user collaboration to the foreground and offer interactivity closer to that of a desktop application.


X BibTeX record

X RIS record


Privacy Statement | Terms & Conditions
CiteULike organises scholarly (or academic) papers or literature and provides bibliographic (which means it makes bibliographies) for universities and higher education establishments. It helps undergraduates and postgraduates. People studying for PhDs or in postdoctoral (postdoc) positions. The service is similar in scope to EndNote or RefWorks or any other reference manager like BibTeX, but it is a social bookmarking service for scientists and humanities researchers.