• Email
  • Like
  • Save
  • Private Content
  • Embed
 

Client-side JavaScript Vulnerabilities

by on Jul 28, 2011

  • 9,449 views

Automatically detecting client side JavaScript vulnerabilities using IBM Rational AppScan and JavaScript Security Analyzer (hybrid analysis)

Automatically detecting client side JavaScript vulnerabilities using IBM Rational AppScan and JavaScript Security Analyzer (hybrid analysis)

Accessibility

Categories

Upload Details

Uploaded via SlideShare as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

3 Embeds 12

http://twitter.com 7
https://twitter.com 4
http://a0.twimg.com 1

Statistics

Likes
4
Downloads
86
Comments
3
Embed Views
12
Views on SlideShare
9,437
Total Views
9,449

13 of 3 previous next Post a comment

  • waqeehulhasan Waqeeh Sonu nice 6 months ago
    Are you sure you want to
  • jasonrboggess Jason Boggess I guess I don't understand. You can manually execute any javascript from the client anyway just by typing 'javascript:{...}' in the address bar of any modern browser and the webkit browsers have a console where you can type and execute your own javascript commands, so if one wanted to call APIs from his own client, he could easily do it without js injection.... I guess someone could create a malicious link as in the examples, but http could be configured not to run cross domains so you can't extract any information from any http request. Most sites require authentication before you access sensitive information anyway, so for the 'attack' to have any effect you would have to be logged in in one tab and then click on a link in another that redirects you back to a hacked page on the first, which would be a strange thing to do. 8 months ago
    Are you sure you want to
  • orysegal orysegal FYI - JSA has been improved greatly recently, and now actually located that 40% of the F500 web sites are actually vulnerable! 1 year ago
    Are you sure you want to
Post Comment
Edit your comment

Client-side JavaScript Vulnerabilities Client-side JavaScript Vulnerabilities Presentation Transcript