When Ajax Attacks! Web application security fundamentals

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

1 comments

Comments 1 - 1 of 1 previous next Post a comment

Post a comment
Embed Video
Edit your comment Cancel

21 Favorites

When Ajax Attacks! Web application security fundamentals - Presentation Transcript

  1. When Ajax Attacks! Web application security fundamentals Simon Willison, @media Ajax 2008
  2. I’m here to scare you • XSS • PDF • CSRF • XBL • UTF-7 • HTC • crossdomain.xml • JSON and JSONP
  3. A few years ago... • Web application security tutorials tended to boil down to three things: • Don’t trust input from users • Avoid SQL injection attacks • Don’t let people inject JS in to your pages
  4. A few years ago... • Web application security tutorials tended to boil down to three things: • Don’t trust input from users Boring! • Avoid SQL injection attacks • Don’t let people inject JS in to your pages
  5. A few years ago... • Web application security tutorials tended to boil down to three things: • Don’t trust input from use

simonsimon, 9 months ago

custom

4636 views, 21 favs, 11 embeds more stats

Web application security is hard, and getting harde more

More Info

© All Rights Reserved

Go to text version
  • Total Views 4636
    • 3187 on SlideShare
    • 1449 from embeds
  • Comments 1
  • Favorites 21
  • Downloads 227
Most viewed embeds
  • 959 views on http://simonwillison.net
  • 454 views on http://ajaxian.com
  • 12 views on http://cybexin.blogspot.com
  • 7 views on http://min2liz.net
  • 6 views on http://extjs.com

more

All embeds
  • 959 views on http://simonwillison.net
  • 454 views on http://ajaxian.com
  • 12 views on http://cybexin.blogspot.com
  • 7 views on http://min2liz.net
  • 6 views on http://extjs.com
  • 4 views on http://itmmetelko.com
  • 2 views on http://www.itmmetelko.com
  • 2 views on http://www.xaguilars.com
  • 1 views on http://www.google.nl
  • 1 views on http://htmledit.squarefree.com
  • 1 views on http://softlibre.barrapunto.com

less

Flagged as inappropriate Flag as inappropriate
Flag as innappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

Categories