• On The Insider: Judge Bans Real Housewives Sex Tape
April 23, 2008 5:41 PM PDT

Web 2.0, meet Internet attack 2.0

by Stephen Shankland

SAN FRANCISCO--The glitzy, interactive abilities of Web 2.0 have led to a profusion of new applications, but the technology also is bringing a new era of security vulnerabilities, a security researcher warned Wednesday.

"Security was a challenge to begin with, but if anything it's getting harder in the Web 2.0 world," said Jacob West, manager of the security research group at Fortify, a company that helps companies make sure their software is secure. He made his comments during a talk at the Web 2.0 Expo in San Francisco here.

Jacob West, manager of the security research group at Fortify, says  Ajax technology means more vulnerabilities.

Jacob West, manager of the security research group at Fortify

(Credit: Stephen Shankland/CNET Networks)

A big culprit is JavaScript, a language that's widely used to control Web browsers and enable more sophisticated operations. JavaScript has been around for more than a decade, but new risks are emerging since it's a major component of Ajax, a Web 2.0 technology used to build richly interactive sites.

"The number of unique problems from Ajax will remain pretty small," West said in an interview after his speech. But Ajax means that JavaScript is being used much more widely and in much more complicated ways, so existing vulnerabilities are more widespread, and "attack techniques are improving quickly."

He did describe one particular Ajax-specific problem called JavaScript hijacking. With it, a Web browser that picks up malicious JavaScript code from a Web site can be instructed, in effect, to send confidential information with an attacker.

"JavaScript hijacking is Ajax-specific," West said. It relies on the transmission of personal information packaged as JavaScript code, and "transmitting information with JavaScript I unique to Ajax code."

Another problem triggered by Ajax are that JavaScript is more complex and therefore harder to test. And more sophistication brings more opportunities for problems with "input validation"--making sure that text typed into forms, for example, isn't actually naughty code that could sidestep ordinary scrutiny and run on somebody's computer.

West was pessimistic that fundamental progress would help reduce vulnerabilities. Companies with browsers and Web sites are reluctant to embrace change that would break compatibility with older technology, for example.

"We're talking about fixes that are going to come in the 10-year time frame," he said.

But some are working to at least close up the holes. For example, programmers working on Direct Web Remoting (DWR) and the Google Web Toolkit (GWT) updated their Ajax programming toolkits to head JavaScript hijacking attacks off at the pass.

Other toolkit makers were not so responsive, though, he said: "Microsoft and Yahoo wrote back and said, 'Nope, we're not going to fix that.'"

Stephen Shankland writes about a wide range of technology and products, but has a particular focus on browsers and digital photography. He joined CNET News in 1998 and since then also has covered Google, Yahoo, servers, supercomputing, Linux and open-source software, and science. E-mail Stephen, or follow him on Twitter at http://www.twitter.com/stshank.

Recent posts from News Blog
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
Add a Comment (Log in or register)
If Microsoft refuses to fix these toolkits
by Leria April 25, 2008 4:27 PM PDT
It's time to stop using Microsoft's toolkits immediately. Same thing for Yahoo's toolkits.
Reply to this comment
advertisement

Making sense of Windows 7 upgrades

faq The basics and the fine print on Microsoft's options for those eyeing the next operating system from Redmond.
• Full Windows 7 coverage

Road Trip 2009: Big Sky Country

CNET News reporter Daniel Terdiman takes his car full of gadgets to the Rockies and the Great Plains in search of tech, science, nature, and more.
• America's Fortress: Cheyenne Mountain

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right